Live data from Hacker News

Why are anime catgirls blocking my access to the Linux kernel?

lock.cmpxchg8b.com

71–80 of 968 posts

Re: Why are anime catgirls blocking my access to the Linux kernel?

#71
post #33

Earlier quoted context omitted.

No, the economics will never work out for a Proof of Work-based counter-abuse challenge. CPU is just too cheap in comparison to the cost of human latency. An hour of a server CPU costs $0.01. How much is an hour of your time worth? That's all the asymmetry you need to make it unviable. Even if the attacker is no better at solving the challenge than your browser is, there's no way to tune the monetary cost to be even…

>An hour of a server CPU costs $0.01. How much is an hour of your time worth? That's irrelevant. A human is not going to be solving the challenge by hand, nor is the computer of a legitimate user going to be solving the challenge continuously for one hour. The real question is, does the challenge slow down clients enough that the server does not expend outsized resources serving requests of only a few users? >Even if…

The problem with proof-of-work is many legitimate users are on battery-powered, 5-year-old smartphones. While the scraping servers are huge, 96-core, quadruple-power-supply beasts.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#72

I disagree with the post author in their premise that things like Anubis are easy to bypass if you craft your bot well enough and throw the compute at it. Thing is, the actual lived experience of webmasters tells that the bots that scrape the internets for LLMs are nothing like crafted software. They are more like your neighborhood shit-for-brain meth junkies competing with one another who makes more robberies in a d…

Those are just the ones that you've managed to ID as bots.

Ask me how I know.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#73

>This dance to get access is just a minor annoyance for me, but I question how it proves I’m not a bot. These steps can be trivially and cheaply automated. >I think the end result is just an internet resource I need is a little harder to access, and we have to waste a small amount of energy. No need to mimic the actual challenge process. Just change your user agent to not have "Mozilla" in it; Anubis only serves you…

> (Why do I do it? For most of them I don't enable JS so the challenge wouldn't pass anyway. For the ones that I do enable JS for, various self-hosted gitlab instances, I don't consent to my electricity being used for this any more than if it was mining Monero or something.)

Hm. If your site is "sticky", can it mine Monero or something in the background?

We need a browser warning: "This site is using your computer heavily in a background task. Do you want to stop that?"

Re: Why are anime catgirls blocking my access to the Linux kernel?

#74
post #63

Earlier quoted context omitted.

[flagged]

>Not only is Anubis a poorly thought out solution from an AI sympathizer [...] But the project description describes it as a project to stop AI crawlers? > Weighs the soul of incoming HTTP requests to stop AI crawlers

Why would a company that wants to stop AI crawlers give talks on LLMs and diffusion models at AI conferences?

Why would they use AI art for the first Anubis mascot until GitHub users called out the hypocrisy on the issue tracker?

Why would they use Stable Diffusion art in their blogposts until Mastodon and Bluesky users called them out on it?

Re: Why are anime catgirls blocking my access to the Linux kernel?

#75

When I instantly read it, I knew it was anubis. I hope the anime catgirls never disapear from that project :)

It's more likely that the project itself will disappear into irrelevance as soon as AI scrapers bother implementing the PoW (which is trivial for them, as the post explains) or figure out that they can simply remove "Mozilla" from their user-agent to bypass it entirely.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#76
post #33

Hmm... What if instead of using plain SHA-256 it was a dynamically tweaked hash function that forced the client to run it in JS?

No, the economics will never work out for a Proof of Work-based counter-abuse challenge. CPU is just too cheap in comparison to the cost of human latency. An hour of a server CPU costs $0.01. How much is an hour of your time worth? That's all the asymmetry you need to make it unviable. Even if the attacker is no better at solving the challenge than your browser is, there's no way to tune the monetary cost to be even…

But for a scraper to be effective it has to load orders of magnitude more pages than a human browses, so a fixed delay causes a human to take 1.1x as long, but it will slow down scraper by 100x. Requiring 100x more hardware to do the same job is absolutely a significant economic impediment.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#78
post #32

[dead]

You needed to have a security contact on your website, or at least in the repo. You did not. You assumed security researchers would instead back out to your Github account's repository list, find the .github repository, and look for a security policy there. That's not a thing!

I'm really surprised you wrote this.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#79
post #69

I really don't understand the hostility towards the mascot. I can't think of a bigger red flag.

Funny to say this when the article literally says "nothing wrong with mascots!" Out of curiosity, what did you read as hostility?

Oh I totally reacted to the title. The last few times Anubis has been the topic there's always comments about "cringy" mascot and putting that front and center in the title just made me believe that anime catgirls was meant as an insult.

Re: Why are anime catgirls blocking my access to the Linux kernel?

#80
post #63

Earlier quoted context omitted.

>Not only is Anubis a poorly thought out solution from an AI sympathizer [...] But the project description describes it as a project to stop AI crawlers? > Weighs the soul of incoming HTTP requests to stop AI crawlers

Why would a company that wants to stop AI crawlers give talks on LLMs and diffusion models at AI conferences? Why would they use AI art for the first Anubis mascot until GitHub users called out the hypocrisy on the issue tracker? Why would they use Stable Diffusion art in their blogposts until Mastodon and Bluesky users called them out on it?

I am not again AI art completely since I think of it as an editing instead of art itself. My thoughts on AI art are nuanced and worth discussing some other day, lets talk about the author of anubis/story of anubis

So, I hope you know the entire story behind Anubis, firstly they were hosting their own git server (I think?) and amazon's ai related department was basically ddosing their server in some sense by trying to scrape it and they created anubis in a way to prevent that.

The idea isn't that new, it is just proof of work and they created it firstly for their own use and I think that they are An AI researcher/ related to AI, so for them using AI pics wasn't that big of a deal and pretty sure that they had some reason behind it and even that has been changed.

Stop whining about free projects/labour man. The same people comment oh well these AI scrapers are scraping so many websites and taking livelihood of website makers and now you have someone who just gave it to ya for free and you are nitpicking the wrong things.

You can just fork it without the anime images or without the AI thing if you don't align with them and their philosophy.

Man now I feel the mandela effect as I read it somewhere on their blog or any thing that they themselves feel the hypocrisy or something along that (pardon me if I am wrong, I usually am) But they themselves (I think?) would like to get rid of working in the AI industry while making anti AI scraper but they might need more donations iirc and they themselves know the hypocrisy.

Post reply on HN