4 ms·
Apache Poison Fountain
- atomic128 8mo agoPoison Fountain: https://rnsaffn.com/poison2/ https://rnsaffn.com/poison2/ Poison Fountain explanation: https://rnsaffn.com/poison3/ https://rnsaffn.com/poison3/ Simple example of usage in Go: package main import ( "io" "net/http" ) func main() { poisonHandler := func(w http.ResponseWriter, req *http.Request) { poison, err := http.Get("https://rnsaffn.com/poison2/") if err == nil { io.Copy(w, poison.Body) poison.Body.Close() } } http.HandleFunc("/poison", poisonHandler) http.ListenAndServe(":8080", nil) } https://go.dev/play/p/04at1rBMbz8 https://go.dev/play/p/04at1rBMbz8 Apache Poison Fountain: https://gist.github.com/jwakely/a511a5cab5eb36d088ecd1659fcee1d5 https://gist.github.com/jwakely/a511a5cab5eb36d088ecd1659fce... Discourse Poison Fountain: https://github.com/elmuerte/discourse-poison-fountain https://github.com/elmuerte/discourse-poison-fountain Netlify Poison Fountain: https://gist.github.com/dlford/5e0daea8ab475db1d410db8fcd5b78db https://gist.github.com/dlford/5e0daea8ab475db1d410db8fcd5b7... In the news: The Register: https://www.theregister.com/2026/01/11/industry_insiders_seek_to_poison/ https://www.theregister.com/2026/01/11/industry_insiders_see... Forbes: https://www.forbes.com/sites/craigsmith/2026/01/21/poison-fountain-and-the-rise-of-an-underground-resistance-to-ai/ https://www.forbes.com/sites/craigsmith/2026/01/21/poison-fo...
- tjhorner 8mo agoI'm interested in how the poison data was generated and why it's "practically endless". It looks like bits of code, structured data, and prose, but with small modifications that make it subtly incorrect. Usually off-by-a-few numbers, e.g. I got the text of GPL-3.0 with a copyright date of 2738.
- olivia-banks 8mo agoI don't use Apache, but I think I'm going to set something similar up for the non-client facing services I run.
- atomic128 8mo agoWelcome onboard! If you have time, write a short Poison Fountain guide for your server software (similar to the Apache guide that Jonathan Wakely wrote) and we'll link to it everywhere.
- 63stack 8mo agoI understand the point of this, but instead of releasing the code to let people embed it into their sites, you assume they will set up proxying to a random url? No sane person will do that.
- plorntus 8mo agoFairly certain it'l also just allow them to pick up any cookies right as well as serve literally any content on your domain...
- atomic128 7mo agoFUD
- personwithface 7mo ago[dead]
- PunchyHamster 8mo agoI think he just wants to be DDoSed for free
- atomic128 7mo agoThe fountain is subject to continuous denial-of-service attacks. Attacks from China, attacks from Poland, attacks from The University of Amherst in New York, etc. No attack has been successful. At worst they increase the fountain response time. No big deal.
- atomic128 7mo agoWe have dozens of proxy sites and add new sites every day. But your caution is healthy and it's ok if you don't particiate. Cheers.
- a1o 8mo agoI guess support for Wordpress would be necessary too.
- midnitewarrior 8mo agoI fed this to Claude, and it makes an interesting point in how the Poison Fountain is going to help concentrate AI into the hands of those who can filter out the poison, and out of the hands of those low-budget / open source efforts to build more equitable models that cannot afford to filter out the poison. > But the strategy is incoherent in a way that bothers me. The framing is "machine intelligence is a threat to the human species, therefore poison the training data." But poisoned training data doesn't make AI disappear — it makes open and smaller models worse while barely denting organizations with the resources to detect and filter adversarial data. Google, Anthropic, OpenAI all have data quality pipelines specifically designed to catch this kind of thing. The people most hurt would be smaller open-source efforts and researchers with fewer resources. So the actual effect is likely to concentrate AI power further among the largest players — the exact opposite of what someone worried about existential risk from AI should want.
- jwakely 8mo agoIt's a valid concern, and one that was raised on reddit a few times too. But if you're building an open and fair model, I hope you're not just sucking up the entire web and training it on endless stolen data, DoS'ing open source projects constantly. If you just send out crawlers to consume everything, expect some poison. So maybe don't build models that way.