656
submitted 1 week ago by hylobates@jlai.lu to c/memes@lemmy.world
top 50 comments
sorted by: hot top new old
[-] undefinedTruth@lemmy.zip 197 points 1 week ago* (last edited 1 week ago)

Anubis is open source, self-hosted, doesn't block me just because I use a VPN and the later versions work even with JavaScript disabled!

Fuck Cloudflare, long live Anubis!

[-] ReginaPhalange@lemmy.world 21 points 6 days ago

How exactly is a proof of work engine suppose to run, without any JS work?

[-] idunnololz@lemmy.world 36 points 6 days ago
[-] daniskarma@lemmy.dbzer0.com 6 points 6 days ago

That's just protection by obscurity then. Any targeted attack could do that challenge at zero cost.

[-] jj4211@lemmy.world 3 points 6 days ago

Seems utterly pointless though...

With the proof of work approach, at least it's demanding the client consume some resources, though the 'right' amount is a tricky question, either it's so trivial as to hardly matter to the scrapers, or it's hard enough to put a dent in the scrapers' build, but human operated low end devices are royally screwed..

Here the crawler simply schedules a resumption and moves on to other work. The crawler doesn't need it right now and it's free for it to wait.

load more comments (1 replies)
load more comments (1 replies)
[-] mecen@lemmy.ca 1 points 5 days ago

Cloudflare is great compared to Recaptcha.

Anubis is the best by far.

[-] mecen@lemmy.ca 41 points 6 days ago

Much better than cludflare and Google recapha

[-] FalschgeldFurkan@lemmy.world 64 points 6 days ago

Her face is the response to years of enshittification; without her, the modern browsing experience would suck much harder. Glory to Anubis!

[-] Gonzako@lemmy.world 36 points 6 days ago
[-] pewpew@feddit.it 35 points 6 days ago
[-] daniskarma@lemmy.dbzer0.com 7 points 6 days ago* (last edited 6 days ago)

Both have different purposes.

The Anubis challenge could be easily and cheapely solved by any JavaScript engine. It only becomes expensive for a massive number of petitions.

If for instance you would want to register a few thousand emails in a forum anubis is not going to stop anyone.

In fact I'm sceptical about really having an impact. As even when the challenge goes up in difficulty is not that expensive compared with all other cost related to these kinds of attacks or massive scrapes.

My suspicion is that most websites using Anubis see a positive impact because most crawlers and probers doesn't take into account Anubis, so they don't even attach a way to solve the challenge and they directly go into the "rejected by anubis" bucket. But any targeted attack I suppose would pass easily, either by doing a slow attack not to up the challenge very much, or just eating the cost. Imagine an AI company that using nuclear plants for training data, the cost of solving a few million JavaScript challenges is nothing in comparison.

As a DDOS mitigation it helps, but once again it's just a matter of eating the cost by the attacker. And the attack will still deny some service as the challenge go up and new legit users would also need to solve harder challenges.

[-] Hupf@feddit.org 5 points 6 days ago

Perry the platypus?

load more comments (1 replies)
[-] trackball_fetish@lemmy.wtf 29 points 6 days ago

+1 Anubis, cloudflare can suck mai balls

[-] HrabiaVulpes@europe.pub 12 points 6 days ago

Looks way better than half the ads I normally see.

[-] GalacticGrapefruit@lemmy.world 16 points 6 days ago

Long live the Canadian anime catgirl!

[-] TerdFerguson@lemmy.world 8 points 6 days ago

Jackal girl.

Anubis weighs the soul of your connection.

load more comments (1 replies)
[-] rants_unnecessarily@piefed.social 10 points 6 days ago* (last edited 6 days ago)

What am I missing to understand this? What is Anubis?

[-] moonshadow@slrpnk.net 33 points 6 days ago

Beloved anti scraping/ddos tool

[-] EchoCranium@lemmy.zip 9 points 6 days ago

I've seen this briefly pop up while looking up linux stuff online recently. Wondered what it was, thank you Lemmy community for some enlightenment!

[-] daniskarma@lemmy.dbzer0.com 7 points 6 days ago

I am skeptical about the real level of protection that Anubis really provides.

At the end is an automated test. Meaning that any machine could easily solve it.

Most "attackers" wont bother solving it because they don't really care. But if they would want they could. It's sort of protection by obscurity.

The more Anubis it's used the more we see attacks that actually equip a way to solve the challenges. Then is when Anubis up the challenge and the battle begin, between how much can Anubis up the challenge so normal users can still browse and how much cost the attacker is willing to eat.

Giving that these attackers tend to have high budgets I'm not that certain about its actual capabilities to reject a targeted ddos.

As for crawling for big data. I do think that it does nothing here. Companies willing yo scrape big amounts of data, for AI training or other purposes, have massive budgets and the electricity cost of solving the JavaScript challenges become nothing in comparison. They also doesn't need ro deny the service so they could spread the scrape to keep the challenge low reducing the cost even more.

Once again, positive results we currently see in practice I believe that are caused just because most scrappers and ddos attackers are just blindly attacking and doesn't really equip themselves for Anubis. Protection by obscurity. But a well equiped attacker I don't think it would have that much trouble getting past it, specially for scrapping, or other type of bot attacks that could be slowed down.

[-] softwarist@programming.dev 12 points 6 days ago

You're right, although my understanding is that there are a lot of poorly implemented scrapers for AI services unintentionally DDoSing websites with requests, so Anubis is more of a mitigation against those.

load more comments (1 replies)
load more comments
view more: next ›
this post was submitted on 28 Apr 2026
656 points (94.8% liked)

memes

21120 readers
2867 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to !politicalmemes@lemmy.world

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/Ads/AI SlopNo advertisements or spam. This is an instance rule and the only way to live. We also consider AI slop to be spam in this community and is subject to removal.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 2 years ago
MODERATORS