This was fascinating, thank you. I expected to read about legal threats against the folks collecting this data and am glad that those didn't materialize.
Also I only realized after finishing the article what a breath of fresh air it was to read something that came straight from another human's brain without LLM intermediation. Thank you to the author for that too.
It's fun to see habhub in an article. ~10 years ago a group of friends and I launched 2 weather balloons for fun with a GPS logger, APRS transmitter, and a few sensors, and then retrieved it afterwards.
I have a bunch of memorable experiences from it, including:
1. Under inflating the first balloon because our helium provider was closed, and instead buying lower pressure "party" balloon containers (and not realizing until too late that lower pressure meant more helium left in the containers)
2. Chasing down the balloon at night and trying to explain why you wanted to walk onto some guys field to check for a weather balloon
3. Later calling a gas station to ask if "some guy just arrived with a weather balloon in their truck" when trying to track down the balloon
If anyone has kids and wants a fun project, I highly recommend it. There are a few companies online that sell kits, and it's neat to watch the different layers of the atmosphere (temperature and wind), and try to "chase" after the balloon and find it afterwards.
We did it in the US, and filed a NOTAM with the FAA. The hardest part was figuring out how to convert what I had (we are launching a weather balloon from X, Y coords at Z time) to what they wanted (distance, direction, etc from nearest air tower). It's just a phone number you call, and they were pretty friendly (helping convert my lat / lng to what they needed).
There are rules you have to understand and follow, notifications required but no approvals if you meet certain criteria. It's mostly an FAA thing in the US, so one jurisdiction.
Yup. We were able to find it both times. First time it "floated" and traveled further than we expected (at one point habhub predicted it to land in Africa). This is the one we called a gas station about, and we did end up getting it back. Second time was cleaner, and we drove up someone's driveway, and asked if we could retrieve it.
We had to move our launch site from where we originally wanted as 3 out of 3 predictions showed our landing site to be on an Air Force base. While I was willing to climb a barbed wire fence way out in the middle of nowhere, a fence around a base was not something I could see myself doing. I also didn't want to end up in a news story for causing military alerts. It was surprising just how far we had to go outside of the city to have it land in a spot that we'd be able to retrieve it.
I had this idea before of sending ballons to "the space" with a collectible object and then retrieve them, saying "I have this specific object that was in space too". Is it possible or am I dreaming too much?
For reasonable definitions of "in space" doesn't really cut it. Balloons top out at around 120,000ft unless you're getting super exotic, and that'll only get you another 20k ft or so. Not even out of the stratosphere. Not space by any reasonable definition.
About the lowest thing that could reasonably be called space is the Karmin line, and that's at 100km, or 330,000ft.
Depending on your definition of space, this is what the Earth To Sky does to finance their helium balloons runs: https://www.earthtosky.store/about. I got a pendant for my partner, it was a nice gift.
Your username betrays you, because this is indeed a good idea. Thank you for sharing! I'd never heard of this, but now have some cool gift ideas for family & friends. :)
We did a similar thing, only we intentionally made it more difficult on ourselves by launching at sunset because we were hoping to grab the view of city lights at night with the GoPros. Also, we did not have any licensed radio operators in our group, so no fun equipment like that. We instead depended on a consumer GPS tracker that updated once ever 5 minutes. We also had an Arduino with various sensors attached, but that was for me as the main purpose was the video footage.
Some of the memorable experiences from it:
1) Purchasing equipment to do a Hydrogen launch because this was during a Helium shortage and the cost difference was significant. Arrived at store to pick up our Hydrogen tank where the guy working took a look at us knuckleheads and had serious reservations about selling us inexperienced dorks Hydrogen. Took pity on us and swapped out all of our fittings (hydrogen fittings are specific to prevent accidental use of hydrogen) and sold us the tank of Helium for a much cheaper price than what we were originally told.
2) Printing up stickers to attach to the payload box with "If Found" contact instructions only to realize one second after letting go of the payload that you forgot to attach said stickers.
3) The terror of realizing that when the balloon took off that it immediately headed west when the flight predictions you had been running for the previous days before all showed the balloon landed east.
4) Having to contact ATC to report the launch of the balloon, only to be told they needed further updates at every 10,000' feet.
5) The terror setting in deeper when the consumer GPS unit stopped responding after 30,000' altitude and then having ATC scold how unprofessional we were for using cheap devices. At least they told us they were still tracking it.
6) The shenanigans a group of knuckleheads got up to waiting the ~3 hours for the balloon to land.
7) The relief when the consumer GPS unit started pinging updates again on the way down and the laugh (with us not at us) from ATC that we could start reporting back again.
8) Using mobile Google Maps to attempt to find the GPS location. Wandering around fields in the middle of the night to find a strange circular pattern of out of place plants to realize it was from a deer feeder's throw. Then searching for the nearby camera trap to wave to leave some hunter with serious WTF.
9) Nearly giving up on the search until deciding to use the hotspot to look up the GPS coordinates not on a mobile device to see that the balloon was less than 300' from where we parked making the hours spent wandering really dumb.
> The terror setting in deeper when the consumer GPS unit stopped responding after 30,000' altitude
Ah yes, the CoCom export control limits so you can't use it to build an ICBM. Legally they're supposed to stop working above 60,000 ft and 1,200 mph, but some manufacturers interpret that as an "or". The rumor was that some really cheap chips out of China failed to implement either, so if you'd bought a crappier gps module, you might have been fine!
I am part of the team which runs the OpenStreetMap.org infrastructure, we also get a lot of weird and wonderful requests / emails. .mil, .gov, .edu and GeoTLD variants.
I remember being in Tel Aviv for work, and pulling up maps to plot out a bike route from the hotel to the office. Only to find that the entire route is blurred out online. Turns out our office was a few 100 meters from something important to the IDF, so no map/route data available. Too far to reasonably walk, and didn't want to try a bike without knowing there was a reasonable route...
"Our transmitters shut down after a certain period of time, at the latest when the battery capacity is exhausted. This is due, among other things, to strategic considerations."
Among other things. And this was the most sane part of Meteolabor's email
The part where he gets contacted over the hit-and-run reads like the curl guy’s experience with people investigating “hacking”.
I wonder how often this happens outside of software? Do fence manufacturers get emails asking to identify the culprit when someone crashes through a fence?
I feel like it's a "cast a wide net" type of strategy. Doesn't really hurt to ask and there _could_ be the tiniest hint that could lead to something. Maybe?
Fair, I guess, I just can’t imagine what it’s like getting all these weird requests and demands for a hobby project. Hopefully the author is more entertained than I would be.
Not a lawyer but as a citizen I generally understand that the courts expect demands from court parties to be met.
If meeting the court's (or court parties') demands costs you something you are generally entitled to charge them for it, within reason and with justification.
As a hobbyist therefore putting a service offering page together with your preferred rate probably helps establish the nature and parameters of any such service.
Bill rates / piece rates, especially, and setting up bounds of what is reasonable to expect, in proportion to your gig and your intended effort level.
Quantity and price tiers, turnaround times, what will be included in the deliverable, how it will be delivered, SLAs, etc.
Whatever defines your service, esp as it relates to the types of requests you end up getting.
If I start listing prices, I may need to ensure that I have a business entity set up for tax purposes and to guard against liability. Especially if I’m listing SLAs.
This is not a hobby, it’s a job.
This is why all my hobbies are dark web projects, these days.
You only need to have a business entity (which, to be fair, can be yourself, although liability concerns apply) once you're about to actually enter into a contract with someone.
Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone. It would however 1) deter requests for unpaid work by giving them an idea of what it would cost to get what they're looking for and 2) give you an idea of the demand for said services and could give you a warm lead which you can then choose to pursue formally by getting the necessary business structure, legal/business advice, etc.
Rings a bell, I think it was because Curl showed up as the user agent for malicious activity.
You have to be kind of lost to contact Daniel about it, but I think it's ok behaviour for junior sysadmins that are just starting out, everyone was starting out sometime, and curl is like a lightning catcher for the world's daily lucky thousand.
It's because curl is often embedded as a library or standalone executable with other software. So when a malicious or compromised piece of software is found, a less experienced investigator might see curl with its author tags in the file metadata, and follow it back to upstream.
Back in the late 2000s when I was just becoming an adult, but still talking to people younger than me on the web, I knew this kid who was maybe 16, he bought a very offensive domain, we were big on 4chan shenanigans (I'll let you imagine the worst thing). I had to intervene when I realized and point out to him, that his first and last name can be looked up by anyone, anywhere, and his address. He started to panic and I forget what we even did, but I think I immediately told him to just change the first and last to literally anything else, find a valid plausible address and adjust it, and just basically abandon the account as soon as possible. Been quite a while since I ever spoke to them, hope they learned their lesson.
The dumb careless things that teens do on the web.
In the UK a few decades ago, if you found a radiosonde from a weather balloon, it would have instructions on how to claim a recovery fee if you returned it for reuse. Sadly I never found one, but I knew this because my dad was a geophysicist and we lived at the time on a Scottish island which was one of the UK's launch spots. Looks like the recovery fee was stopped a long time ago, when the devices became cheap enough to be effectively disposable.
Slightly unrelated but I have no idea how wind speed predictions are made up high in the altitudes, is it just interpolation of data that are get from various radiosonoids across various timestamps and finding a regular or seasonal pattern?
As I understand it, it's a combination of things: aircraft reports, atmospheric motion vectors (e.g. a cloud doesn't have any propulsion, so if a cloud moves 30 km in an hour, you have learned something about the wind), Doppler wind lidar, and satellite measurements.
The numerical predictions of weather models often have many vertical components as well, so solving it for ground level also requires extending the forecast to the air, depending on the model.
To predict anything on the ground, you have to predict air temperature, humidity, wind speed and direction etc. for the entire troposphere. The output of the models in altitude are as relevant to the meteorologists as the output on the ground for manual expert analysis.
Generally at altitude the wind goes from west to east. During the Cold War the US would launch spy balloons to overfly Russia whilst the wind was blowing against the Russians reciprocating. This is generally true in the current Ukraine war too.
There are of course several different global weather models that predict the behavior of the atmosphere, and it is a lot more complicated than just interpolating past data. But they all do rely on radiosonde data for daily calibration of actual atmospheric conditions.
I've only read the first few paragraphs but I've noticed a narrative issue. I might be the only person to have this peeve, but when introducing a story to non technical and even technical readers, it's always clearer to introduce which website is not theirs and which website is theirs. It's written in a 3rd person perspective that doesn't take ownership of the websites.
"Only Melbourne and Adelaide radiosondes (the transmitter on weather balloons) were being tracked on a website called Habhub - high altitude ballooning hub."
Ok, I can infer that habhub probably isn't the speaker's website.
"A query parameter could be added to the URL to remove the filter and on 12th of May 2018 sondehub.org registered with a single purpose - a URL redirect to Habhub with a radiosonde specific filter."
Ok, I can infer sondehub was set up by a jokey duo or group of weather balloon hobbyists.
But it's really annoying reading and doubting this because I'm not 100% sure that the speaker is actually the domain creator of sondehub.
You can say "we registered sondehub" or "I registered sondehub.org." Poor journalists use this passive voice sometimes. "Something happened. A source said..." Unless you're protecting a source, you can say who said what, and what caused something to happen.
Right, it's a small little intro that goes a long way.
I checked the habhub website and found this blurb:
"habhub is the home of high altitude ballooning tools developed by UKHAS, and the SondeHub team. The habitat database was retired in 2022, replaced by the SondeHub database and tracker."
This intro was also quite helpful, which I found on the Sondehub github page:
"SondeHub started out in 2019 as a database and mapping system for tracking meteorological radiosondes. It's hosted in Amazon Web Services, so it is scalable and reliable (though does cost more to run...). SondeHub is run by a small team lead by x, y and is currently funded through Patreon Sponsors and a grant from Amateur Radio Digital Communications. SondeHub handles many millions of radiosonde telemetry packets a day, with telemetry contributed by over 700 unique receiver stations."
I didn't include the names because it wasn't the purpose of the comment, just a nice way to introduce the story.
I understand that the habhhub shutdown is part of the story that they later reveal, and now folded into/adapted into Sondehub:
"HabHub, the Habitat database, and associated utilities have been hosted on a server donated by Nevis (name) since 2011. However, due to ongoing issues with server maintenance and rising power prices, continued hosting has become untenable. In addition to this, the software behind the Habitat servers has become extremely difficult to maintain, and a very large amount of work would be required to port it to a more modern operating system."
> Meanwhile (and you might have noticed me asking for AWS help on fedi) we contacted AWS as the source IP was from an AWS network. It was very important however to make sure the AWS support did not shutdown access.
I'm legitimately impressed that whoever got that ticket on AWS side actually followed through and was able to divert from their script...
When AWS suspects malicious usage in my experience they usually ask before shutting you down.
The company I work at got one of these emails from AWS. We had a bug which caused us to hit a 3rd party API much more than we should have, and the service provider reported us to AWS for attempted DDoS. AWS just asked us to give our side of the story. I'm sure that being a large (but not enterprise) customer gives us some leeway, but I've also heard similar things from hobbyists.
There are exceptions if you are a fairly new account, or if you operate in certain low reputation regions. Specifically I have heard regions in Africa tend to get the "shoot first ask questions later" treatment from AWS Support.
However, all of this was before 2026 (when AWS Support seems to have 100% turned over to AI). For all I know their actions might look completely different now.
I was one of the data points in that spike related to the Chinese balloon incident though that is not the first time I used sondehub. A couple years before that incident I found the site while trying to help someone understand what they were seeing in the sky near where they live.
An old dopehead, friend-of-a-friend was paranoid that they were being surveilled by aliens in UFOs, something they could assure you had been happening since the 1970's. Not coincidentally I'm sure, that's when they were a young dopehead. While outwardly funny to most of us, it was a serious issue for them. To help them understand all the shiny things in the sky at night I assembled a list of tools that could help them rule out various terrestrial sources for the shiny things. Stellaris or Celestia could help them identify stars and constellations, even showing them what the sky should look like at their exact location so they could compare in real time. They could also use their digital camera (after instructions on how to take low light photos that show stars) to take photos and later compare those photos to stars and planets that would've been visible when the photo was taken. I pointed them at Flightradar24 and FlightAware for air traffic and recommended they get a license instead of the free version so they could track more things better. They weren't close to an active military base but using either or both of those could help rule out military air traffic when the pilots were flying and broadcasting ADS-B.
Since many UFOs in the historical record were blamed on weather balloons I looked around for a way to find weather balloons visible in your area and that is when I found sondehub. The ability to see the balloon track was especially useful since I explained how objects at high altitudes could be visible even if they are hundreds of miles distant when you have a clear line of sight so the balloon doesn't need to be between them and the horizon. It only needed to be visible above the horizon and using the tools they could rule out quite a few things. Around the same time people were posting great photos of sprites associated with powerful thunderstorms well over the horizon so this helped them understand that shiny things in the sky are not necessarily close to them. I also used HeavensAbove to help them track known satellites and the ISS. Having them see the ISS cross the sky at their location a little after dark helped them understand why a bright light crossing the sky can quickly disappear once the concept of the earth's shadow was clear. It was nice and bright while sunlit and winked out as soon as it passed into shadow. I gave them links to astronomy sites so they could know when to expect meteor showers and other celestial phenomena.
All in all, they got a nice collection of tools, freely available, that they could use to understand why there were sparkly, shiny things in their sky. I haven't yet had confirmation that any of those sparkly, shiny things could not be explained using those tools.
The author’s concern about keeping the infrastructure decentralized is pretty understandable, not just from a censorship/open-data perspective, but also from a security perspective: you don't want one server, or one person, to become an obvious target.
FlightAware (ADSB) and MarineTraffic (AIS) systems hide data upon request too. Which is why it's important that citizen scientists run there own receivers.
Worked on a very basic level with my Logi webcam, but couldn't get it to detect my MX Master 4 despite a few attempts. A shame, I'd love to escape Logi+ for a feature-parity solution.
>Fuck. And Fuck Russia. (for time travellers and people in the future - in 2022 started a “special military operation” - aka a full scale invasion into Ukraine. The war continues at time of writing. Fuck Russia)
>In 2025 we received a request for data from the “Office of the Secretary of War (Intelligence and Security)” (US). Generally if there’s mutual community benefit we’ll find, process and release the data for free. However given this is was the Department of War and no expected community benefit we decided they should pay for the data. I was hesitant even working with them, as I don’t really want to help military, let alone the US - but since our data is public if we didn’t do it someone else probably would. So my reasoning shifted to, may as well extract some funds to pay for SondeHub infrastructure at the very least.
such a seamless transition from moral absolutism to moral relativism ;-)
What makes you think they are being absolutist when saying fuck Russia? You can disapprove of an unprovoked invasion from many, many ethical perspectives without going near absolutism.
I don't really see them saying fuck the US, even though they've bombed girls schools in Iran.
Or saying fuck Israel because of their super well documented ongoing genocide.
"You can disapprove of ... from many, many ethical perspectives without going near absolutism."
Did they find evidence of their service being used to bomb schools in Iran, like they found for Russia tracking launch sites in Ukraine?
If not, then why would they go on such a tangent? Do you expect them to list every one of their personal geopolitical stances, regardless of the relevance to the article?
> Official response from Meteolabor AG: For strategic reasons, we do not provide any data or sample devices. Our transmitters shut down after a certain period of time, at the latest when the battery capacity is exhausted. This is due, among other things, to strategic considerations.
>We are aware of the so-called waste problem.
>Personal comment: I would personally like to draw attention to military activities, particularly in the Middle East, which result in significantly (exponentially) more waste and toxic substances being released into the atmosphere and left lying around in the environment – or entering the food and water cycles
>In addition to military operations, countless “missions” are currently being flown over Europe with the aim of leaving “contrails” in the sky [rather “chemtrails”]. I know their purpose; I know what NetZero is supposed to achieve, and what decarbonization and CO2 reduction are intended to accomplish. I am well-informed about the climate hoax.
>Start there! The people to talk to are politicians, NGOs, and very wealthy old white men.
I wonder who at the company wrote that? Paul Klöti? Rolf Maag? Elisabeth Ruppert-Bolliger? Walter Büchler? Andreas Kräuchi?
You know. I came to that conclusion when they started shootings rockets at a civilian airplane in 2014, killing 298 civilians of which 196 people that I share citizenship with.
One of the fun things on sondehub is you can provide live location data on yourself going to pick up the balloon. And report whether or not you were successful so others don't try to collect those already claimed
Yeah back in 2022, I had just found my voice and developed a speaking style able to inspire understanding and articulate complex concerns down to simple concepts.
I used that to convey the idea that a certain spy agency was a terrorist group (by how they were operating) and were using accounts, with said very accounts visible in many of the instagram threads I was commenting in, being astro turf to sway certain opinions and do psyops on the American people. I got thousands of up votes and engagement.
Safe to say, I was naive, and it was terrifying to have them follow up and send investigators into private and public spaces. I had terror follow me from this time but I'm alive so glad that I wasn't enough of a threat to exterminate. Suppose I can thank either this was entirely made-up, or I was cautious enough after this incident (though I keep making the embarrassing mistake of sharing posts like this on hacker news and getting the occasional "You're crazy" accusation and ad hominem style credibility attacks). Who knows what really happened. I can't dismiss the possibility as 0%.
Edit: Thing is when you have an expert who's job it is to act sane and credible, operating to remain in stealth and hide their behavior, any accusation to call them out as so is met with a rational response to call out the veil-piercing observations as incredulous. And who's going to spy on the spy, would you look to gather evidence and record your interactions, send in a spy tape recorder, etc lol.
"as I don’t really want to help military, let alone the US"
Yet the Australian author so passionately and strongly curses Russia, as if some magical fairy keeps huge portions of the world at calm. I wonder if the AUSTRALIAN author understands what would happen the day the US navy left Oceania.
I found the cognitive dissonance interesting between emailing AWS support about the Ukrainian war effort: "it is incredibly important that the source AWS account is not blocked, rate limited or terminated - loss of life could occur.", then a paragraph later: "I was hesitant even working with them, as I don’t really want to help military, let alone the US."
This was fascinating, thank you. I expected to read about legal threats against the folks collecting this data and am glad that those didn't materialize.
Also I only realized after finishing the article what a breath of fresh air it was to read something that came straight from another human's brain without LLM intermediation. Thank you to the author for that too.
>I expected to read about legal threats against the folks collecting this data and am glad that those didn't materialize.
That's because the author folded over and played nice. Imagine if he exercised his first amendment rights.
They are Australian. Don't everyone is from the US just because they speak English.
It's fun to see habhub in an article. ~10 years ago a group of friends and I launched 2 weather balloons for fun with a GPS logger, APRS transmitter, and a few sensors, and then retrieved it afterwards.
I have a bunch of memorable experiences from it, including:
1. Under inflating the first balloon because our helium provider was closed, and instead buying lower pressure "party" balloon containers (and not realizing until too late that lower pressure meant more helium left in the containers)
2. Chasing down the balloon at night and trying to explain why you wanted to walk onto some guys field to check for a weather balloon
3. Later calling a gas station to ask if "some guy just arrived with a weather balloon in their truck" when trying to track down the balloon
If anyone has kids and wants a fun project, I highly recommend it. There are a few companies online that sell kits, and it's neat to watch the different layers of the atmosphere (temperature and wind), and try to "chase" after the balloon and find it afterwards.
Can you “just do this” or is there some preapproval you’re meant to get beforehand? Presumably the answer varies wildly by jurisdiction.
We did it in the US, and filed a NOTAM with the FAA. The hardest part was figuring out how to convert what I had (we are launching a weather balloon from X, Y coords at Z time) to what they wanted (distance, direction, etc from nearest air tower). It's just a phone number you call, and they were pretty friendly (helping convert my lat / lng to what they needed).
There are rules you have to understand and follow, notifications required but no approvals if you meet certain criteria. It's mostly an FAA thing in the US, so one jurisdiction.
Were you able to find the balloon? Your last point has me wondering what happened. Did someone else get to it first?
Yup. We were able to find it both times. First time it "floated" and traveled further than we expected (at one point habhub predicted it to land in Africa). This is the one we called a gas station about, and we did end up getting it back. Second time was cleaner, and we drove up someone's driveway, and asked if we could retrieve it.
We had to move our launch site from where we originally wanted as 3 out of 3 predictions showed our landing site to be on an Air Force base. While I was willing to climb a barbed wire fence way out in the middle of nowhere, a fence around a base was not something I could see myself doing. I also didn't want to end up in a news story for causing military alerts. It was surprising just how far we had to go outside of the city to have it land in a spot that we'd be able to retrieve it.
I had this idea before of sending ballons to "the space" with a collectible object and then retrieve them, saying "I have this specific object that was in space too". Is it possible or am I dreaming too much?
People do that routinely-ish.
https://www.youtube.com/live/Let4NxZRnMA
For reasonable definitions of "in space" doesn't really cut it. Balloons top out at around 120,000ft unless you're getting super exotic, and that'll only get you another 20k ft or so. Not even out of the stratosphere. Not space by any reasonable definition.
About the lowest thing that could reasonably be called space is the Karmin line, and that's at 100km, or 330,000ft.
Depending on your definition of space, this is what the Earth To Sky does to finance their helium balloons runs: https://www.earthtosky.store/about. I got a pendant for my partner, it was a nice gift.
Your username betrays you, because this is indeed a good idea. Thank you for sharing! I'd never heard of this, but now have some cool gift ideas for family & friends. :)
Lego did a video of that, they sent one of their space stations sets. I'm quite sure they glued it.
We did a similar thing, only we intentionally made it more difficult on ourselves by launching at sunset because we were hoping to grab the view of city lights at night with the GoPros. Also, we did not have any licensed radio operators in our group, so no fun equipment like that. We instead depended on a consumer GPS tracker that updated once ever 5 minutes. We also had an Arduino with various sensors attached, but that was for me as the main purpose was the video footage.
Some of the memorable experiences from it:
1) Purchasing equipment to do a Hydrogen launch because this was during a Helium shortage and the cost difference was significant. Arrived at store to pick up our Hydrogen tank where the guy working took a look at us knuckleheads and had serious reservations about selling us inexperienced dorks Hydrogen. Took pity on us and swapped out all of our fittings (hydrogen fittings are specific to prevent accidental use of hydrogen) and sold us the tank of Helium for a much cheaper price than what we were originally told.
2) Printing up stickers to attach to the payload box with "If Found" contact instructions only to realize one second after letting go of the payload that you forgot to attach said stickers.
3) The terror of realizing that when the balloon took off that it immediately headed west when the flight predictions you had been running for the previous days before all showed the balloon landed east.
4) Having to contact ATC to report the launch of the balloon, only to be told they needed further updates at every 10,000' feet.
5) The terror setting in deeper when the consumer GPS unit stopped responding after 30,000' altitude and then having ATC scold how unprofessional we were for using cheap devices. At least they told us they were still tracking it.
6) The shenanigans a group of knuckleheads got up to waiting the ~3 hours for the balloon to land.
7) The relief when the consumer GPS unit started pinging updates again on the way down and the laugh (with us not at us) from ATC that we could start reporting back again.
8) Using mobile Google Maps to attempt to find the GPS location. Wandering around fields in the middle of the night to find a strange circular pattern of out of place plants to realize it was from a deer feeder's throw. Then searching for the nearby camera trap to wave to leave some hunter with serious WTF.
9) Nearly giving up on the search until deciding to use the hotspot to look up the GPS coordinates not on a mobile device to see that the balloon was less than 300' from where we parked making the hours spent wandering really dumb.
That's incredible.
> The terror setting in deeper when the consumer GPS unit stopped responding after 30,000' altitude
Ah yes, the CoCom export control limits so you can't use it to build an ICBM. Legally they're supposed to stop working above 60,000 ft and 1,200 mph, but some manufacturers interpret that as an "or". The rumor was that some really cheap chips out of China failed to implement either, so if you'd bought a crappier gps module, you might have been fine!
That's an awesome story tho!
Can you recommend any kits? Out sounds like an extremely fun hobby.
I am part of the team which runs the OpenStreetMap.org infrastructure, we also get a lot of weird and wonderful requests / emails. .mil, .gov, .edu and GeoTLD variants.
I should really do a write-up sometime.
I encourage you to make it! That sounds like it could be a really fun read.
I remember being in Tel Aviv for work, and pulling up maps to plot out a bike route from the hotel to the office. Only to find that the entire route is blurred out online. Turns out our office was a few 100 meters from something important to the IDF, so no map/route data available. Too far to reasonably walk, and didn't want to try a bike without knowing there was a reasonable route...
"Our transmitters shut down after a certain period of time, at the latest when the battery capacity is exhausted. This is due, among other things, to strategic considerations."
Among other things. And this was the most sane part of Meteolabor's email
If the transmitters continued to operate after battery exhaustion, then I may begin to question the laws of physics, as well as my life choices
They just have access to classified physics and definitions of energy most people don’t have.
Does the title mean, "...turned into..."?
That is, should it be "A joke domain purchase turned into geopolitical warfare"
Anyway, fascinating reading.
Yeah the title reads quite weird, but I would think “turned up” instead of “turned into”. The domain didn’t cause geopolitical war after all.
The part where he gets contacted over the hit-and-run reads like the curl guy’s experience with people investigating “hacking”.
I wonder how often this happens outside of software? Do fence manufacturers get emails asking to identify the culprit when someone crashes through a fence?
I feel like it's a "cast a wide net" type of strategy. Doesn't really hurt to ask and there _could_ be the tiniest hint that could lead to something. Maybe?
In my first law class the prof said, "When it doubt, sue everybody."
Actually, it wasn't unreasonable. If the guy caused the damage while picking up a sonde, to know who's sonde it was would help identify the culprit.
Fair, I guess, I just can’t imagine what it’s like getting all these weird requests and demands for a hobby project. Hopefully the author is more entertained than I would be.
Not a lawyer but as a citizen I generally understand that the courts expect demands from court parties to be met.
If meeting the court's (or court parties') demands costs you something you are generally entitled to charge them for it, within reason and with justification.
As a hobbyist therefore putting a service offering page together with your preferred rate probably helps establish the nature and parameters of any such service.
Bill rates / piece rates, especially, and setting up bounds of what is reasonable to expect, in proportion to your gig and your intended effort level.
Quantity and price tiers, turnaround times, what will be included in the deliverable, how it will be delivered, SLAs, etc.
Whatever defines your service, esp as it relates to the types of requests you end up getting.
If I start listing prices, I may need to ensure that I have a business entity set up for tax purposes and to guard against liability. Especially if I’m listing SLAs.
This is not a hobby, it’s a job.
This is why all my hobbies are dark web projects, these days.
You only need to have a business entity (which, to be fair, can be yourself, although liability concerns apply) once you're about to actually enter into a contract with someone.
Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone. It would however 1) deter requests for unpaid work by giving them an idea of what it would cost to get what they're looking for and 2) give you an idea of the demand for said services and could give you a warm lead which you can then choose to pursue formally by getting the necessary business structure, legal/business advice, etc.
Or maybe the sonde continued transmitting and they have data on where the guy took it which would help ID him.
Rings a bell, I think it was because Curl showed up as the user agent for malicious activity.
You have to be kind of lost to contact Daniel about it, but I think it's ok behaviour for junior sysadmins that are just starting out, everyone was starting out sometime, and curl is like a lightning catcher for the world's daily lucky thousand.
It's because curl is often embedded as a library or standalone executable with other software. So when a malicious or compromised piece of software is found, a less experienced investigator might see curl with its author tags in the file metadata, and follow it back to upstream.
Back in the late 2000s when I was just becoming an adult, but still talking to people younger than me on the web, I knew this kid who was maybe 16, he bought a very offensive domain, we were big on 4chan shenanigans (I'll let you imagine the worst thing). I had to intervene when I realized and point out to him, that his first and last name can be looked up by anyone, anywhere, and his address. He started to panic and I forget what we even did, but I think I immediately told him to just change the first and last to literally anything else, find a valid plausible address and adjust it, and just basically abandon the account as soon as possible. Been quite a while since I ever spoke to them, hope they learned their lesson.
The dumb careless things that teens do on the web.
How did they pivot from just providing a redirect to
> we decided to start proxying radiosonde ingestion data through SondeHub
Redirecting to the habhub UI doesn't seem like it would also let them intercept people uploading their data to habhub.
I like how a website for tracking balloons escalated into critical infrastructure. Reminds me of 99 Red Balloons.
https://en.wikipedia.org/wiki/99_Luftballons
In the UK a few decades ago, if you found a radiosonde from a weather balloon, it would have instructions on how to claim a recovery fee if you returned it for reuse. Sadly I never found one, but I knew this because my dad was a geophysicist and we lived at the time on a Scottish island which was one of the UK's launch spots. Looks like the recovery fee was stopped a long time ago, when the devices became cheap enough to be effectively disposable.
reminds me of keys/badges with "drop in any mailbox" instructions that recover them.
Slightly unrelated but I have no idea how wind speed predictions are made up high in the altitudes, is it just interpolation of data that are get from various radiosonoids across various timestamps and finding a regular or seasonal pattern?
As I understand it, it's a combination of things: aircraft reports, atmospheric motion vectors (e.g. a cloud doesn't have any propulsion, so if a cloud moves 30 km in an hour, you have learned something about the wind), Doppler wind lidar, and satellite measurements.
The numerical predictions of weather models often have many vertical components as well, so solving it for ground level also requires extending the forecast to the air, depending on the model.
To predict anything on the ground, you have to predict air temperature, humidity, wind speed and direction etc. for the entire troposphere. The output of the models in altitude are as relevant to the meteorologists as the output on the ground for manual expert analysis.
Generally at altitude the wind goes from west to east. During the Cold War the US would launch spy balloons to overfly Russia whilst the wind was blowing against the Russians reciprocating. This is generally true in the current Ukraine war too.
Some interesting links:
https://www.hisutton.com/US-Navy-CIA-Submarine-Launched-Spy-...
https://www.hisutton.com/Chinese-Navy-High-Altitude-Spy-Ball...
https://m.youtube.com/watch?v=iD6XaaO9bEo
Not just wind speed, but all kinds of weather data can be extracted from radiosonde recordings. The data output is called a Skew-T Log-P graph. Some examples of how to interpret them at https://www.weather.gov/source/zhu/ZHU_Training_Page/convect...
There are of course several different global weather models that predict the behavior of the atmosphere, and it is a lot more complicated than just interpolating past data. But they all do rely on radiosonde data for daily calibration of actual atmospheric conditions.
I've only read the first few paragraphs but I've noticed a narrative issue. I might be the only person to have this peeve, but when introducing a story to non technical and even technical readers, it's always clearer to introduce which website is not theirs and which website is theirs. It's written in a 3rd person perspective that doesn't take ownership of the websites.
"Only Melbourne and Adelaide radiosondes (the transmitter on weather balloons) were being tracked on a website called Habhub - high altitude ballooning hub."
Ok, I can infer that habhub probably isn't the speaker's website.
"A query parameter could be added to the URL to remove the filter and on 12th of May 2018 sondehub.org registered with a single purpose - a URL redirect to Habhub with a radiosonde specific filter."
Ok, I can infer sondehub was set up by a jokey duo or group of weather balloon hobbyists.
But it's really annoying reading and doubting this because I'm not 100% sure that the speaker is actually the domain creator of sondehub.
You can say "we registered sondehub" or "I registered sondehub.org." Poor journalists use this passive voice sometimes. "Something happened. A source said..." Unless you're protecting a source, you can say who said what, and what caused something to happen.
So I stopped reading, and wrote this comment.
I think the author isn't a native English speaker? Either that or the writing is just a bit confusing at times, a lot of sentence fragments.
> We poke their website to see - sure enough they are - an angry email to them.
In general it was easy enough to understand the stories, though
Right, it's a small little intro that goes a long way.
I checked the habhub website and found this blurb: "habhub is the home of high altitude ballooning tools developed by UKHAS, and the SondeHub team. The habitat database was retired in 2022, replaced by the SondeHub database and tracker."
This intro was also quite helpful, which I found on the Sondehub github page:
https://github.com/projecthorus/sondehub-amateur-tracker/wik...
"SondeHub started out in 2019 as a database and mapping system for tracking meteorological radiosondes. It's hosted in Amazon Web Services, so it is scalable and reliable (though does cost more to run...). SondeHub is run by a small team lead by x, y and is currently funded through Patreon Sponsors and a grant from Amateur Radio Digital Communications. SondeHub handles many millions of radiosonde telemetry packets a day, with telemetry contributed by over 700 unique receiver stations."
I didn't include the names because it wasn't the purpose of the comment, just a nice way to introduce the story.
I understand that the habhhub shutdown is part of the story that they later reveal, and now folded into/adapted into Sondehub:
"HabHub, the Habitat database, and associated utilities have been hosted on a server donated by Nevis (name) since 2011. However, due to ongoing issues with server maintenance and rising power prices, continued hosting has become untenable. In addition to this, the software behind the Habitat servers has become extremely difficult to maintain, and a very large amount of work would be required to port it to a more modern operating system."
This really escalated amusingly. Some things just write themselves.
> Meanwhile (and you might have noticed me asking for AWS help on fedi) we contacted AWS as the source IP was from an AWS network. It was very important however to make sure the AWS support did not shutdown access.
I'm legitimately impressed that whoever got that ticket on AWS side actually followed through and was able to divert from their script...
Ditto. My experience with AWS support has been generally disappointing.
You just have to project life and death into your request and bobs your uncle!
When AWS suspects malicious usage in my experience they usually ask before shutting you down.
The company I work at got one of these emails from AWS. We had a bug which caused us to hit a 3rd party API much more than we should have, and the service provider reported us to AWS for attempted DDoS. AWS just asked us to give our side of the story. I'm sure that being a large (but not enterprise) customer gives us some leeway, but I've also heard similar things from hobbyists.
There are exceptions if you are a fairly new account, or if you operate in certain low reputation regions. Specifically I have heard regions in Africa tend to get the "shoot first ask questions later" treatment from AWS Support.
However, all of this was before 2026 (when AWS Support seems to have 100% turned over to AI). For all I know their actions might look completely different now.
I was one of the data points in that spike related to the Chinese balloon incident though that is not the first time I used sondehub. A couple years before that incident I found the site while trying to help someone understand what they were seeing in the sky near where they live.
An old dopehead, friend-of-a-friend was paranoid that they were being surveilled by aliens in UFOs, something they could assure you had been happening since the 1970's. Not coincidentally I'm sure, that's when they were a young dopehead. While outwardly funny to most of us, it was a serious issue for them. To help them understand all the shiny things in the sky at night I assembled a list of tools that could help them rule out various terrestrial sources for the shiny things. Stellaris or Celestia could help them identify stars and constellations, even showing them what the sky should look like at their exact location so they could compare in real time. They could also use their digital camera (after instructions on how to take low light photos that show stars) to take photos and later compare those photos to stars and planets that would've been visible when the photo was taken. I pointed them at Flightradar24 and FlightAware for air traffic and recommended they get a license instead of the free version so they could track more things better. They weren't close to an active military base but using either or both of those could help rule out military air traffic when the pilots were flying and broadcasting ADS-B.
Since many UFOs in the historical record were blamed on weather balloons I looked around for a way to find weather balloons visible in your area and that is when I found sondehub. The ability to see the balloon track was especially useful since I explained how objects at high altitudes could be visible even if they are hundreds of miles distant when you have a clear line of sight so the balloon doesn't need to be between them and the horizon. It only needed to be visible above the horizon and using the tools they could rule out quite a few things. Around the same time people were posting great photos of sprites associated with powerful thunderstorms well over the horizon so this helped them understand that shiny things in the sky are not necessarily close to them. I also used HeavensAbove to help them track known satellites and the ISS. Having them see the ISS cross the sky at their location a little after dark helped them understand why a bright light crossing the sky can quickly disappear once the concept of the earth's shadow was clear. It was nice and bright while sunlit and winked out as soon as it passed into shadow. I gave them links to astronomy sites so they could know when to expect meteor showers and other celestial phenomena.
All in all, they got a nice collection of tools, freely available, that they could use to understand why there were sparkly, shiny things in their sky. I haven't yet had confirmation that any of those sparkly, shiny things could not be explained using those tools.
Thanks for this link.
The author’s concern about keeping the infrastructure decentralized is pretty understandable, not just from a censorship/open-data perspective, but also from a security perspective: you don't want one server, or one person, to become an obvious target.
2 is 1, one is none. I hope they do regular backups too.
FlightAware (ADSB) and MarineTraffic (AIS) systems hide data upon request too. Which is why it's important that citizen scientists run there own receivers.
> Meteolabor AG
> climate hoax
Once again, the Swiss are confirming their image as the most US-like country in Europe :'(
Worked on a very basic level with my Logi webcam, but couldn't get it to detect my MX Master 4 despite a few attempts. A shame, I'd love to escape Logi+ for a feature-parity solution.
I'm afraid you're in the wrong thread
Interacting with the public is the most exciting yet frightening aspect of any public project.
There are always flashes of brilliance but it's hard to see them when wading through the vitriol.
Someone needs to option this for a book or movie. I’d read it!
>Fuck. And Fuck Russia. (for time travellers and people in the future - in 2022 started a “special military operation” - aka a full scale invasion into Ukraine. The war continues at time of writing. Fuck Russia)
>In 2025 we received a request for data from the “Office of the Secretary of War (Intelligence and Security)” (US). Generally if there’s mutual community benefit we’ll find, process and release the data for free. However given this is was the Department of War and no expected community benefit we decided they should pay for the data. I was hesitant even working with them, as I don’t really want to help military, let alone the US - but since our data is public if we didn’t do it someone else probably would. So my reasoning shifted to, may as well extract some funds to pay for SondeHub infrastructure at the very least.
such a seamless transition from moral absolutism to moral relativism ;-)
What makes you think they are being absolutist when saying fuck Russia? You can disapprove of an unprovoked invasion from many, many ethical perspectives without going near absolutism.
I don't really see them saying fuck the US, even though they've bombed girls schools in Iran. Or saying fuck Israel because of their super well documented ongoing genocide.
"You can disapprove of ... from many, many ethical perspectives without going near absolutism."
Did they find evidence of their service being used to bomb schools in Iran, like they found for Russia tracking launch sites in Ukraine?
If not, then why would they go on such a tangent? Do you expect them to list every one of their personal geopolitical stances, regardless of the relevance to the article?
Unprovoked.. Putin woke up one day and decided to roll in the tanks. Got it.
You seem to be mixing up the words "planned" and "provoked" here.
It makes me laugh also. « It's bad except when it's our side »
> Official response from Meteolabor AG: For strategic reasons, we do not provide any data or sample devices. Our transmitters shut down after a certain period of time, at the latest when the battery capacity is exhausted. This is due, among other things, to strategic considerations.
>We are aware of the so-called waste problem.
>Personal comment: I would personally like to draw attention to military activities, particularly in the Middle East, which result in significantly (exponentially) more waste and toxic substances being released into the atmosphere and left lying around in the environment – or entering the food and water cycles
>In addition to military operations, countless “missions” are currently being flown over Europe with the aim of leaving “contrails” in the sky [rather “chemtrails”]. I know their purpose; I know what NetZero is supposed to achieve, and what decarbonization and CO2 reduction are intended to accomplish. I am well-informed about the climate hoax.
>Start there! The people to talk to are politicians, NGOs, and very wealthy old white men.
I wonder who at the company wrote that? Paul Klöti? Rolf Maag? Elisabeth Ruppert-Bolliger? Walter Büchler? Andreas Kräuchi?
Yeye, bestof fuel. Ty so much for that read.
> Fuck Russia
You know. I came to that conclusion when they started shootings rockets at a civilian airplane in 2014, killing 298 civilians of which 196 people that I share citizenship with.
And fuck Germany for still buying Russian gas.
https://en.wikipedia.org/wiki/Iran_Air_Flight_655 US govt never apologized.
The difference is that the US didn't start that war.
Dude , were you actually able to find the balloon though ?
One of the fun things on sondehub is you can provide live location data on yourself going to pick up the balloon. And report whether or not you were successful so others don't try to collect those already claimed
Yeah back in 2022, I had just found my voice and developed a speaking style able to inspire understanding and articulate complex concerns down to simple concepts.
I used that to convey the idea that a certain spy agency was a terrorist group (by how they were operating) and were using accounts, with said very accounts visible in many of the instagram threads I was commenting in, being astro turf to sway certain opinions and do psyops on the American people. I got thousands of up votes and engagement.
Safe to say, I was naive, and it was terrifying to have them follow up and send investigators into private and public spaces. I had terror follow me from this time but I'm alive so glad that I wasn't enough of a threat to exterminate. Suppose I can thank either this was entirely made-up, or I was cautious enough after this incident (though I keep making the embarrassing mistake of sharing posts like this on hacker news and getting the occasional "You're crazy" accusation and ad hominem style credibility attacks). Who knows what really happened. I can't dismiss the possibility as 0%.
Edit: Thing is when you have an expert who's job it is to act sane and credible, operating to remain in stealth and hide their behavior, any accusation to call them out as so is met with a rational response to call out the veil-piercing observations as incredulous. And who's going to spy on the spy, would you look to gather evidence and record your interactions, send in a spy tape recorder, etc lol.
What?
"as I don’t really want to help military, let alone the US"
Yet the Australian author so passionately and strongly curses Russia, as if some magical fairy keeps huge portions of the world at calm. I wonder if the AUSTRALIAN author understands what would happen the day the US navy left Oceania.
Geopolitical warfare can be triggered by much less than that: https://en.wikipedia.org/wiki/Spell_My_Name_with_an_S
This is fiction...
I found the cognitive dissonance interesting between emailing AWS support about the Ukrainian war effort: "it is incredibly important that the source AWS account is not blocked, rate limited or terminated - loss of life could occur.", then a paragraph later: "I was hesitant even working with them, as I don’t really want to help military, let alone the US."