Past 1 a.m., I was still revising a quote—then this page made my stomach drop
A while ago I was at home reworking a client proposal. Around 1 a.m., I casually opened a site that lets you watch bots try passwords in real time, and the screen was full of people hammering away at remote login portals. I got stuck on this too: I kept thinking I was too small, and my business was too small, for anyone to bother targeting me.
It is not really security software. It is more like a mirror that makes the risk impossible to ignore
This site shows, live, how bots keep cycling through account names and passwords. For non-technical people, the biggest value is not that it looks cool. It is that it turns an abstract risk into something concrete. Last Wednesday at 9 p.m., in a coworking office in Binjiang, Hangzhou, Lin Lan, who runs a cross-border design outsourcing business, was replying to a client voice message while watching this page. The first thing she said was, “So it is not that I am unlucky. People scanning doors like this are just always out there.” I got this wrong before too. I used to think that if nobody knew my URL, I was safe.
I worked out the cost to copy this today
Money: $0. Time: 10 minutes. Technical barrier: you do not need to code. Just think of it as a demo of how people try to pry open a remote door lock. First step: open the homepage and watch for 5 minutes. Then go back and check whether you have weak passwords, default accounts, or a cloud server with remote login exposed directly to the internet. If you do not have a server right now, this tool is not something everyone needs, and skipping it is totally fine.
If I were at different stages, this is how I would use it
Just starting out: if I were mainly creating content, taking client work, or selling courses, I would treat this as a security wake-up call. After watching it, I would first turn on two-factor authentication for email, cloud storage, and payment platforms.
With 1-2 clients: if I had already started storing client info, quotes, and contracts, I would put a weak-password check on this week’s to-do list instead of waiting until something goes wrong.
Scaling up: if we had cloud servers, outsourced technical help, or a shared admin backend, I would drop this page into the team chat and use it as a 10-minute security alignment piece, then follow up with the most basic permission and login checks.