alt.hn

3/26/2026 at 4:06:14 PM

The Hackers Who Tracked My Sleep Cycle

https://glama.ai/blog/2026-03-26-the-hackers-who-tracked-my-sleep-cycle

by statements

3/26/2026 at 9:44:54 PM

One thing I excluded from the article was that we intentionally disabled several checks (like hCaptcha) to let them get to the stage of setting up the payment intents. This is not something I've done before, but basically I wanted to see what happens if in future an attacker is able to bypass all IP/captcha/altcaptcha, etc. restrictions and gets to something that actually does damage. This allowed to see how they are trying to bypass various rate limits/checks that we added specifically for that step. Somewhat an isolated experiment.

by statements

3/29/2026 at 10:21:42 AM

I would wonder if this could also be used as a kind of tripwire, where legitimate users won't present CAPCHA tokens, etc. But fake connections will.

by qmarchi

3/29/2026 at 12:54:17 PM

I have no clue if this worked at all, but in college I made a site that had a checkbox that said “check this box if you’re human” and then hid it with bizarre CSS. If they checked the box, we errored out. I didn’t really do telemetry at all, so no clue if that worked at all, but yeah, I’ve had the same thought!

by LadyCailin

3/29/2026 at 10:32:39 AM

It's insane to me that Stripe cancels accounts when they get used for card testing. I get that it's because the onus would be on them otherwise, but the problem is that the onus is on anyone but the card companies in the first place.

by cassonmars

3/29/2026 at 4:13:56 PM

That's pretty creepy that they found you (well, the author, not sure if this was a self-submit) on discord though. Oof.

by wolvoleo

3/29/2026 at 5:35:30 PM

Well, their Discord server is right on their front page, so he's pretty easy to find.

by KK7NIL

3/29/2026 at 6:53:39 PM

Ah ok I didn't realise that. I only use discord for non work related stuff and never with my real identity. That makes sense though. I still view it as a gaming thing somehow.

by wolvoleo

3/30/2026 at 3:40:58 PM

interesting

by tenghuanhe

3/29/2026 at 12:21:13 PM

[dead]

by s5300