Anubis rarely ever annoys me (I still prefer it over cloudflare’s Mitm) but this specific visit feels almost vindictive. It used half my CPU cores at full blast for three straight minutes.
It seems to be effective since I can’t really “bypass” it with extensions, so AI crawlers probably can’t either, but damn there really should be an option to complete a manual captcha or email the administrators to complain.
As I’m typing this the challenge is still running xD


It’s not about stopping the bots, it’s about slowing them down
But once the challenge is completed, they have the token and can scrape until it’s expired right? So if it’s just taking them a bit more time to get the auth token, what is it solving?
Example: the token lasts for a week and it takes 30 seconds to get the token.
I would assume the token is only good for a few page accesses.
E.g. 500 would mean that a person would see this extremely rarely, and still block a bot from crashing the site.
No it actually lasts for a long time. We have it on my Lemmy instance for https://old.lemmy.today/ and it’s generated once and lasts for many days, probably a week. I guess it’s configurable but if you generate it too often, your visitors will also be annoyed.
It will still slow them down and cobsume a ton of processing power- for data centers, it gets less profitable for them to scrap, it also completly stop some shitty bots