logoalt Hacker News

Aachenyesterday at 10:12 PM3 repliesview on HN

> requiring 1 second of compute before allowing a page load

After 1 solve, you get a cookie and can load tons of pages with it. Scrapers and user agents alike will need to spend the compute only once to get a valid session for themselves

Seems to be working so far though. Fwiw, lots of silly things stop bots until someone puts their mind (or tokens) to bypassing it, and then the blocking mechanism has to adapt. We'll see how it plays out, for now it's a lot better than begging big brother (cloudflare, google, or amazon captcha) for access, so I'm quite appreciative of what Techaro is doing


Replies

jdlshoreyesterday at 10:18 PM

The issue is that scrapers are rotating their IP and essentially performing a DDoS attack. Anubis is part of a defense-in-depth solution. If scrapers reuse a cookie, traditional anti-abuse mechanisms will work.

show 1 reply
__stoday at 12:26 AM

https://people.kernel.org/monsieuricon/creepy-crawlies reports anubis effectiveness falling off

show 1 reply
mitxelayesterday at 11:12 PM

If you change your IP address, it invalidates the cookie. If you don't change your IP address, you can be blocked by IP address.