A joke domain purchase turned in geopolitical warfare

974 points · 158 comments on HN · read original →

Points and comments are a snapshot, not live.

A weather balloon tracking hobby site becomes entangled with military, espionage, and war.

SondeHub started in 2018 as a URL redirect joke, grew into a global radiosonde tracker. Its reverse predictions accidentally mapped artillery sites, drawing military attention. In 2023, after the Chinese balloon incident, usage spiked. By 2024, DDoS attacks traced to Russian IPs appeared, suspected to assist Ukrainian drone operations. The operator contacted AWS, urging them not to cut the attacker's access to avoid loss of life. Later, the US Office of the Secretary of War requested data (invoice unpaid). Other contacts include an NTSB inquiry about a balloon-plane collision and a hit-and-run involving a recovered radiosonde.

What commenters are saying

Top comment asks how high-altitude wind predictions are made. Replies detail a mix of aircraft reports, atmospheric motion vectors, Doppler lidar, satellite data, and numerical weather models. The second comment likens the hit-and-run inquiry to the curl guy's experience. One reply warns against responding to such emails without a lawyer. Another commenter recalls AWS contacting them after a bug caused excessive API hits, giving them a chance to explain before shutting down. A top commenter notes AWS support has generally been disappointing, though others recall being asked for their side of the story first.