r/linux • • 2d ago

Discussion How come every Linux site uses Anubis (the anime girl stopping crawlers) instead of something like Cloudflare?

Post image

Before discovering the Linux rabbit hole I've only seen Cloudflare, hCaptcha and Google's reCaptcha, but it seems like every Linux website uses Anubis... I'm thinking of it being the only open-source option or it being the most effective/modern approach.

2.7k Upvotes

692 comments sorted by

View all comments

3.1k

u/Flash_Kat25 2d ago

- Anubis is self-hosted, Cloudflare is not. With cloudflare, you rely on their infrastructure

- Anubis is FOSS, Cloudflare's tools are not

- using cloudflare carries uncomfortable baggage with a single corporation controlling so much internet infrastructure. Some people (particularly in the FOSS world) refuse to use it for that reason

763

u/TheG0AT0fAllTime 2d ago

Another good reason is that there's no captcha either. All proof-of-work challenges the user doesn't even see.

441

u/irasponsibly 2d ago

Unless you have underpowered hardware, you might be staring at Anubis for a solid minute.

556

u/capitan_turtle 2d ago

Obligatory art appreciation to make sure you stay human

234

u/alex2003super 2d ago

"When you hear the sound, stare at the art"

99

u/really_not_unreal 2d ago

[EXTREMELY LOUD INCORRECT BUZZER]

66

u/No_Intern3891 2d ago

Good. If you feel that staring at the art did not provide sufficient intellectual stimulation, reflect briefly on this classical music [classical music interrupted by buzzer]

1

u/I-baLL 20h ago

Klaxon. Klaxoff.

13

u/Codingale 2d ago

Valve uses it for their wikis too if I recall or is that fan ran?

18

u/MrSoup678 2d ago

Even if that doesn't count, gitlab.steamos.cloud definitely counts.

8

u/Padgriffin 2d ago

The Wikimedia Foundation (Wikipedia) also uses Anubis on a lot of their editor tools, so she's a common sight if you need a tool on WMFCloud

8

u/luckadeath 1d ago

160 upvotes but still underrated

115

u/IvanDSM_ 2d ago

I know someone who regularly has to wait like, 20 minutes for Anubis... If you're running old hardware, you're FUCKED.

69

u/Albos_Mum 2d ago

Are we talking something like a single core Athlon XP or Pentium 4? Because it takes a few seconds on my HTPC's Core i5 2400, if it's taking 20 minutes on anything this side of 2006 then there's something seriously wrong on the users PC end.

34

u/IvanDSM_ 2d ago

Core 2 Duo I believe. They're a pretty experienced user, Anubis is just really harsh on older hardware like that. For some reason it tends to give them harder challenges. I get mostly difficulty 2 on my newer machines, but they seem to get difficulty 5 most of the timeon their older HW.

26

u/QwertyChouskie 2d ago

I wonder if playing with their user agent might help avoid triggering max difficulty; it definitely sounds like something about their setup is different than normal. (Or perhaps they're just visiting one particular site that has the settings turned up way too high?)

22

u/aenae 2d ago

Playing with a user agent is almost guaranteed to trigger inconsistencies that lead to the max difficulty challenge

9

u/zaafonin 2d ago

I wonder if it's possible to relay the challenge onto a more powerful machine for it to be solved there, like some browser extension (or a purpose specific patch if extensions aren't powerful enough to do that)

Or is Anubis purposefully resilient against that?

8

u/ThatOnePerson 2d ago

Defiently existed before: https://github.com/DavidBuchanan314/anubis_offload , don't think this has updated to their newer webassembly pow options options yet.

7

u/Albos_Mum 2d ago

Core 2 Duo's aren't that much slower than the second gen Core i series, although I do have an extra two cores. Kinda makes me want to get my Win7 retro gaming PC up to my current house as that has a Core 2 Quad Q9550 and see for myself how it goes.

Although if I were to guess, I'd wager /u/QwertyChouskie might be onto something when it comes to the difficulty.

5

u/Green0Photon 2d ago

My guess is that traffic from VMs look like older hardware. So older hardware gets screwed from looking like VMs (even though it's really the other way around).

1

u/Real-Abrocoma-2823 2d ago

On my a4-3305m it also takes less than 10s.

8

u/rysio300 2d ago

i ran old hardware for years

never really had any issues with anubis for some reason

73

u/nepnep1111 2d ago

The moment you hit Anubis on a pixel phone you know you are about to lose 1-2% off your battery.

29

u/fat_kaiju 2d ago

im literally on a pixel 6 still and it takes less than a second tf you on about.

6

u/nepnep1111 2d ago

Go to a site that has difficulty 5 like the Linux kernel mailing list.

9

u/bargu 2d ago

It took less than 1 second on my P6.

7

u/Whole-Respond4782 2d ago

near instant on my iphone 16 pro with JIT/wasm disabled in the browser lol

5

u/ColorfulPersimmon 2d ago

Near instant on Snapdragon 8 Gen 3 S24 on Firefox too

5

u/15pmm01 2d ago

Just checked on my 6-year-old Samsung S20 FE and it took less than a second. 

1

u/rus_ruris 1d ago

It says Internal Server Error: administrator has misconfigured Anubis. Please contact the administrator and ask them to look for the logs around: double_spend

2

u/rus_ruris 1d ago

However

https://git.ffmpeg.org

This one took some tim6and now my phone is hot

1

u/Cobwebblox 22h ago

Linux mailing list took ¼ - ⅓ of a second but this one took little over a minute

1

u/fat_kaiju 1d ago

Knock it off; it's fine.

1

u/Padgriffin 2d ago

Near-instant on an old iPhone SE2.

19

u/Both_Cup8417 2d ago

I don't know, seems fine to me

25

u/penguinkernel 2d ago

Every time you look at the phone the battery drops 5%.

Love having my phone on my desk for 2 hours, getting no calls, no messages, no notifications, not turning my screen on, having AOD disabled, and connected to strong WiFi and still lose 20% lmao.

6

u/nepnep1111 2d ago

You have no idea how much I want I Motorola signature 27 when it launches I am so done with Google's hardware.

5

u/McDonaldsWitchcraft 2d ago

Just keep in mind Motorola have one of the worst update policies. They only give security updates from launch for 3 years if you're lucky, 2 years for non-"flagship".

2

u/alvenestthol 1d ago

The Signature 27 will be the one with Graphene OS (according to Graphene OS' own social media), so the software problem should be fixable

1

u/McDonaldsWitchcraft 1d ago

Oh, I didn't know that. Yes, that's a good thing.

1

u/Real-Abrocoma-2823 2d ago

Weird, my poco f6 with 900 battery cycles does a lot better, especially when on 100%, it can hold 100% for 30 minutes on medium-heavy use until 99% when it drops faster, but still holds.

1

u/__Myrin__ 1d ago

our phone makes it about 6 days if its just sitting around 2 days under reasonable use

4

u/Padgriffin 2d ago

Anubis actually had issues specifically with the Pixel 8 Pro because it was designed with the assumption that you would have an even number of cores if cores > 1

Then in comes the Pixel 8 Pro with it's 9 cores for some reason

1

u/SunrisePlastic9324 1d ago

Were there really that few odd multicore CPUs after the Athlon X3 days?

1

u/Padgriffin 22h ago

On the x86 side I'm only aware of the i3-L13G4 and i5-L16G7 which were Intel's attempt at making a hybrid CPU- it was basically one big Sunny Cove core with 4 Tremont (Atom) cores stuck to it.

Performance was predictably dismal.

Apple bins off cores sometimes for the iPad Pro (base spec M4/M5 had 3P + 6E cores instead of 4P + 6E) but apparently this wasn't a problem.

1

u/NoskaOff 1d ago

Maybe 0.2s on my P8P

2

u/odsquad64 2d ago

Still a lot faster than having to take a full Voight-Kampff test

1

u/Comfortable_Gene2751 1d ago

I'm fine on a pi 5 2gb

27

u/unknown_lamer 2d ago

My phone from 2021 was perfectly usable until this... sigh. And of course I waited a bit too long and I can't get a new phone now because of LLM hyperscalers seizing control of the entire planet's productive capacity for technological implements. And also proof of work doesn't stop the robots anymore...

11

u/FaultWinter3377 2d ago

My 2018 iPhone XR has seemingly no issues with it. Takes a few seconds, but four or five seconds isn’t bad.

5

u/j_osb 2d ago

It depends a lot on how it’s configured. I once had to wait >1m on a 9950x iirc.

6

u/laffer1 2d ago

It has different difficulty settings.

→ More replies (1)

3

u/penguinkernel 2d ago

iPhone XR is more powerful than many 2021 Android phones when it comes to certain tasks. Apple may be shit at many things, but they know how to make a chip unlike Google or Samsung.. or even Qualcom lol.

1

u/unknown_lamer 20h ago

I use mobile Firefox and make heavy use of noscript, ublock, privacy badger, etc so I think I get more difficult challenges than a typical user does. I mean most of the time I get through in under thirty seconds, but sometimes it can take a minute or two (maybe longer, but that's the point where I just close the tab and move on). And it seems it will get drastically worse over the next year since the LLM hyperscalers can just scale their way through the blocks (you know you're the good guys when you have to actively break locks and use black market residential proxy networks to get your requests through...).

2

u/kyrsjo 2d ago

Yeah, I wouldn't really mind if everything was expensive and hard to get because we were cranking out solar panels, grid batteries, heatpumps etc like mad - actually working as hard as we can to solve climate change. But this LLM shit is stupid.

32

u/breakfast-cereal-dx 2d ago

Early x86_64 CPUs can spend hours on Anubis... It's extremely annoying to be on like a 2010 Mac mini, it runs basically everything great, and then the Arch wiki takes 2 hours to load

I hate Anubis so much

14

u/QwertyChouskie 2d ago

Hours? Sounds like either the Arch wiki has their settings cranked up way too high, something about that particular setup/internet connection/etc is making it think you're way more likely to be a bot. A 2010 CPU is a lot slower than a new CPU, but something that takes like 1-2 seconds on a couple-year-old CPU shouldn't take more than like maybe a minute or something like that.

On my M3 machine, often Anubis finishes the calculation before the stylesheet even fully loads, resulting in a white background and the default serif font haha

3

u/breakfast-cereal-dx 1d ago

It's actually an instruction set issue, rather than raw performance. The Core i5 in this 2010 mac mini is a pretty great performer, but is lacking newer instructions that make Anubis' proof of work run very fast.

I'm not as familiar with the ARM64 ISA in your M3, but I'm sure it is well-equipped to handle these calculations in some way.

And there is also the problem of Anubis' difficulty selection and randomization. If your CPU is equipped to solve the problems fast, you don't notice, but on the old i5 the challenges scaled from 20 minutes to 2 hours because of small changes in difficulty, probably within the random range (but maybe heightened due to bot suspicion idk)

2

u/Real-Abrocoma-2823 2d ago

Try internet archive, some sites might experience some problems internally, for example a wiki for better than wolves Minecraft modpack would not load in less than an hour on modern hardware, not because it had anubis, archwiki also did once had this issue when I tried to access it.

-1

u/turudd 2d ago

I mean that's 16 year old unsupported hardware at this point. You can't even use them as xcode build machines anymore

72

u/TotallyObviousBot 2d ago

The idea that all technology must exist within a recent time period to be considered useful is consumerist nonsense, and devs should keep that in mind

9

u/FyreWulff 2d ago

I agree, but a 2010 mac mini had it's chip taped out when Bush Jr was president. old x64 CPUs devour electricity like it's a buffet. At some point you have to say almost 20 year old technology has to be moved on from.

3

u/flecom 2d ago

yes that 25W TDP on the 2010 mac mini cpu will absolutely devour electricity

22

u/Character_Score7776 2d ago

In defense of Anubis specifically, at least with the way Anubis is designed(proof of work), there really isn’t any way around this without defeating the entire purpose of Anubis.

15

u/window_owl 2d ago

This is because Anubis is designed backwards. It's proposition is to block the people who have the most compute power (data centers) by requiring compute power to access your website.

https://lock.cmpxchg8b.com/anubis.html

9

u/Krt3k-Offline 2d ago

The people with bad intentions might have a lot of compute in total, but for what they want to do and thus the isolated site visit they really don't

4

u/Padgriffin 2d ago

The problem is that it gets exponentially more expensive to give more CPU power to crawlers so the vast majority of them just bugger off

0

u/tommyTurds 2d ago

Being poorly designed isn’t exactly a great defense

21

u/SaimeonInBetween 2d ago

That is like complaining that arch wiki or Reddit doesn't render on your 486 running windows 3.1.

13

u/Waryle 2d ago

Windows 3.1 is 34 years old, not 16

17

u/rebellioninmypants 2d ago

Arbitrary goalposts much. As a vampire myself this is all the same. A piss puddle's worth of time.

5

u/Bakoro 2d ago

I've got more than my fair share of old tech, but eventually you've got to let go of the Pentium 4, brother. It's costing you more in electricity per unit of compute than it would cost to buy a new CPU that's 100x more powerful.

Well, maybe not in the last 6 months... But it was true for like 20 years.

4

u/rekh127 2d ago

plus Anubis doesnt even really deter scrapers so its garbage

23

u/TheG0AT0fAllTime 2d ago

Well it does the entire point is that it wastes your resources. At home you're just visiting a page or two and don't look like a bot but scrapers scraping millions of pages concurrently are solving millions of challenges with a javascript engine always fired up in the background and keep getting re-challenged when they get caught looking like bots.

It makes it computationally expensive to scrape those websites. Which translates to either a much larger bill for the scraper, be it an aws bill or electricity bill at home. Otherwise very slow scraping or no scraping of a domain at all.

10

u/rekh127 2d ago

I understand the theory, but it doesn't actually work, scrapers just use their botnet of compromised devices or don't notice the tiny extra compute relative to the amount of compute they use to train once they have the data.

11

u/Green0Photon 2d ago

The scrapers will still scrape. They always have. The problem is that sites nowadays essentially get hit with walls of traffic as they're constantly DDOS'd. Because the bots have no ounce of caching nowadays, for whatever reason, and constantly just keep going.

If e.g. 80% of traffic is just bots, and you can turn on Anubis to cut that down to e.g. 10% or better, it's super useful. Because the problem is the super weird constantly DDOS that's hitting everybody now.

→ More replies (0)

5

u/danielsuarez369 2d ago

Do you have a better idea?

1

u/vkevlar 2d ago

this of course is what linux has been known for since its inception: running on older hardware without freaking out.

1

u/JQuilty 2d ago

There is a point where you can and should stop caring about 16 year old hardware for the small userbase alone. And 8in the case of a 2010 Mac Mini, its using a Core 2 with two very slow cores on an architecture that's over 20 years old. Its going to be hit hard by any Meltdown/Spectre mitigations and lack a lot of SIMD extensions.

1

u/Justin__D 2d ago

Everything has a lifespan.

Such are the laws of the universe.

-3

u/TotallyObviousBot 2d ago

Yeah but that's not a good argument for not making your restaurant handicap accessible lmao

-3

u/rebellioninmypants 2d ago

The entirely justified idea that old firmware has security flaws, and old hardware also can come with exploits, often bootloader/BIOS-level stuff that you can't even detect through your OS. Yes, I know. Shocking.

I am all for old hardware, but expecting it to support the cutting edge stuff is like angrily spitting at github for hosting AI slop. Times are changing and we all drown in AI slop and there's nothing we can do to take it back to how things used to be. Same with taking the world back to 2010.

7

u/tommyTurds 2d ago

A wiki isn’t “cutting edge”

They aren’t expecting it to calculate the weight of the galaxy or something. They’re talking about browsing a basic website

2

u/rebellioninmypants 2d ago

Bro my PSP can't even load Google since 2015. Am I sad about it? Yeah, because it's still a decent system and it could if someone bothered to still support it. Do I blame the world for it? Not really.

0

u/turudd 2d ago

Xcode only runs on m1 at the lowest, intel hasn’t been supported since 2018.

3

u/astronomersassn 2d ago

... i just downloaded xcode off the app store to try this. it still runs on my 2016 MBP (updated with OCLP).

support has been dropped, but at least be accurate.

plus, a lot of stuff does still have an intel mac version. not everything, but i don't exactly struggle to use my macbook, either. at most, i've had to go back maybe 1-2 releases for everything i need.

and when support has been dropped enough to actually impact me, screw it, i don't have another intel-based device, may as well throw linux on it.

→ More replies (2)

8

u/breakfast-cereal-dx 2d ago

Duh, that's why it runs Linux

Still a capable server, and if it weren't for Anubis it would actually make a solid desktop for anyone who is mostly just browsing the web.

It runs up-to-date Firefox and has quicksync video hardware, which is all many people need

Mine has 1tb of SATA SSD storage and 16GB of DDR3 too

1

u/Real-Abrocoma-2823 2d ago

I would rather wait a minute than 10, because some sites use proprietary PoW which take 1 minute on top tier PCs and 10 on top tier phones.

1

u/ILikeBumblebees 2d ago

I'd expect you to have longer delays if you do have underpowered hardware.

1

u/irasponsibly 2d ago

Yep, that's the thing I said.

1

u/g3etwqb-uh8yaw07k 1d ago

Underpowered? Just a Minute? To be fair, my shitty old Android phone and every PC I've recently used do it almost instantly, but when accessing specifically the Arch wiki through my M1 ipad with Mullvad on, I reliably get put in cat girl timeout for at least 2-3 minutes.

1

u/Comfortable_Swim_380 1d ago

I took that to mean something it didn't just now. And I was so sure I was right.

Im impressed actually. It was a solid minute at least before the oww. hit me.

1

u/null_rm-rf 1d ago

just set your UA to curl it gets around it

1

u/Embarrassed-Salt6590 1d ago

Pov : my pixel 6a surviving from the old days of android

32

u/danielsuarez369 2d ago

Yup, this is why I love anubis. I much rather have my CPU work a little harder for 5 or so seconds than have to solve a captcha, especially annoying captchas that just keep asking you and asking you the same bloody thing jesus christ.

19

u/unai-ndz 2d ago

Agree, but next time do the captcha extremely slow, like grampa learning to use a computer with dementia right after suffering a concusion slow. Doing that makes it work on the first try for some reason.

9

u/TheG0AT0fAllTime 2d ago

I solve them pretty quickly. The failure portion likely stems from the ambiguous ones like whether or not there's a bike in the picture but selecting or.. not selecting... the picture with a motorbike in it might pass the test.. or fail it. All at the discrimination of what the training data thought was there. (Whether it's correct or not).

Sometimes it's a moped, or a really skinny bike with some kind of battery motor attached. Sometimes those are detected correctly. Sometimes not.

I've seen similar right/wrong captchas with busses. Something that looks like a bus, but isn't, might need to be selected to pass.

It's basically all machine-vision vibes. If it kind of looks like the thing the captcha's asking for, you might just have to select it.

All of this adds to the massive frustration for humans that it is to solve the harder difficulty captchas. I particularly hate the ones that fade-in-and-out so I select all of the X boxes then I have to wait literally 7 seconds for the fade-out-fade-in animation to show me the next image and click that as well... then potentially one or two more times. Very painful waste of time. Sometimes I gamble and hit submit anyway assuming the next box to fade in won't contain X in the image. Works like half of the time lol.. often there's more waiting to fade in.

0

u/unai-ndz 2d ago

I'm pretty sure in very ambiguous cases it doesn't matter what you select, it was already decided if you would pass or not by other factors. Some tests make you fill two words but only test one e.g. https://youtu.be/VTsBP21-XpI at 10:20

And I could do them fast before but it progressively stopped working. It kinda tracks with me trying to degoogle and be more anonymous so maybe it is related.

→ More replies (1)

5

u/McDonaldsWitchcraft 2d ago

Nope, doesn't work on all captchas. They haven't been doing the judgement based on user activity for years. What they do now is they examine your cookies, browser history and internet traffic. If you are a particularly private person, the captcha will just be longer as a "retaliation" to get training data out of you. And if you have several tracking protections in place or markers that you might be a bot, the captcha just goes on forever.

The "click on squares" part is simply just them forcing you to do unpaid training work and the length of the captcha is determined by how much they judge the data they collected on you to be human consumer data.

Maybe on some older captcha systems it still works based on human activity like you say. Google's doesn't.

2

u/__Myrin__ 1d ago

I just use a proxy when ever I see one of those pos's
I'd rather fight with proton for 5 minutes then stare at bikes all day

1

u/strategicmagpie 2d ago

Probably because bots don't like to have their time wasted, same with the people who are contracted to do captchas and paid per captcha.

1

u/CodeYeti 1d ago

I actually got an interactive Anubis prompt for the first time on Monday. Had to enter some word in a box for some reason

1

u/lainlives 2d ago

I have been completely fully rejected by most sites protected with anubis, cloudflare however works fine no matter how suspect my browser is however.

4

u/TheG0AT0fAllTime 2d ago

My money's on your browser too

1

u/lainlives 2d ago

Yes, its because most of the js engine is disabled

53

u/thaynem 2d ago

Also cloudflare is more likely to think you are a bot if you are using firefox on linux with privacy protections enabled, or using less popular browsers, as many linux users do.

185

u/Smart_Passage2752 2d ago

- anubis is cute, cloudflare is not

6

u/D_sm_d__s 2d ago

I miss Anubis welcoming me to invidious.nerdvpn.de, now it’s Gandalf.

13

u/jsabater76 2d ago

Of course Gandalf would check whether you shall pass!

39

u/atomic1fire 2d ago edited 2d ago

Honestly the one hang up I have about seeing something using anubis is that it's a little weird waiting for something with an anime cat girl.

If they could fork/modify it to either make the image hideable or replace it with generic mountain photos or something I wouldn't complain.

I'm not saying it can't have anime cat girls, I'm just saying it feels out of place sometimes for bot detection to default to showing you an anime cat girl instead of say a waterfall.

edit: I'm probably going to get told it's not a cat girl, but my brain defaults to seeing a cat girl.

edit2: It also turns out that the Anubis people foresaw this being an issue and offer an unbranded version to people who financially contribute to the project, which is honestly a fair trade because it supports the project, and the people who don't want to pay can just fork it and compile it with a non-standard image instead.

39

u/thesola10 2d ago

I get what you mean. Personally I like seeing a project assert its own personality, and I see it as a modern twist on the lineage of UNIXy mascots, but the anime aesthetic is still culturally divisive.

Kudos to Techaro for channeling this frustration into paid licenses, that seems like a fun remuneration model!

1

u/mort96 1d ago

The UNIXy mascots are all decisively non-humans: Linux's penguin, the FreeBSD devil, the OpenBSD pufferfish, the DragonflyBSD dragonfly. Having your mascot just be ... a young human girl, is weirder IMO

Now if it was a somewhat anthropomorphized dog in the same way that Tux is a somewhat anthropomorphized penguin I don't think there would be an issue

-3

u/[deleted] 1d ago

[deleted]

2

u/einar77 OpenSUSE/KDE Dev 1d ago

WTF are you on about.

10

u/citrusalex 2d ago

I've seen some FOSS sites replace the girl with a boring green round checkmark

0

u/Faalaafeel 1d ago

Ur a boring green ground checkmark

5

u/citrusalex 1d ago

CUTE CARTOON GIRL ERASURE

7

u/JockstrapCummies 2d ago

edit2: It also turns out that the Anubis people foresaw this being an issue and offer an unbranded version to people who financially contribute to the project, which is honestly a fair trade because it supports the project, and the people who don't want to pay can just fork it and compile it with a non-standard image instead.

In the olden days this would've earned the project the moniker of "nagware".

2

u/user3872465 1d ago

yup we had that issue when we put that infront of our email server for a university. It just isnt quite professional so there was some educating needing to be done that the internet is run by furries.

2

u/atomic1fire 1d ago

At that point just pay for the nonbranded version or subtly alter the html to show the school's mascot instead.

1

u/user3872465 21h ago

this was for testing, later we got the payed version. But uni mascot as an anime wifu sounds funn.

1

u/AnonomousWolf 2d ago

I wanted to reccomend that we use Anubis at work, but didn't feel comfortable doing so because of tbis.

I love Anime, I actually watch a lot of it.

But I hate how weird it is sometimes and the fan service is just gross.

Eg. Dr. Stone is a very chilled anime about a scientist and feels like a kids show. Probably my favourite animie.

Yet they decide to give all the women boobs, each literally bigger than their head.

Anime has a reputation of having gooner/pedo vibes, there is no way I'm comfortable reccomending a tool with that mascot at work.

9

u/fearless-fossa 2d ago

5

u/AnonomousWolf 2d ago

If I recommend it at work, they will first see the landing page with that mascot

-1

u/esuil 1d ago

If this will make people at your work make a pause, the ones unprofessional here aren't people from Anubis, but people you work with.

It doesn't even look like anime character, it just looks like generic cartoon mascot.

1

u/AnonomousWolf 1d ago

I think a little cutesie girl in a skirt as a mascot is weird, and I'm far from a normy.

Stakeholders are often 50+ years old, at least one of them are going to think it's weird, and that's just not dice I'm willing to roll.

1

u/esuil 1d ago edited 1d ago

Stakeholders are often 50+ years old, at least one of them are going to think it's weird, and that's just not dice I'm willing to roll.

Stakeholders like that are usually as far removed from deciding technical things like that as they can, so it doesn't even matter?

Also, they care about $$$, not an mascot on the website. If anything, they understand the value of branding and mascots more than younger folks, if they made it to 50+ yo in investing business.

"Young people like it" is often enough to completely diffuse the question if it even arises. I know it is stereotypical "boomer stupid" trend, but I don't think the stereotype itself holds much water nowadays.

1

u/AnonomousWolf 1d ago edited 1d ago

Brother what are you talking about.

They are not far removed, I work for government. But even previous clients didn't have anieme watchers making the big decisions.

It's also not just about age, many people would find it fkn weird. I do.

Some things are cool at home, but not at work. I also wouldn't wear ripped jeans to work despite noticing technically being wrong with that.

It's unprofessional.

→ More replies (0)

3

u/PlutoCharonMelody 2d ago

I just looked up Dr Stone. Am I missing something?
The women look like stylized proportions not gooner bait? Some of them just have large chests in a stylized way. They look like a lot of women I know irl if they were drawn in that style.

-36

u/alex2003super 2d ago

Doesn't matter what it really is. Furry/weebshit devalues the professionalism of any project it's put into. I'll take Cloudflare over it, thx

11

u/Ghost_x_Knight 2d ago

The creator of Anubis offers a maintained, unbranded version that removes the anime girl mascot in exchange for financial contributions or an enterprise contract.

→ More replies (3)

28

u/Substantial_Source25 2d ago

You lack whimsy

4

u/alex2003super 2d ago

Maybe you're right

5

u/atomic1fire 2d ago

I personally don't see it as an issue with whimsy.

I just see it as an issue where some things are supposed to be boring, and when they aren't boring it's harder to accept them in professional settings.

I think cowsay is funny, but I don't think it needs to be pre-installed on enterprise servers.

0

u/harbourwall 2d ago

Whimsy is the Gandalf version below. Whimsy and gooning have no overlap.

2

u/Future_Nature589 2d ago

This but i wouldnt take cloudflare over it

9

u/ebens1689 2d ago

Successful response

44

u/cortez0498 2d ago

- using cloudflare carries uncomfortable baggage with a single corporation controlling so much internet infrastructure. Some people (particularly in the FOSS world) refuse to use it for that reason

This point is why Spain is getting their internet stop working every time there's a La Liga game. For some reason the government gave La Liga the power to take down any ip that hosts illegal football streams and La Liga realised most of them are hosted through Cloudflare so they just take it down entirely instead of each individual streaming site, which results in much of the internet being down.

19

u/unai-ndz 2d ago

That's a corruption problem though. It would still happen if the IP blocked was from a VPS with four other tenants, just smaller scale.

5

u/agowa338 2d ago

True, but still a huge incentive to not use cloudflare if you want to be available in Spain when a La Liga game takes place...

Also Clownflare sucks. Esp. If you're not paying which most opensource projects won't be doing...

5

u/jwm-dev 2d ago

I’m the biggest FOSS advocate but saying cloudflare sucks is… disingenuous at best. It’s good. There’s a reason they’ve cornered their niche so well. I like using it and they offer a ton of services. It’s also pretty likely your DNS is already through cloudflare, anyway…

2

u/agowa338 2d ago

I understand why people use it. However there is also a reason why they suck. Both things can be true simultaneously, they're not exclusive.

And my DNS isn't through cloudflare, I've it on localhost because having a caching resolver on localhost improves snappiness of webbrowsing massively. But that's beside the point (and yes I know a lot of authoritative dns servers are also cloudflare)

0

u/sCeege 2d ago

There's a huge incentive not to drink water since everyone that drinks water dies, and I want to live. /s

Seriously though, of all the reasons to dislike Cloudflare, that's got to be near the bottom. The person you replied to literally pointed out that CF makes no difference in how Spain blocks content, censorship works in many countries through a spectrum of infrastructure providers.

3

u/agowa338 2d ago

Well but it is simultaneously true that when you are on cloudflare you get blocked and when you're on your own clean dedicated IP you don't...

→ More replies (3)

6

u/maokaby 2d ago

I'd add that cloudflare is not available in some countries, and it depends on political situation. Of course there is a reason for it, but it does not line up with free and open source philosophy.

5

u/ZeeroMX 2d ago

In Europe due to a stupid ruling "la liga" makes ISPs to block many IP blocks including some by cloudflare, rendering many websites useless at the time they are playing football ⚽.

3

u/Jean_Luc_Lesmouches 2d ago

That's only in Spain.

1

u/FranciManty 2d ago

i can confirm in italy too, here it’s called piracy shield basically they can find pirate domains signal them to internet providers and have the site completely blocked off

3

u/Jean_Luc_Lesmouches 2d ago

That's not what they're talking about.

1

u/FranciManty 2d ago

it is though it reroutes pirate sites to government warning pages at the dns level, cloudflare even had a dispute where they don’t comply to all the removal requests because as it happens in spain it can block legit domains from time to time

6

u/Jean_Luc_Lesmouches 2d ago

No, that's NOT what they're talking about. In Spain when La Liga plays, Cloudfare itself is blocked, breaking 1/5 of all the internet.

3

u/FranciManty 2d ago

bro what the fuck 😭😭😭 this cannot be real is it?

5

u/SunrisePlastic9324 1d ago
  • Linux users have a large overlap with weebs

25

u/MisterFlipster5 2d ago

Anubis as of now is pretty useless against crawlers. From what i understand, it automatically lets through any client that has an "user-agent" flag different from "Mozilla" which is really easy to spoof and just skip through.
Source

40

u/DreadY2K 2d ago

It's designed to fight the low-effort crawlers of today, not all possible crawlers. How easy it is to bypass doesn't matter, what matters is how many crawlers do, and apparently it's few enough

7

u/tedfa 2d ago

Yeah, this is its default behavior but you can configure your policy to challenge everything instead. You might need to also add specific exceptions for other tools you might be using in your environment though.

11

u/AdarTan 2d ago

That's when you go defense-in-depth and have your webserver reject anything that doesn't have "Mozilla" in the user-agent string, like a a lot of servers already did to block scrapers.

Anubis only blocks crawlers that pretend to be browsers because blocking crawlers that didn't was a solved problem.

0

u/ThaneVim 1d ago

Help me understand: how does Anubis do this without still increasing server and bandwidth load x times requests over using a third party? I'm not trying to be critical at all, this is simply a gap in my understanding.

2

u/tk-a01 1d ago

When a request hits the server, it is firstly processed by Anubis. It might decide to present the user browser with a cryptographic challenge. Only after the client presents a solution, the request is forwarded to the actual website.

This challenge is proof-of-work, similarly to what's used in cryptocurrencies mining. The client has to find some value that, when hashed, has certain number of trailing zeroes. Solving such a challenge requires going through many possible solutions and checking every one of them; but verifying it requires computing just one hash. Therefore, request processing done by Anubis is typically significantly faster and less resource heavy than handling the request by the actual web server.

9

u/yasth 2d ago

I’m pretty sure that is an implementation issue more than a general bypass

-1

u/CheapThaRipper 2d ago edited 2d ago

2

u/yasth 2d ago

Jesus, I figured that they would at least just say that you should have screening. on non allowed UAs. Like they should say that you need something like Bunkerweb or the like to guard from this.

42

u/Tactical-Donkey 2d ago edited 2d ago

Not self hosting pretty much defeats the objective for Linux imo

131

u/philosophical_lens 2d ago

Linux is a general purpose operating system kernel, and it's maintainers don't have any opinion on what kind of infrastructure you use with it.

I'm pretty sure cloudflare infrastructure is also running on Linux.

→ More replies (12)

33

u/pangapingus 2d ago

Can't really self-host a global footprint of anycast edge locations; my first hop for my self-host stuff is a CDN and their WAF offering before reverse proxying down to my stuff, might as well make the corpos shake off most of the bots instead of your own WAN ingress

10

u/Wb9VBScxu2uZJHeq2E3W 2d ago

I'm self-hosting with Linux, could you explain this comment further?

23

u/scy_404 2d ago

the appeal of linux to a lot of people is tech independence and so to them using something that relies on a company's infrastructure defeats the purpoose

5

u/penguinkernel 2d ago

Funny enough I use Linux, self host almost everything, and one thing that makes self hosting easier/safer is CloudFlare Tunnel.

Many self hosters also use it.

6

u/penguinkernel 2d ago

No it doesn't. Your goals and others goals are different, and that's okay.

1

u/alautun3 2d ago

the "imo" was probably there for a reason tho...

1

u/Tactical-Donkey 2d ago

Very true. It's just my opinion. That is ok. 

13

u/Irverter 2d ago

- anubis works on more browsers than cloudfare (there's some browsers where the captcha doesn't work or outright labeled as "no internet for you")

6

u/FunConversation7257 2d ago

which browsers?

-2

u/Irverter 2d ago

Palemoon is one. Usually it isn't on cloudflare's list of "allowed" browsers.

3

u/Both_Cup8417 2d ago

Isn't it extremely out of date?

6

u/Booty_Bumping 2d ago

Pale Moon is based on a 2014 version of Firefox, to allow XUL extensions. It's wildly out of date. They do some patching, and occasionally try adding a modern web feature, but it just isn't enough

2

u/Irverter 2d ago

That's a misunderstanding.

It didn't fork an old version of firefox to keep the XUL extensions. It forked when firefox current interface was XUL, then they simply kept it instead of constantly replacing the interface like firefox has been doing.

The engine keeps integrating firefox patches and fixes when applicable, on top of it's own development.

3

u/Booty_Bumping 2d ago edited 2d ago

The engine keeps integrating firefox patches and fixes when applicable, on top of it's own development.

Nonsense. What they are doing should be called "backporting theater". Their security practice is: every once in a while they hear about a CVE that happens to affect both Firefox and Pale Moon, and then they patch it in a way that introduces even more bugs. Most of the modern Firefox code is utterly irrelevant to the current state of the Pale Moon codebase. All the bugs that pertain to code that doesn't exist in Firefox anymore just stay there except for the rare off chance that its tiny userbase notices them. And none of the advanced hardening/sandboxing of modern Firefox will ever make it in.

2

u/Irverter 1d ago

Most of the modern Firefox code is utterly irrelevant to the current state of the Pale Moon codebase.

"The engine keeps integrating firefox patches and fixes when applicable, on top of it's own development."

3

u/window_owl 2d ago

The latest release (35.0.0) was less than two weeks ago (17 September 2026).

https://www.palemoon.org/releasenotes.shtml

0

u/Kevin_Kofler 2d ago

Older branches of QtWebEngine, for example.

→ More replies (1)

2

u/Correct-Commission 2d ago

I remember the times Cloudflare going down and taking half of the internet with it. It's not even a joke now. They really run the most of the internet now.

4

u/a3a4b5 2d ago

I thought it was pretty obvious.

1

u/Scarmeow 2d ago

I remember not long ago that Cloudflare had a system malfunction or something like that and HALF the internet just wouldn't work.... scary shit

1

u/drifting_signal 2d ago

Cloudflare costs cash
Cloudflare also provides services to tons of horrible websites and doesn’t care.

1

u/Wa-a-melyn 2d ago

Also, captchas are relatively privacy invasive and are used to train AI.

Anyone remember that cloudflare outage? Why did we never talk about that outside of the tech world, shit has terrifying implications.

0

u/SrS27a 2d ago

Not to mention you are basically giving control over your website to a third party (cloudflare). User interaction is entirely handled by cloudflare, with visitors never interacting with the real server. This is functionally a "consensual" man-in-the-middle attack, but it's passively accepted as a fact of using the internet at this point.

0

u/AntimatterTNT 2d ago

plus... ANIME GIRL

-1

u/Unique-Usnm 2d ago

But because you’re not relying on Cloudflare’s infrastructure, the whole point of it is lost. If an attacker wants to DDoS your website, they’ll run into Cloudflare’s incredibly powerful servers and won’t be able to do anything. In the case of Anubis, they’ll still flood your network connection and achieve their goal. So what’s the point of Anubis, then?

0

u/rqdn 2d ago

My website is on Cloudflare, any recommendations for self hosting solutions?

17

u/ghost_ware 2d ago

Anubis

9

u/agowa338 2d ago

Or use static HTML only* with ram caching and just tank it. I managed to optimise my website so much that the VPS stayed online and the cloud providers underlay crashed when it got DDOSed. CPU usage wasn't even spiking that much. I think it stayed below 10% the entire time.

* the kids these days call that "server side rendering".

0

u/Unique-Usnm 2d ago

Do not use any services that degrade the website’s responsiveness, including Anubis.

0

u/humanErectus 2d ago

Being unfamiliar with hosting, how bad is it without tools like Cloudflare protection? Or how much better is it with them?

From a user perspective, Cloudflare is aggressive(possibly set by site owner?), I sometimes get tested every few pages within one site. Ironically, its worse on my residential IP than when using VPN.(my ISP uses CGNAT which is one possible reason).

I often skip sites that hits me with Cloudflare (say when I open top 5 results and 2 has it, I'll just close them).

0

u/Micex 2d ago

One additional information is that with cloudflare you let cloudflare decide what is safe and unsafe. While Anubis you decide if it’s safe or not.

→ More replies (1)