• 1 Post
  • 942 Comments
Joined 2 years ago
cake
Cake day: April 30th, 2024

help-circle


  • You are right. For most self-hosting usecases anubis is not only irrelevant, but it actually works against you. False sense of security and making your devices do extra work for nothing.

    Anubis is though for public facing services that may get ddos or AI scrapped by some not targeted bot (for a target bot it’s trivial to get over Anubis in order to scrap).

    And it’s never a substitute of crowdsec or fail2ban. Getting an Anubis token it’s just a matter of executing the PoW challenge. You still need a way to detect and ban malicious attacks.


  • I don’t think you have a usecase for Anubis.

    Anubis is mainly aimed against bad AI scrappers and some ddos mitigation if you have a heavy service.

    You are getting hit exactly the same, anubis doesn’t put up a block list or anything. It just put itself in front of the service. The load on your server and the risk you take it’s very similar anubis or not anubis here. Most bots are not AI scrappers they are just proving. So the hit on your server is the same.

    What you want is to properly set up fail2ban or, even better, crowdsec. That would actually block and ban bots that try to prove your server.

    If you are just self-hosting with Anubis the only thing you are doing is deriving the log noise towards Anubis logs and making your devices do a PoW every once in a while when you want to use your services.

    Being honest I don’t know what you are self hosting. But at least it’s something that’s going to get ddos or AI scrapped, there’s not much point with Anubis.

    Also Anubis is not a substitute for fail2ban or crowdsec. You need something to detect and ban brute force attacks. If not the attacker would only need to execute the anubis challenge get the token for the week and then they are free to attack your services as they like.


  • It’s possible with certificates and 2fa issued by a government, which already have all your data, that would only verify that you are over 18.

    We already have that in Spain, sort of. We have a government app where you have a digital id stored and you can make it create a verify qr that only shows if the user is over 18 or under 18, no more data. The qr only last 5 minutes active.

    It is necessary? Not for internet access. That’s a duty of the one paying for internet in the household, not the government. If they have underage kids under their responsibility it’s their duty to make sure that they get good education about what to see and what not and restrict access if needed. Having the government to universally interfere everyone it’s just plain bad.






  • I still mess around in some traditional forums and I do not miss them.

    The time bias is much bigger. First comments are usually the only ones people read and replies. If there’s a great comment in page 5 no one is going to see it. But if there’s a troll comment in page one it is on everyone’s faces. Karma system fixed that.

    It’s true the thing about usernames and avatars. But I prefer not to personalize a lot so for me that’s also a plus, I can focus in the comment and not in who has written it.