Admin on the slrpnk.net Lemmy instance.

He/Him or what ever you feel like.

XMPP: [email protected]

Avatar is an image of a baby octopus.

  • 72 Posts
  • 897 Comments
Joined 3 years ago
cake
Cake day: September 19th, 2022

help-circle









  • You could enable Suricata on OPNsense, which will allow you to subscribe to some known attacker lists and so one. But the problem these days are mostly AI scrapers that usually don’t show up on these lists as they are not attackers per se, but just cause a lot of database load by repeatably probing every part of your web-applications.






  • No one is disputing that in theory (!) Anubis offers very little protection against an adversary that specifically tries to circumvent it, but we are dealing with an elephant in the porcelain shop kind of situation. The AI companies simply don’t care if they kill off small independently hosted web-applications with their scraping and Anubis is the mouse that is currently sufficient to make them back off.

    And no, forced site reloads are extremely disruptive for web-applications and often force a lot of extra load for re-authentication etc. It is not as easy as you make it sound.





  • If you check for GPU (not generally a bad idea) you will have the same people that currently complain about JS, complain about this breaking with their anti-fingerprinting browser addons.

    But no, you can’t spoof PoW obviously, that’s the entire point of it. If you do the calculation in Javascript or not doesn’t really matter for it to work.

    In the current shape Anubis has zero impact on usability for 99% of the site visitors, not so with meta refresh.