Live data from Hacker News

Who does Anubis actually stop?

fzakaria.com

71–80 of 84 posts

Re: Who does Anubis actually stop?

#71
post #8

Anubis's primary goal is to prevent web scrapers from DDoSing a website. It's not meant to be an unbeatable challenge or only allow humans like Google's more privacy-invasive captchas. You do the proof of work, you get the content. Not all web scrapers are willing to do the work, which reduces the strain put on web servers. It's by no means a perfect system. It's goals in part prevent it from doing so. It tries to no…

[deleted]

Re: Who does Anubis actually stop?

#72
post #57

Earlier quoted context omitted.

I see. I take this to mean that we have some kind of (perhaps-fundamental) difference in the ways in which we understand how free software works. (That's OK, comrade. I'm not here to change you.)

I suspect we do. In my view, people using free software take the gift they were given as-is, and if they don’t like it, they either contribute in a way the giver appreciates, or move on. They certainly don’t whine about their free gift online, and especially don’t complain that their free gift isn’t professional enough for them.

So no bug reports. No wishing that things could be improved in any way.

All users all must take what they are given. If they do not like what they are given, then they must only contribute in the ways that are prescribed from on-high. No freeloading. No complaining. No discussion, even in the form of a comment on a completely separate, independent forum. If they are unwilling or unable to follow these rules, then they must pound sand.

Am I on the right track here with the intended restraint?

Re: Who does Anubis actually stop?

#73
post #47

Earlier quoted context omitted.

In my experience, not really. Each asset is made by a new proxy, eg some TV somewhere, they send every new request via a new IP address, which is a new machine, and it doesn’t matter how long the response takes, they have already rotated to the next ip immediately and sent another request. Most of these providers have millions of IPs, and it generally doesn’t take millions of requests to scrape a website (unless it’s…

And each new IP triggers a new Anubis challenge. Isn't it great?

So, once the challenges are solved by the residential proxies (with optimized native implementations [1]). Some unsuspecting TV owner is paying with their electricity bill (not the companies doing the scraping) and we all suffer through challenges.

Yes, great outcome!

[1] https://lock.cmpxchg8b.com/anubis.html

Re: Who does Anubis actually stop?

#74
post #12

Earlier quoted context omitted.

Except it does not actually increase the cost of scraping meaningfully. Compute is really cheap. The compute for minting an Anubis cookie will cost less than a thousandth of a cent even assuming the attacker uses the same JS implementation of proof of work rather than an optimized native implementation. That cookie can then be used for hundreds of requests. How big of a deterrent is a millionth of a cent per page goi…

Your theoretical counterargument falls apart by the reality of just putting up anubis and comparing the before and after. I don't understand why this argument shows up in every thread about anubis. There are plenty of people and orgs who have empirical before and after results. We don't need theoretical arguments when there exists actual data.

falls apart by the reality of just putting up anubis and comparing the before and after. [...] We don't need theoretical arguments when there exists actual data.

And the data says it stopped working for some sites that actually have a lot of data.

We apologize for a period of extreme slowness today. The army of AI crawlers just leveled up and hit us very badly. [...] It seems like the AI crawlers learned how to solve the Anubis challenges. [...] However, we can confirm that at least Huawei networks now send the challenge responses and they actually do seem to take a few seconds to actually compute the answers. It looks plausible, so we assume that AI crawlers leveled up their computing power to emulate more of real browser behaviour to bypass the diversity of challenges that platform enabled to avoid the bot army.

https://social.anoxinon.de/@Codeberg/115033790447125787

Re: Who does Anubis actually stop?

#75
post #54
post #37

Earlier quoted context omitted.

It’s meant to be both funny AND highly unprofessional; Anubis makes money of licensing a version of the firewall where you can change the image. It’s a good strategy; personal websites and blogs can display the anime girl without fear, and companies that care about their image end up paying. Win-win.

It appears in places where that are neither personal websites nor blogs, and that are places where professionals conduct work. For instance: The act of searching the Arch Linux wiki produces a picture of the anime girl. (Should I just not use Arch professionally?)

Arch is a largely non-commercial project. You’re free to not use it, if that’s where you draw your personal line. You must be a really principled person then, who no doubt also won’t tolerate much worse offenses.

Re: Who does Anubis actually stop?

#76
post #60

Anubis does not stop me from browsing a site (not scraping, browsing with a human at the wheel) On the other hand, Cloudflare and the others stop me dead. "enable javascript and cookies." Ok. "your browser is too old". (I have an old OS with the newest firefox esr that supports it). sigh.

Anubis also forces cookies and javascript, which deters me from many of the sites that use it that require neither.

Re: Who does Anubis actually stop?

#77
post #72

Earlier quoted context omitted.

I suspect we do. In my view, people using free software take the gift they were given as-is, and if they don’t like it, they either contribute in a way the giver appreciates, or move on. They certainly don’t whine about their free gift online, and especially don’t complain that their free gift isn’t professional enough for them.

So no bug reports. No wishing that things could be improved in any way. All users all must take what they are given. If they do not like what they are given, then they must only contribute in the ways that are prescribed from on-high. No freeloading. No complaining. No discussion, even in the form of a comment on a completely separate, independent forum. If they are unwilling or unable to follow these rules, then the…

Yes, they have no obligations to you, just as you have no obligations to them (beyond whatever licenses apply to their content).

Re: Who does Anubis actually stop?

#78
post #77
post #72

Earlier quoted context omitted.

So no bug reports. No wishing that things could be improved in any way. All users all must take what they are given. If they do not like what they are given, then they must only contribute in the ways that are prescribed from on-high. No freeloading. No complaining. No discussion, even in the form of a comment on a completely separate, independent forum. If they are unwilling or unable to follow these rules, then the…

Yes, they have no obligations to you, just as you have no obligations to them (beyond whatever licenses apply to their content).

Indeed. They owe me nothing, and I owe them nothing.

We are all free to have a slice of the infinitely-divisible cake, and also to talk about it when that behooves us. We can say positive things when it suits us, but we can also say whatever else we wish to as well.

Re: Who does Anubis actually stop?

#79
post #47

Earlier quoted context omitted.

And each new IP triggers a new Anubis challenge. Isn't it great?

So, once the challenges are solved by the residential proxies (with optimized native implementations [1]). Some unsuspecting TV owner is paying with their electricity bill (not the companies doing the scraping) and we all suffer through challenges. Yes, great outcome! [1] https://lock.cmpxchg8b.com/anubis.html

Proxy networks just proxy. They don't let their client run compute on the proxy. That isn't even a possibility in socks5 protocol.

Re: Who does Anubis actually stop?

#80
post #54
post #37

Earlier quoted context omitted.

It’s meant to be both funny AND highly unprofessional; Anubis makes money of licensing a version of the firewall where you can change the image. It’s a good strategy; personal websites and blogs can display the anime girl without fear, and companies that care about their image end up paying. Win-win.

It appears in places where that are neither personal websites nor blogs, and that are places where professionals conduct work. For instance: The act of searching the Arch Linux wiki produces a picture of the anime girl. (Should I just not use Arch professionally?)

I don't see what's so offensive about it. If it had huge boobs or something that would be one thing, but it's just a regular mascot character. Out of all the "necessary evils" that get inserted to keep a service above water, that anime girl image is the least offensive one I can think of. It's still completely normalized to show ads for porn on sites like youtube. Captchas are an insult, with the "photo challenge" type being a full on slap in the face most of the time. I would look at 1000 anime girls to avoid one street sign captcha.
Post reply on HN