Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

46% Positive

Analyzed from 2069 words in the discussion.

Trending Topics

#anubis#scrapers#don#more#compute#bots#https#problem#cost#pages

Discussion (77 Comments)Read Original on HackerNews

vintagedaveabout 2 hours ago
> In my experience the kinds of people who run this exact combination of circumstances also tend to be the kind of people that have a wide variance in the level of kindness they display to the authors of open source programs that happen to be in their way.

Love this. There’s been past discussion on HN re how OSS maintainers are treated, and this is such a wry sentence. I really appreciate the tone / attitude to the problem.

jezek217 minutes ago
Great article, WebAssembly is such a good technology when you have use case for it.

I've just finished creating a WASM 1.0 implementation (simple JIT on x86 and x86_64) for plugin usage and I'm looking on how to support more languages beyond C (for which I have "micro-libc" to create really small binaries). In particular C++ and Rust so the article contains useful info for that. C++ that would be more problematic I think, would have to resort to full Emscripten or something... I've tried to compile standalone C++ stdlib but wasn't much sucessful yet.

BTW, I see in the screenshots you also test Firefox, I think it would make sense to test the latest two ESR versions (these are often used by Linux distributions).

raincoleabout 2 hours ago
It's still very unclear to me how Anubis is supposed to work in the long term or even the medium term. The assumption is that scrappers, a.k.a. AI companies, a.k.a. those who hog all the RAM, are short of memory...?
solid_fuelabout 2 hours ago
The assumption is that requiring 1 second of compute before allowing a page load will have more impact on the people requesting 1000 pages/sec than it will on consumers requesting 1 page every minute.

Personally I don’t understand where this confusion comes from - it’s a simple economic tactic. Yes the large scale scrapers won’t run out of compute but putting anubis in front of a website demonstrably reduces the amount of crawling and that is the entire goal.

Aachenabout 2 hours ago
> requiring 1 second of compute before allowing a page load

After 1 solve, you get a cookie and can load tons of pages with it. Scrapers and user agents alike will need to spend the compute only once to get a valid session for themselves

Seems to be working so far though. Fwiw, lots of silly things stop bots until someone puts their mind (or tokens) to bypassing it, and then the blocking mechanism has to adapt. We'll see how it plays out, for now it's a lot better than begging big brother (cloudflare, google, or amazon captcha) for access, so I'm quite appreciative of what Techaro is doing

jdlshoreabout 2 hours ago
The issue is that scrapers are rotating their IP and essentially performing a DDoS attack. Anubis is part of a defense-in-depth solution. If scrapers reuse a cookie, traditional anti-abuse mechanisms will work.
mitxelaabout 1 hour ago
If you change your IP address, it invalidates the cookie. If you don't change your IP address, you can be blocked by IP address.
drum55about 2 hours ago
It’s not seconds though, it’s in the order of tens of milliseconds of work, it’s faster to complete the challenge than most http requests will take.

last difficulty 5 nonce 645376 in 9 ms (101.6MH/s, avx512-x16)

This takes many minutes to solve on a cellphone, 9 milliseconds on a cheap VPS. It’s not stopping anyone.

bombelaabout 2 hours ago
Yep, on my aging phone it takes quite w noticable amount of time to go through. But on my more recent laptop wnd workstations, it's a quick flash of a manga lolita.
Jtariiiiiabout 2 hours ago
>It’s not stopping anyone.

You could just spend 30 seconds googling instead of confidently asserting nonsense. There are plenty of people demonstrating that Anubis reduces bot traffic.

gruezabout 2 hours ago
>The assumption is that requiring 1 second of compute before allowing a page load will have more impact on the people requesting 1000 pages/sec than it will on consumers requesting 1 page every minute.

Which doesn't hold. A 1s delay, despite being inperceptible is still a cost to human users. After all, 3600 x 1s delay adds up to an hour. Worse yet, the typical human visitor will always have to solve a challenge, because chances are it's the first time they're visiting your blog or whatever. Someone scraping reuse a valid session for at least a few more pages.

There's also the problem of time. It might be tempting to think the cost of a challenge is 1M cpu cycles or whatever, but the cost is better modeled as two parts, a time cost (for the human) and a cpu cost (for the computer). A scraper might have to pay the cpu cost, but not the time cost, because they can have their scraper solve challenges in their sleep. Unless the user is utterly destitute, their time is worth far more than whatever the compute cost is.

peri-cl13 minutes ago
There was a lot of discussion (715 comments) about this question a couple days back, if anyone missed it. It was the thread about kernel.org sharing their anubis stats.

https://news.ycombinator.com/item?id=49491791 ("Creepy Crawlies (kernel.org)")

https://people.kernel.org/monsieuricon/creepy-crawlies

I was particularly struck by the ASIC estimates 'semiquaver shared.

fc417fc802about 2 hours ago
The assumption is that there will always be some population distribution in terms of effort expended as well as in terms of problems caused. At present it's the lowest effort actors that are causing the highest number of problems. So an 80% (or even just a 20%) solution largely solves the practical problem faced by site operators.

If against all odds it turns out that skiddies (or agents or AI billionaires or what have you) are willing to burn inordinate amounts of RAM and CPU just to scrape autogenerated cgit pages that are of approximately zero value to them to begin with then I guess we'll just have to cross that bridge when we come to it.

XorNot5 minutes ago
Okay but it's like no RAM at all. Thats the problem: you've got stupid bots causing a bunch of issues - these can be stopped.

And then regular users: who now can't really browse your site.

And then smart bots - anyone with even a moderate amount of funding in the AI space, who aren't even slightly slowed down.

The solution basically makes the favored customer well funded AI scrapers, not users.

kccqzyabout 2 hours ago
Hats off to Xe for spending so much time on backwards compatibility, especially the tidbit about targeting Chrome 66.

I have a Mac from 2014 running Yosemite that I occasionally use to test for backwards compatibility in my own frontend code (for fun!). But IMO the best way to ensure compatibility is to use period-correct toolchains or toolchains where the pace of change is slower, like ClojureScript.

0x696C6961about 3 hours ago
It would be cool if the POW could be done ahead of time. That way I don't get stuck waiting while I'm working. Some type of credit/tokens that my browser could then spend.
xenaabout 3 hours ago
I'm working on this with a private prototype. I'm probably going to lean towards using a Service Worker (https://developer.mozilla.org/en-US/docs/Web/API/Service_Wor...) to renew challenges at a reduced difficulty. Stay tuned!
gruezabout 2 hours ago
That just creates another problem: if you're taking any measures to reduce tracking (ie. clearing cookies on shutdown or using temporary containers), this won't work. If anubis was being deployed on a site that a user visits often (eg. HN), the user might be convinced to whitelist it, but most anubis deployments are on random blogs or fediverse instances that I might not visit again in months. I'm certainly am not going to whitelist those sites, nor am I going to enable cookies wholesale just to avoid solving challenges.
xena29 minutes ago
Look, if you're going out of your way to break expected behaviour on websites you shouldn't be surprised when people code to the most common denominator and then you have weird subtle breakage as a result.
lxgrabout 2 hours ago
Or something that shadier websites could calculate ahead of time in your browser, then spend on your behalf.

I feel like Anubis is ironically speedrunning a lot of discoveries the crypto folks have already made several years ago...

tomodachi9434 minutes ago
Privacy Pass does something similar to what you describe: https://developers.cloudflare.com/waf/tools/privacy-pass/
dist-epochabout 2 hours ago
Then we could implement an exchange, so that if you generate too much Anubis POW, you could exchange it with others.

We could link it to a site, you generate for HN, I for Reddit, but it so happens that you visited Reddit more and I HN, so we depleted our Anubis POW, so we could exchange some Reddit Anubis with some HN Anubis.

ssl-3about 2 hours ago
And then, we can inextricably link it to a new cryptocurrency -- let's call it BotCoin -- and make Sam Altman pay for it!
kelvinjps10about 2 hours ago
Basically reinventing crypto one step at the time.
packetlostabout 3 hours ago
I wonder if you could convince the Anubis author to implement x402 payments to bypass the PoW
miralineabout 1 hour ago
The interesting part is that bots mitigation is actually an economic problem. You don't need to make scraping impossible, you only need to just make it expensive enough so that abusive traffic stops being worth it.
mitxelaabout 1 hour ago
Scrapers scrape all sorts of nonsense, notably every possible git diff from git hosts. They clearly aren't concerned with rationality.
XorNot2 minutes ago
Scrapers scrape every link they can find.

The git host example is probably the one which Anubis is the dumbest defense for: the main reason to have those links is for easy machine interaction. So that's dead when you implement it.

So why even host the links? It's a git repo: send them a local got client and let them clone the repo in browser or something.

omoikaneabout 1 hour ago
> This means that adding one (1) to the difficulty of a challenge makes it 1024 (one thousand twenty-four) times as hard to solve in the worst case.

I don't understand the units here, wouldn't a bit versus nibble difference make the multiplier 16, instead of 1024?

xenaabout 1 hour ago
Oops, there's your proof I didn't write this with AI! Fixing, sorry.
Aachenabout 2 hours ago
Is there a place where I can try out if my browser is compatible? Easier to find out now than when I'm trying to get work done and a million websites now have it deployed

On https://wasm-feature-detect.surma.technology it shows that I don't have 3 of all these features but I'm not sure if Anubis needs any of them to not kick me back to the pure JS solution

Which would apparently be bad because

> The WebAssembly that's shipped with this flow is ridiculously performant. This may mean you need to adjust the difficulty [upward, to avoid that bots solve it trivially when they support wasm, I assume this means]

combined with

> The wasm2js flow doesn't currently have a way to update the progress bar [so you have no clue about remaining time]

(wouldn't be the first time that I gave up on a page because it was stuck on 0 hashes per second)

anthoniksabout 1 hour ago
I think the idea is to just raise marginal costs for scraping high enough to make it expensive and non-profitable.
evmarabout 1 hour ago
I think the Rust feature you’re looking for regarding recompiling the standard library is called “build-std”, that should be enough for you to search for it. (For similar reasons you also need that flag if you are trying to use Rust to build multithreaded wasm binaries, so it might come up for you!)
tefkahabout 2 hours ago
thanks for trying to make the web suck a little less these days xena!
Advertisement
arjieabout 2 hours ago
Anubis is fine if you want to block bots that are bothering you, but I never understood why they don't have robots.txt at the root level too. I happily obey that for my private crawler. I suppose you don't want to duplicate implementations. Fair enough. I guess I should add an Anubis detector so I can just blacklist because that person clearly doesn't want bots.
mitxelaabout 1 hour ago
In this day and age, only good bots, the ones you actually want, obey robots.txt. You obtain no benefit by having a restrictive one.
xenaabout 2 hours ago
One of the standard library rules enables robots.txt passthrough by default. I can't control people not choosing to use it.
arjie10 minutes ago
That makes sense, Xe, but you don't enable it at:

- https://techaro.lol/robots.txt

- https://anubis.techaro.lol/robots.txt

and the latter (at least) is Anubis protected. It could be just an omission. But if it's intentional, I am just curious why so that as a bot author I can be well-behaved.

stephenlfabout 2 hours ago
Comparatively, this is what it's like getting all of this working across browser versions, platforms, and so many other things:

…<img not found/>…

I don’t know what this picture was supposed to be, but a 404 demonstrates your point perfectly well.

xenaabout 2 hours ago
Refresh, the Anubis docs site regenerates its cookie secret on every deploy as part of the "holy shit did I break everything?" verification step.
Retr0idabout 3 hours ago
See also:

https://github.com/eternal-flame-AD/pow-buster - Browser extension that already used WASM to accelerate the anubis solver, among others.

https://github.com/kasper93/anubis_webgpu - Browser extension that uses webgpu, for another order-of-magnitude speedup (depending on your GPU of course).

throawayontheabout 3 hours ago
afaik argon2 should make the GPU less helpful
dist-epochabout 2 hours ago
Argon2 is already GPU-accelerated.
chewsabout 3 hours ago
It's wild to me that PoW systems are how we sort the bot problem... the bummer is that all this "work" is just wasted cycles, at least in crypto there is a token you can sell.
Levitatingabout 3 hours ago
> at least in crypto there is a token you can sell

That would defeat the purpose. The goal is to make scraping costly, not profitable.

articulatepangabout 3 hours ago
Scraping would be costly in this world: scrapers would have to spend tokens in order to get the webpage.

But, in this world, the website owner would receive tokens that they can then use to do whatever they want, including paying for servers and bandwidth. This is the sense in which the cycles aren’t wasted: the website owner now has cash to spend.

Effectively, both scrapers and ordinary users would be paying for the privilege of getting website bytes.

This also solves the problem of having to wait for your phone to solve the challenge while you’re browsing: you can buy or mine some tokens ahead of time and pay them as soon as challenged. So can the scrapers, but because they’re accessing enormous numbers of pages it’s hopefully prohibitively expensive for them.

cozzydabout 3 hours ago
I guess it could in principle be profitable for the website, not the client?
xoscabout 3 hours ago
unfortunately at that point it would be indistinguishable from running cryptojacking on your website
TacticalCoderabout 3 hours ago
Yup was thinking the same: make honest people pay $0.00001 when they visit the site (in electricity/compute), have the challenge made so that only the website wins a tiny something. Bleed the bots dry.

> This makes Anubis challenges use a memory-hard proof of work function (argon2id) instead of just a CPU hard one. It also means that the "hey Claude vibeslop me a CUDA Anubis solver" route is on its way to being fundamentally dead.

Nice.

saagarjhaabout 3 hours ago
Sure, then just replace it with something that is useful to society but not immediately profitable to a scraper, like science research
xenaabout 2 hours ago
I want to do this eventually, but it's hard to split things into the micro-tasks that would be required to make this work on Anubis. One of the ideas I'm throwing around is a world where Anubis helps fuzz old games to find timesaves in tool-assisted speedruns. It's harder than you think.
odo1242about 2 hours ago
Well, there was CoinHive which did this exact thing 6-7 years ago, but that system got abused a bit much
CarVacabout 2 hours ago
PoW was originally anti-spam technology.
kingstnapabout 3 hours ago
> hey Claude vibeslop me a CUDA Anubis solver" route is on its way to being fundamentally dead.

Lmao yeah no. I don't think a little argon2 is going to change shit all.

I mean the thesis of Anubis itself is "scrappers are compute limited (in ways that consumer devices are not)" which has its own massive flaws.

Jtariiiiiabout 2 hours ago
The goal isn't to eliminate scrapers, its to prevent a distributed scraping network from requesting 10000 pages a second each from 10000 different websites.
lxgrabout 2 hours ago
Yes, I also strongly suspect that this is only going to move more parts of scrapers onto consumer devices. The egress proxies are already there, why not use a little bit of the compute as well?
fwip25 minutes ago
When you force a low end device to burn CPU or fill ram constantly, the owner throws it out and buys a new one.