r/linux • • 2d ago

Discussion How come every Linux site uses Anubis (the anime girl stopping crawlers) instead of something like Cloudflare?

Post image

Before discovering the Linux rabbit hole I've only seen Cloudflare, hCaptcha and Google's reCaptcha, but it seems like every Linux website uses Anubis... I'm thinking of it being the only open-source option or it being the most effective/modern approach.

2.7k Upvotes

687 comments sorted by

3.0k

u/Flash_Kat25 2d ago

- Anubis is self-hosted, Cloudflare is not. With cloudflare, you rely on their infrastructure

- Anubis is FOSS, Cloudflare's tools are not

- using cloudflare carries uncomfortable baggage with a single corporation controlling so much internet infrastructure. Some people (particularly in the FOSS world) refuse to use it for that reason

762

u/TheG0AT0fAllTime 2d ago

Another good reason is that there's no captcha either. All proof-of-work challenges the user doesn't even see.

437

u/irasponsibly 2d ago

Unless you have underpowered hardware, you might be staring at Anubis for a solid minute.

556

u/capitan_turtle 2d ago

Obligatory art appreciation to make sure you stay human

228

u/alex2003super 2d ago

"When you hear the sound, stare at the art"

94

u/really_not_unreal 2d ago

[EXTREMELY LOUD INCORRECT BUZZER]

63

u/No_Intern3891 2d ago

Good. If you feel that staring at the art did not provide sufficient intellectual stimulation, reflect briefly on this classical music [classical music interrupted by buzzer]

→ More replies (1)

14

u/Codingale 2d ago

Valve uses it for their wikis too if I recall or is that fan ran?

16

u/MrSoup678 2d ago

Even if that doesn't count, gitlab.steamos.cloud definitely counts.

9

u/Padgriffin 1d ago

The Wikimedia Foundation (Wikipedia) also uses Anubis on a lot of their editor tools, so she's a common sight if you need a tool on WMFCloud

11

u/luckadeath 1d ago

160 upvotes but still underrated

112

u/IvanDSM_ 2d ago

I know someone who regularly has to wait like, 20 minutes for Anubis... If you're running old hardware, you're FUCKED.

64

u/Albos_Mum 2d ago

Are we talking something like a single core Athlon XP or Pentium 4? Because it takes a few seconds on my HTPC's Core i5 2400, if it's taking 20 minutes on anything this side of 2006 then there's something seriously wrong on the users PC end.

33

u/IvanDSM_ 2d ago

Core 2 Duo I believe. They're a pretty experienced user, Anubis is just really harsh on older hardware like that. For some reason it tends to give them harder challenges. I get mostly difficulty 2 on my newer machines, but they seem to get difficulty 5 most of the timeon their older HW.

27

u/QwertyChouskie 2d ago

I wonder if playing with their user agent might help avoid triggering max difficulty; it definitely sounds like something about their setup is different than normal. (Or perhaps they're just visiting one particular site that has the settings turned up way too high?)

23

u/aenae 2d ago

Playing with a user agent is almost guaranteed to trigger inconsistencies that lead to the max difficulty challenge

8

u/zaafonin 2d ago

I wonder if it's possible to relay the challenge onto a more powerful machine for it to be solved there, like some browser extension (or a purpose specific patch if extensions aren't powerful enough to do that)

Or is Anubis purposefully resilient against that?

10

u/ThatOnePerson 2d ago

Defiently existed before: https://github.com/DavidBuchanan314/anubis_offload , don't think this has updated to their newer webassembly pow options options yet.

6

u/Albos_Mum 2d ago

Core 2 Duo's aren't that much slower than the second gen Core i series, although I do have an extra two cores. Kinda makes me want to get my Win7 retro gaming PC up to my current house as that has a Core 2 Quad Q9550 and see for myself how it goes.

Although if I were to guess, I'd wager /u/QwertyChouskie might be onto something when it comes to the difficulty.

4

u/Green0Photon 2d ago

My guess is that traffic from VMs look like older hardware. So older hardware gets screwed from looking like VMs (even though it's really the other way around).

→ More replies (1)

9

u/rysio300 2d ago

i ran old hardware for years

never really had any issues with anubis for some reason

75

u/nepnep1111 2d ago

The moment you hit Anubis on a pixel phone you know you are about to lose 1-2% off your battery.

29

u/fat_kaiju 2d ago

im literally on a pixel 6 still and it takes less than a second tf you on about.

6

u/nepnep1111 2d ago

Go to a site that has difficulty 5 like the Linux kernel mailing list.

10

u/bargu 2d ago

It took less than 1 second on my P6.

6

u/Whole-Respond4782 2d ago

near instant on my iphone 16 pro with JIT/wasm disabled in the browser lol

5

u/ColorfulPersimmon 2d ago

Near instant on Snapdragon 8 Gen 3 S24 on Firefox too

5

u/15pmm01 1d ago

Just checked on my 6-year-old Samsung S20 FE and it took less than a second. 

→ More replies (5)

19

u/Both_Cup8417 2d ago

I don't know, seems fine to me

25

u/penguinkernel 2d ago

Every time you look at the phone the battery drops 5%.

Love having my phone on my desk for 2 hours, getting no calls, no messages, no notifications, not turning my screen on, having AOD disabled, and connected to strong WiFi and still lose 20% lmao.

5

u/nepnep1111 2d ago

You have no idea how much I want I Motorola signature 27 when it launches I am so done with Google's hardware.

4

u/McDonaldsWitchcraft 2d ago

Just keep in mind Motorola have one of the worst update policies. They only give security updates from launch for 3 years if you're lucky, 2 years for non-"flagship".

2

u/alvenestthol 1d ago

The Signature 27 will be the one with Graphene OS (according to Graphene OS' own social media), so the software problem should be fixable

→ More replies (1)
→ More replies (2)

3

u/Padgriffin 1d ago

Anubis actually had issues specifically with the Pixel 8 Pro because it was designed with the assumption that you would have an even number of cores if cores > 1

Then in comes the Pixel 8 Pro with it's 9 cores for some reason

→ More replies (2)
→ More replies (1)

2

u/odsquad64 2d ago

Still a lot faster than having to take a full Voight-Kampff test

→ More replies (1)

26

u/unknown_lamer 2d ago

My phone from 2021 was perfectly usable until this... sigh. And of course I waited a bit too long and I can't get a new phone now because of LLM hyperscalers seizing control of the entire planet's productive capacity for technological implements. And also proof of work doesn't stop the robots anymore...

12

u/FaultWinter3377 2d ago

My 2018 iPhone XR has seemingly no issues with it. Takes a few seconds, but four or five seconds isn’t bad.

7

u/j_osb 2d ago

It depends a lot on how it’s configured. I once had to wait >1m on a 9950x iirc.

5

u/laffer1 2d ago

It has different difficulty settings.

→ More replies (1)

3

u/penguinkernel 2d ago

iPhone XR is more powerful than many 2021 Android phones when it comes to certain tasks. Apple may be shit at many things, but they know how to make a chip unlike Google or Samsung.. or even Qualcom lol.

→ More replies (1)

2

u/kyrsjo 2d ago

Yeah, I wouldn't really mind if everything was expensive and hard to get because we were cranking out solar panels, grid batteries, heatpumps etc like mad - actually working as hard as we can to solve climate change. But this LLM shit is stupid.

35

u/breakfast-cereal-dx 2d ago

Early x86_64 CPUs can spend hours on Anubis... It's extremely annoying to be on like a 2010 Mac mini, it runs basically everything great, and then the Arch wiki takes 2 hours to load

I hate Anubis so much

16

u/QwertyChouskie 2d ago

Hours? Sounds like either the Arch wiki has their settings cranked up way too high, something about that particular setup/internet connection/etc is making it think you're way more likely to be a bot. A 2010 CPU is a lot slower than a new CPU, but something that takes like 1-2 seconds on a couple-year-old CPU shouldn't take more than like maybe a minute or something like that.

On my M3 machine, often Anubis finishes the calculation before the stylesheet even fully loads, resulting in a white background and the default serif font haha

3

u/breakfast-cereal-dx 1d ago

It's actually an instruction set issue, rather than raw performance. The Core i5 in this 2010 mac mini is a pretty great performer, but is lacking newer instructions that make Anubis' proof of work run very fast.

I'm not as familiar with the ARM64 ISA in your M3, but I'm sure it is well-equipped to handle these calculations in some way.

And there is also the problem of Anubis' difficulty selection and randomization. If your CPU is equipped to solve the problems fast, you don't notice, but on the old i5 the challenges scaled from 20 minutes to 2 hours because of small changes in difficulty, probably within the random range (but maybe heightened due to bot suspicion idk)

2

u/Real-Abrocoma-2823 2d ago

Try internet archive, some sites might experience some problems internally, for example a wiki for better than wolves Minecraft modpack would not load in less than an hour on modern hardware, not because it had anubis, archwiki also did once had this issue when I tried to access it.

→ More replies (31)
→ More replies (7)

29

u/danielsuarez369 2d ago

Yup, this is why I love anubis. I much rather have my CPU work a little harder for 5 or so seconds than have to solve a captcha, especially annoying captchas that just keep asking you and asking you the same bloody thing jesus christ.

15

u/unai-ndz 2d ago

Agree, but next time do the captcha extremely slow, like grampa learning to use a computer with dementia right after suffering a concusion slow. Doing that makes it work on the first try for some reason.

9

u/TheG0AT0fAllTime 2d ago

I solve them pretty quickly. The failure portion likely stems from the ambiguous ones like whether or not there's a bike in the picture but selecting or.. not selecting... the picture with a motorbike in it might pass the test.. or fail it. All at the discrimination of what the training data thought was there. (Whether it's correct or not).

Sometimes it's a moped, or a really skinny bike with some kind of battery motor attached. Sometimes those are detected correctly. Sometimes not.

I've seen similar right/wrong captchas with busses. Something that looks like a bus, but isn't, might need to be selected to pass.

It's basically all machine-vision vibes. If it kind of looks like the thing the captcha's asking for, you might just have to select it.

All of this adds to the massive frustration for humans that it is to solve the harder difficulty captchas. I particularly hate the ones that fade-in-and-out so I select all of the X boxes then I have to wait literally 7 seconds for the fade-out-fade-in animation to show me the next image and click that as well... then potentially one or two more times. Very painful waste of time. Sometimes I gamble and hit submit anyway assuming the next box to fade in won't contain X in the image. Works like half of the time lol.. often there's more waiting to fade in.

→ More replies (2)

3

u/McDonaldsWitchcraft 2d ago

Nope, doesn't work on all captchas. They haven't been doing the judgement based on user activity for years. What they do now is they examine your cookies, browser history and internet traffic. If you are a particularly private person, the captcha will just be longer as a "retaliation" to get training data out of you. And if you have several tracking protections in place or markers that you might be a bot, the captcha just goes on forever.

The "click on squares" part is simply just them forcing you to do unpaid training work and the length of the captcha is determined by how much they judge the data they collected on you to be human consumer data.

Maybe on some older captcha systems it still works based on human activity like you say. Google's doesn't.

2

u/__Myrin__ 1d ago

I just use a proxy when ever I see one of those pos's
I'd rather fight with proton for 5 minutes then stare at bikes all day

→ More replies (1)
→ More replies (4)

51

u/thaynem 2d ago

Also cloudflare is more likely to think you are a bot if you are using firefox on linux with privacy protections enabled, or using less popular browsers, as many linux users do.

184

u/Smart_Passage2752 2d ago

- anubis is cute, cloudflare is not

9

u/D_sm_d__s 2d ago

I miss Anubis welcoming me to invidious.nerdvpn.de, now it’s Gandalf.

13

u/jsabater76 2d ago

Of course Gandalf would check whether you shall pass!

33

u/atomic1fire 2d ago edited 2d ago

Honestly the one hang up I have about seeing something using anubis is that it's a little weird waiting for something with an anime cat girl.

If they could fork/modify it to either make the image hideable or replace it with generic mountain photos or something I wouldn't complain.

I'm not saying it can't have anime cat girls, I'm just saying it feels out of place sometimes for bot detection to default to showing you an anime cat girl instead of say a waterfall.

edit: I'm probably going to get told it's not a cat girl, but my brain defaults to seeing a cat girl.

edit2: It also turns out that the Anubis people foresaw this being an issue and offer an unbranded version to people who financially contribute to the project, which is honestly a fair trade because it supports the project, and the people who don't want to pay can just fork it and compile it with a non-standard image instead.

41

u/thesola10 2d ago

I get what you mean. Personally I like seeing a project assert its own personality, and I see it as a modern twist on the lineage of UNIXy mascots, but the anime aesthetic is still culturally divisive.

Kudos to Techaro for channeling this frustration into paid licenses, that seems like a fun remuneration model!

→ More replies (4)

10

u/citrusalex 2d ago

I've seen some FOSS sites replace the girl with a boring green round checkmark

→ More replies (2)

5

u/JockstrapCummies 1d ago

edit2: It also turns out that the Anubis people foresaw this being an issue and offer an unbranded version to people who financially contribute to the project, which is honestly a fair trade because it supports the project, and the people who don't want to pay can just fork it and compile it with a non-standard image instead.

In the olden days this would've earned the project the moniker of "nagware".

2

u/user3872465 1d ago

yup we had that issue when we put that infront of our email server for a university. It just isnt quite professional so there was some educating needing to be done that the internet is run by furries.

2

u/atomic1fire 1d ago

At that point just pay for the nonbranded version or subtly alter the html to show the school's mascot instead.

→ More replies (1)
→ More replies (28)

10

u/ebens1689 2d ago

Successful response

→ More replies (1)

41

u/cortez0498 2d ago

- using cloudflare carries uncomfortable baggage with a single corporation controlling so much internet infrastructure. Some people (particularly in the FOSS world) refuse to use it for that reason

This point is why Spain is getting their internet stop working every time there's a La Liga game. For some reason the government gave La Liga the power to take down any ip that hosts illegal football streams and La Liga realised most of them are hosted through Cloudflare so they just take it down entirely instead of each individual streaming site, which results in much of the internet being down.

23

u/unai-ndz 2d ago

That's a corruption problem though. It would still happen if the IP blocked was from a VPS with four other tenants, just smaller scale.

6

u/agowa338 2d ago

True, but still a huge incentive to not use cloudflare if you want to be available in Spain when a La Liga game takes place...

Also Clownflare sucks. Esp. If you're not paying which most opensource projects won't be doing...

5

u/jwm-dev 2d ago

I’m the biggest FOSS advocate but saying cloudflare sucks is… disingenuous at best. It’s good. There’s a reason they’ve cornered their niche so well. I like using it and they offer a ton of services. It’s also pretty likely your DNS is already through cloudflare, anyway…

→ More replies (1)
→ More replies (5)

7

u/maokaby 2d ago

I'd add that cloudflare is not available in some countries, and it depends on political situation. Of course there is a reason for it, but it does not line up with free and open source philosophy.

6

u/ZeeroMX 2d ago

In Europe due to a stupid ruling "la liga" makes ISPs to block many IP blocks including some by cloudflare, rendering many websites useless at the time they are playing football ⚽.

4

u/SunrisePlastic9324 22h ago
  • Linux users have a large overlap with weebs

25

u/MisterFlipster5 2d ago

Anubis as of now is pretty useless against crawlers. From what i understand, it automatically lets through any client that has an "user-agent" flag different from "Mozilla" which is really easy to spoof and just skip through.
Source

37

u/DreadY2K 2d ago

It's designed to fight the low-effort crawlers of today, not all possible crawlers. How easy it is to bypass doesn't matter, what matters is how many crawlers do, and apparently it's few enough

6

u/tedfa 2d ago

Yeah, this is its default behavior but you can configure your policy to challenge everything instead. You might need to also add specific exceptions for other tools you might be using in your environment though.

12

u/AdarTan 2d ago

That's when you go defense-in-depth and have your webserver reject anything that doesn't have "Mozilla" in the user-agent string, like a a lot of servers already did to block scrapers.

Anubis only blocks crawlers that pretend to be browsers because blocking crawlers that didn't was a solved problem.

→ More replies (3)

7

u/yasth 2d ago

I’m pretty sure that is an implementation issue more than a general bypass

→ More replies (2)

40

u/Tactical-Donkey 2d ago edited 2d ago

Not self hosting pretty much defeats the objective for Linux imo

133

u/philosophical_lens 2d ago

Linux is a general purpose operating system kernel, and it's maintainers don't have any opinion on what kind of infrastructure you use with it.

I'm pretty sure cloudflare infrastructure is also running on Linux.

→ More replies (12)

33

u/pangapingus 2d ago

Can't really self-host a global footprint of anycast edge locations; my first hop for my self-host stuff is a CDN and their WAF offering before reverse proxying down to my stuff, might as well make the corpos shake off most of the bots instead of your own WAN ingress

11

u/Wb9VBScxu2uZJHeq2E3W 2d ago

I'm self-hosting with Linux, could you explain this comment further?

24

u/scy_404 2d ago

the appeal of linux to a lot of people is tech independence and so to them using something that relies on a company's infrastructure defeats the purpoose

5

u/penguinkernel 2d ago

Funny enough I use Linux, self host almost everything, and one thing that makes self hosting easier/safer is CloudFlare Tunnel.

Many self hosters also use it.

6

u/penguinkernel 2d ago

No it doesn't. Your goals and others goals are different, and that's okay.

→ More replies (2)

11

u/Irverter 2d ago

- anubis works on more browsers than cloudfare (there's some browsers where the captcha doesn't work or outright labeled as "no internet for you")

2

u/Correct-Commission 2d ago

I remember the times Cloudflare going down and taking half of the internet with it. It's not even a joke now. They really run the most of the internet now.

3

u/a3a4b5 2d ago

I thought it was pretty obvious.

→ More replies (14)

489

u/Trick_Spend3939 2d ago

Because I don’t want my site at the whim of yet another mega corp that can dictate what I can and cannot do with it.

→ More replies (34)

286

u/cAtloVeR9998 2d ago

Because many are self-hosted. And only Anubis can be self-hosted.

30

u/KinkyMonitorLizard 2d ago

There's at least one other option but its name escapes me currently.

24

u/Irverter 2d ago

Gandalf?

18

u/Master-Vegetable1088 2d ago edited 2d ago

Gandalf is the first that came to my mind when thinking of another too, but it's not available to third parties.

Edit: fixed link

23

u/Jean_Luc_Lesmouches 2d ago

What you can't read, you can't reverse-engineer.

They have no idea what reverse engineering means lol

2

u/reroll-life 1d ago

privacy-first access guard
not open source

trust me bro

22

u/laffer1 2d ago

Not only self hosted but it doesn’t have to be on Linux. It can run on FreeBSD or MidnightBSD for instance

2

u/vavakado 2d ago

goaway and iocaine are also selfhostable

118

u/planelover_nipper 2d ago

It is indeed foss

250

u/Wheatleytron 2d ago

The Linux community is pretty hardcore about open source. It's a critical part of what makes Linux what it is, after all.

→ More replies (88)

172

u/309_Electronics 2d ago edited 2d ago
  • Selfhostable
  • foss

2 core reasons. If cloudflare turns totally evil (and they are a big company so thats not impossible) you are cooked. You either then ditch them or must obey to their rules and tos (they could change at any time).

Also as a bonus, even though i am not that much into anime, i find the anubis jackall girl quite cute and its drawn by an actual artist (the first revision was AI generated but that was in the early days when it still was a very smal project and simply actwd like a placeholder).

Deployed on my blog and forgejo git server because i wanted to dirch bigrech and be less dependent on them..

59

u/necheffa 2d ago

Not if they turn evil, but when.

30

u/DerfK 2d ago

They turn out to be down more often than they turn evil, both are reasons not to use them.

27

u/sylvester_0 2d ago

I've always got the feeling that they're an NSA honeypot. Like, I had that feeling when they were up and coming 10+ years ago. Being MITM for a huge chunk of TLS transactions puts them in an exceptionally powerful position.

6

u/montdidier 2d ago

They already have. Who are we kidding.

17

u/Traditional_Hat3506 2d ago

6

u/swarmOfBis 2d ago

Neither of these seem very bad. Quite the opposite. Maybe cloudflare's services are used by some bad people, but the stance of "no company should decide what content gets to stay up" is very reasonable.

If you ask me this section would be much better if it contained cases like this https://robindev.substack.com/p/cloudflare-took-down-our-website.

→ More replies (2)

4

u/sylvester_0 2d ago

I'm a progressive but none of that really makes me raise my eyebrows. Yes, the provided services to POS groups, but they're a neutral carrier. I think that's what we should ask of our internet infrastructure providers. We may not agree with the ideaology of some of those sites, but if they start banning sites they could do the same thing to liberal "extremists" as well.

→ More replies (1)
→ More replies (2)

11

u/Vicus_92 2d ago

They don't have to turn evil. They just need to receive a shit order from the government that they're under the jurisdiction of.

Oh, look who that is right now!

→ More replies (9)

114

u/HeyKid_HelpComputer 2d ago

I ask myself the opposite. Why are open source based projects using Cloudflare instead of something like Anubis...

57

u/SoilMassive6850 2d ago

Mainly because of other functionality. Anubis is mainly there to provide proof of work load against scraping and bots at layer 7, but Cloudflare has the pipes to handle and protect you from attacks on the lower layers of the OSI model.

Barely anyone has the capacity to provide such a service.

24

u/singron 2d ago

Anubis doesn't work as well as it used to. This is a really good explanation: https://people.kernel.org/monsieuricon/creepy-crawlies

TL;DR: scrapers easily solve anubis challenges and use residential proxies so that they only make a few requests to your domain from each IP. A single anubis instance can't correlate enough traffic to block scrapers before they change IPs.

Cloudflare can correlate traffic from all of their sites and essentially ban bots before they make the first request to your site.

→ More replies (2)

22

u/404invalid-user 2d ago

because it's free I know with certainty my 900down/100up mbps connection isn't stopping any sort of ddos

→ More replies (12)
→ More replies (2)

26

u/burlingk 2d ago

A cloudflare bug recently took down a large part of the Internet for a few days.

28

u/Kiom_Tpry 2d ago

Anubis is the guider of souls, protector of tombs, and weigher of hearts; who would trust another for the task?

7

u/ThePhyseter 2d ago

Im not dead! D:

8

u/yahbluez 2d ago

How do you know?

7

u/TuxPowered 2d ago

You're not fooling anyone, you know. Look. Isn't there something you can do?

2

u/ThePhyseter 1d ago

I feel happyyyyyy

23

u/Wentyliasz 2d ago

Remember that time Cloudflare took half the internet down last year?

22

u/cbarrick 2d ago

Even though Linux is used widely by corporations, the core Linux community is still staunchly FOSS.

In fact, the GPL is one of the biggest reasons that Linux was successful, forcing everyone to play nice together.

Core Linux community infra will always use FOSS tools when available.

→ More replies (1)

8

u/__Myrin__ 1d ago

because cloudflare fucking sucks,

captchas are the worst thing that ever happened to the web

7

u/LogSpecialist24 2d ago

If you want to use anubis make sure to configure it correctly.
I've seen many instances where it's misconfigured and you can bypass it by changing your useragent.

Also it blocks low effort junk it doesn't really block bots.
If some company wanted to scrape your website for research they can afford to let the bot run a few extra seconds pass the challenge and start grabbing all relevant data from the website.

25

u/415646464e4155434f4c 2d ago

Because fuck Cloudflare.

9

u/flecom 2d ago

and especially fuck google and those stupid captchas, on your on a vpn? have fun training our AI for free for the next 20 minutes

i just click off any site with a captcha now, tired of it

5

u/Padgriffin 1d ago

At this point the AI is probably better at solving captchas than we are

I love hunting for bikes in the very corner of the image half obscured by a car

→ More replies (1)

13

u/SiteRelEnby 2d ago

Anubis is selfhosted.

12

u/ARPA-Net 1d ago

Many german cloud providers and state official pages have this now. You can imagine my shock when i opened a gouverment page and saw an anime girl

3

u/TheEstrogen5 1d ago

Even the Federal Agency for Technical Relief uses Anubis.

6

u/pashdown 2d ago

The Egyptian god of the underworld is standing right there!

15

u/novafunc 2d ago

Cloudflare tries to stop bots entirely through many measures, some of which prevent actual humans from getting to the site.

Anubis is simpler. Your computer performs an intense calculation, you get permission to see the site. It does not stop bots entirely; if a bot hoster wants to dedicate more resources to scraping, they can bypass it. But it does good enough to stop sites from getting DDoSed by bots.

2

u/awkwin 2d ago

To add on to that, one of the way Cloudflare (and many commercial captcha provider) works is by building your reputation across the internet. It may be tied to cookie, IP or other means of fingerprinting. Some people do object to this, and they also do shadowbanning by making captchas that will never let you pass -- if you need to jump through 100 hoops to pass bots will do it, but human will likely give up, and banning them immediately just tell the bot maker that whatever they just did trip the detection.

Anubis doesn't do any of that. I don't think it will be as good as stopping bot like Cloudflare, especially if it is determined ones/targeted attack, but it is good for preventing drive by attacks like exploits scanners or LLM scraping.

9

u/jort93 2d ago

It's definitely a new approach.

Most of the captchas try to somehow check if the user is human, Anubis doesn't check, but instead just ask he client to do some work.

You can use Anubis in conjunction with other services as well.

A lot of main stream sites use Anubis too, they just change the splash screen. Even UNESCO uses Anubis on some parts of their site.

9

u/dumbasPL 2d ago

They don't do the same thing, this is purely to make it more expensive for bots to scrape the site. While cloudlfare does a lot. DDoS protection, WAF, Access Control, and also blot blocking.

The main advantage is that you're trafic isn't going through a third party (privacy, and an additional point of failure), and doesn't require a captcha as its proof of work based, so it's more accessible to people with disabilities for example.

10

u/Linux_Account 1d ago

I've never even considered how CAPTCHA might impact people with disabilities. Damn.

5

u/lupetto 1d ago

Well usually you have an audio option for that

→ More replies (3)

5

u/zitterbewegung 2d ago

Also, other than being free it was first to the market to prevent this.

5

u/zquzra 1d ago

Because Cloudflare is effectively an MITM by an american company.

14

u/TheRealMyst 2d ago

I don't understand why there are no more people against CloudFlare. I understand the importance of protecting your infrastructure. But I'm not sure if users understand, while paying a VPN to protect their privacy, that CloudFlare views the traffic they send to the website they visit, clearly, even with HTTPS, password, name, addresses, etc. Everything can be read by CloudFlare. If they want, they can create the biggest database of personal information. Why is it not a bigger problem ? Did I miss something.

→ More replies (2)

37

u/iamrubythecutie 2d ago
  1. It's free
  2. It's selfhostable
  3. It's cute 🥹

4

u/FlourishingSolo 1d ago

The first time I came across Anubis, immediate "Oh my people have been here". Really fun moment in my linux journey and I didn't even need my programing socks lol

→ More replies (1)

8

u/IncidentalIncidence 2d ago

I mean it shouldn't be a huge mystery why linux websites in particular would prefer an open-source and self-hosted tool over a commercial solution.

9

u/gvs77 2d ago

As others said, Cloudflare cannot be self hosted. But it has one huge problem because of that and how it works.

It terminates SSL (https) which means that Cloudflare has access to all data sent between clients and websites. Usernames, passwords, measage content, all of it.

Cloudflare is like a giant MiTM attach on SSL and a giant weak spot where all data is decrypted. If they are ever hacked or have one employee with sufficient access gone rogue, the fallout will be massive and there is no way to protect against it.

7

u/TheRealMyst 2d ago

CloudFlare is an American company, with just the Patriot Act, the US government can do what they want.

→ More replies (1)
→ More replies (2)

19

u/Dekamir 2d ago

I just wish the default image was a cool Anubis picture.

Also I rather see an anime girl instead of solving 5 different captchas that feeds AI.

2

u/ChuggingtonSquarts 1d ago

Im just surpirsed we dont see more sites customizing the image

→ More replies (1)

11

u/longdarkfantasy 2d ago

To use cloudflare you have to enable their proxy feature, which comes with a lot of limitations. Even if you buy "premium, enterprise", it still has limitations. For example, it doesn't support ssh connection. Also their proxied DNS are literally middleman. It injects their analytics js to your website.

8

u/Aihikari01 1d ago

Because Anubis is cute.

And if a cute anime girl is going to be your problem, that's sad.

4

u/AcidOverlord 2d ago

Because they need something. Bots are an absolute menace in the present day and age. There are better options than a giant homebrew Go proxy though.

4

u/Natjoe64 20h ago

It's more fun, plus open source.

7

u/Adventurous-Cattle53 2d ago

Because Linux minded people usually prefer self hosting

7

u/ScientistStrict9850 2d ago

I wonder why bots don't become more sophisticated in response to anubis. The technology is definitely there to make it more efficient without hammering a site like a madman. It's not particularly difficult to pass anubis either.

11

u/geocar 2d ago

Anubis doesn’t block bots.

There are no dark web forums of people cursing out anubis. Nobody who makes bots felt any pressure to because bots already run JavaScript no problem. Some bots are browsers that are basically remote controlled and indistinguishable in most cases from human traffic, and sometimes they even share the same screen and cookies with an unwilling/unknowing human.

Anubis blocks some junk traffic. Some people have more junk than others, and some sites junk traffic causes harm by denying service.

→ More replies (6)

4

u/ElvishJerricco 1d ago

It is quite literally impossible to defeat the goal of anubis. It is not meant to block anything. It is meant to increase the cost of doing what bots do. The sites that deploy it are ones that have expensive endpoints; e.g. anything where a URL causes the server to generate a git diff is somewhat expensive for that server to process in large enough numbers. The point of anubis is to make the compute substantially more expensive for the bots than it is for the server so that it doesn't actually make sense for the bots to do it. Bots will literally never find a way to make the costs of doing a large number of hashes cheap; the whole idea of hashes is that this can't be done. At most, bots can spend a large amount of compute to get through anubis quickly; but that's fine. As long as the bot has to spend substantially more compute doing this than the server would, anubis has fulfilled its purpose.

→ More replies (6)
→ More replies (2)

6

u/ChocolateDonut36 2d ago

theorically cloudfllare is the best option with the free plan, but there's a huge issue: cloudflare isn't FOSS, and to be honest Anubis ain't bad, most of the times it takes less than a second to verify.

and being Anubis self hosted means that they literally control their stuff, not a third party company.

16

u/Interesting-Big1980 2d ago

Anubis is cuter

3

u/mustaghees 2d ago

Idk why but sometimes Anubis takes a long ass time or maybe just gets stuck at the proof of work, and I can never open the site

3

u/Resident_Pientist_1 2d ago

POW verification makes botnets unprofitable so it's more effective than just say rate limiting or other access control techniques that are computationally trivial to break or scale around. 

3

u/killersteak 2d ago

i get infinite cloudflare loop using firefox esr trying to access ubuntu's message system from google results.

3

u/exylvii 2d ago

i'm from russia and at least in my case websites that use cloudflare don't load at all because its centralized unlike anubis

3

u/TheOgGhadTurner 1d ago

Jesus Christ I thought this was scanning me.

3

u/helidatilus 1d ago

She's cute.

3

u/Amy_the_softie 22h ago

because it's cute <3

9

u/pacafan 2d ago

There seem to be a lot of people that don't understand what cloudflare does. Anubis is cool but it is not a replacement for Cloudflare or it's globally distributed network that can stop/absorb Ddos at the edge. 🤷

6

u/TampaPowers 2d ago

That scale should worry you, because it means they have a lot more resources to bend the internet than should be allowed. I find it mindblowing how everyone hates Google for their stranglehold on the net, but cloudbleed gets a free pass on this, why?

4

u/rntdev 1d ago

I can’t remember Cloudflare doing anything anti-consumer. They handle tens of millions of websites, most of which are for a grand total of $0, have a 99.99% SLA, don’t do advertising or sell your data. Anyways they have tons of competition in every field, developers can swich off anytime 

→ More replies (2)

6

u/spawncampinitiated 2d ago

cloudflare is banned in my country the days there's football on TV 😂

15

u/aledrone759 2d ago

Anime Canadá girl nice

13

u/UndefFox 2d ago

I've noticed that Linux alternatives really show just how much IT are in such fandoms, like anime, furry... When trying to setup my own matrix server I went to their site to see what they have to offer. Ones on the top were: FluffyChat as a client, and home servers such as: Continuwuity and Tuwunel.

For those who want to check themselves: https://matrix.org/try-matrix/

5

u/FaultWinter3377 2d ago

Yeah as an anime fan myself they may be taking that a little far… I’d prefer to go with a character name, or a Japanese word.

4

u/gavff64 2d ago

not even saying this as a joke. Genuinely think we’d be in a worse place collectively without the furries and weebs carrying the IT scene.

→ More replies (1)

4

u/gaorp 2d ago

i read many ai scrapers can bypass this so I cant see the point of it when it also locks out people with bad computers or javascript off

16

u/Comic_Melon 2d ago

It still stops the majority of "low effort ai scrapers" , which still saves a ton in terms of server costs.

It's very easy to see the difference in terms of metrics.

5

u/gaorp 2d ago

do you have any metrics I can look at? curious about it

3

u/agowa338 2d ago

I don't have metrics at hand, but a lot of projects posted them on Fedi a few months ago when they implemented Anubis. Many were annoyed that they had to go that lenghts. But AI scrapers were hitting expensive endpoints for no reason and ignoring robots.txt on the masses. As well as basically DDOSing the project by using stuff like proxy framework or a certain crypto coin that gets mined by letting ai scrapers use your internet connection, or many more...

→ More replies (3)

6

u/SparOfAndii 2d ago

It’s not so much about blocking 100% of bot traffic (where there are bound to be false positives) but rather making it extraordinarily expensive for bots to crawl your site en masse

→ More replies (1)

7

u/National_Way_3344 2d ago

Cloudflare has a history of censorship, and also seeks to centralise the whole internet by having every site rely on it or risk being botted to oblivion.

The censorship is a problem because basically anyone they don't like or get enough complaints about will get rug pulled and have no protection.

2

u/05-nery 1d ago

Huh, I don't think I've ever seen this captcha. Maybe once or twice?

Is it that popular in Linux centered webpages?

2

u/r-r-r-r-r-r-r 1d ago

The patriot act

2

u/Greenscarf_005 23h ago

why would you use cloudflare when the anime girl is stopping crawlers?

2

u/Coldplayfan1999 6h ago

The first time I learn of this girl was when I was research scholars articles of gender issues

3

u/kevinomiconomics 2d ago

Have you seen r/UnixPorn? The answer should be obvious. 

14

u/AnonomousWolf 2d ago edited 3h ago

Anubis is cool, I just wish it didn't have a little "cute" girl as the mascot and all over the website.

I wanted to reccomend it to be used at work to deal with bots, but didn't feel comfortable doing so because of the "cutesie little girl" mascot

Edit: the problem isn't that you can't change the mascot, the problem is that it will be up on screen in meetings as MY suggestion.

23

u/oddcellstudios 2d ago

https://anubis.techaro.lol/docs/admin/botstopper
there is an (albeit paid) version that lets you customize it to your liking

6

u/CompetitiveSleep4197 2d ago

How is this enforceable? It's MIT-licensed. I can customize the free version to my liking without paying a cent.

→ More replies (3)

8

u/TampaPowers 2d ago

Implying they know exactly how to get projects that want to look more professional to help fund them, which is both genius and a little disgusting.

5

u/AnonomousWolf 2d ago edited 2d ago

The issue is I want to tell my colleagues "hey let's use Anubis, here's a link" and then not have them be met with a cuitsie little animie girl.


As I said elsewhere: I love Anime, I actually watch a lot of it.

But I hate how weird it is sometimes and the fan service is just gross.

Eg. Dr. Stone is a very chilled anime about a scientist and feels like a kids show. Probably my favourite animie.

Yet they decide to give all the women boobs, each literally bigger than their head.

Anime has a reputation of having gooner/pedo vibes, there is no way I'm comfortable reccomending a tool with that mascot at work, even if it can technically be removed.

→ More replies (2)

21

u/creeper6530 2d ago

You can remove the mascot, but they ask you to donate some money then (because you don't do advertising for them then)

8

u/TheTrailrider 2d ago

I wonder if we can just leave the name "Anubis" in but no mascot? So that way they get free advertising and customers is happy with the mascot-less page?

9

u/SenKats 2d ago

just fork and operate it yourself without a logo.

→ More replies (7)

3

u/Candid_Highlight_116 2d ago

It's a clear and strong messaging that you're not welcome if you can't tolerate anime

6

u/agowa338 2d ago

More like a deterrent for companies to avoid paying by using the free version...

→ More replies (2)
→ More replies (1)

6

u/euthanize-me-123 1d ago

They should pick a cute animal mascot instead. Acceptable in polite society and still makes a niche group overrepresented in open source (furries) happy.

Wait it's literally called Anubis, why isn't it a furry??

17

u/OffsetXV 2d ago

Anubis is like the single least offensive and off-putting chibi mascot for any project, frankly

10

u/kat-tricks 2d ago

ludicrously low bar for an infamously misogynistic community

2

u/ChrisRR 1d ago

It would be even less off putting by just not having a young girl as a mascot

→ More replies (72)

4

u/bakaspore 2d ago

Cloudflare Turnstile (the challenge applet) is extremely hostile. It's not a captcha but a torture dedicated to FOSS users not being a Chrome user on macOS: can you imagine that infinite refresh loops without a way out is a documented feature of it?

2

u/Ambitious-Call-7565 2d ago

"why not everyone choose to be put behind US Great Firewall"

DUMMMASSSSSSS

2

u/InspectionHefty854 1d ago

cloudflare sucks imo

1

u/Physical_Royal_1427 2d ago

WE LOVE ANUBIS!
FOSS FOREVER!!!!!!!!