Anubis rarely ever annoys me (I still prefer it over cloudflare’s Mitm) but this specific visit feels almost vindictive. It used half my CPU cores at full blast for three straight minutes.

It seems to be effective since I can’t really “bypass” it with extensions, so AI crawlers probably can’t either, but damn there really should be an option to complete a manual captcha or email the administrators to complain.

As I’m typing this the challenge is still running xD

  • 1984@lemmy.today
    link
    fedilink
    English
    arrow-up
    4
    ·
    14 hours ago

    I wonder if this even is effective. If a bot can solve anubis challenges, why can’t it solve all difficulties?

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      7
      ·
      6 hours ago

      I’m a server asking with it.

      I went from thousands of requests per minute down to 5. Five. Database was pegged constantly at 100% serving requests down to ~50% now. Huge difference.

    • balsoft@lemmy.ml
      link
      fedilink
      English
      arrow-up
      19
      ·
      10 hours ago

      The point is to make scraping too expensive to be profitable. Even the easy level 4 anubis challenge multiplied by a few million pages becomes very expensive.

      • 1984@lemmy.today
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        10 hours ago

        But once the challenge is completed, they have the token and can scrape until it’s expired right? So if it’s just taking them a bit more time to get the auth token, what is it solving?

        Example: the token lasts for a week and it takes 30 seconds to get the token.

        • OhNoMoreLemmy@lemmy.ml
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          2 hours ago

          I would assume the token is only good for a few page accesses.

          E.g. 500 would mean that a person would see this extremely rarely, and still block a bot from crashing the site.

          • 1984@lemmy.today
            link
            fedilink
            English
            arrow-up
            3
            ·
            10 hours ago

            No it actually lasts for a long time. We have it on my Lemmy instance for https://old.lemmy.today/ and it’s generated once and lasts for many days, probably a week. I guess it’s configurable but if you generate it too often, your visitors will also be annoyed.

        • Axolotl@feddit.it
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          9 hours ago

          It will still slow them down and cobsume a ton of processing power- for data centers, it gets less profitable for them to scrap, it also completly stop some shitty bots