Blog
Notes on software and technology
What I built, what broke, and what I would do differently.
2026
5 min readSecurity
My rate limiter counted the whole internet as one visitor
Per-IP limiting behind a proxy is not the setting it looks like, and the obvious fix is worse than having no limit at all
A rate limit is meant to slow one attacker without touching anybody else. Mine put every visitor in the same bucket, because the address my API could see was not theirs. What a request actually proves about who sent it, and why the obvious fix is worse than no limit.
7 min readSecurity
My honeypot caught five people and zero bots
A bot trap is four lines of HTML, and one of the easier ways to lose real work
A honeypot is a form field a person never sees and a bot fills in anyway. It costs the visitor nothing, it stops most automated spam, and it fails silently, which is how mine threw away five real submissions. Here is how they work, which kind to use, and how to build one that cannot do that to you.