Comment on Anubis is awesome and I want to talk aout it
SmokeyDope@piefed.social 17 hours agoSomething that hasn’t been mentioned much in discussions about Anubis is that it has a graded tier system of how sketchy a client is and changing the kind of challenge based on a a weighted priority system. The default not policies it comes with has it so regular clients are passed through, only slightly weighted clients/IPs get the metarefresh, its when you get to moderate-suspicion level that JavaScript Proof of Work kicks. The bot policy and weight triggers for these levels, challenge action, and duration of clients validity are all configurable.
It seems to me that the sites who heavy hand the proof of work for every client with validity that only last every 5 minutes are the ones who are giving Anubis a bad wrap. The default policy settings dont trigger PoW on the Firefox android clients ive tried including Firefox meanwhile other sites show the finger wag every connection. Its understandable why some choose strict policies but I’m glad theres config options to mitigate impact normal user experience.
sudo@programming.dev 5 hours ago
Last I checked that was just User-Agent regexes and IP lists. But that’s where Anubis should continue development, and hopefully they’ve improved since. Discerning real users from bots is how you do proper bot management. Not imposing a flat tax on all connections.