Elektrine lite

← Feed

@Codeberg@social.anoxinon.de

Post #2836500

2025-08-15 17:11 UTC

@Suiseiseki@freesoftwareextremist.com Anubis is the option that saved us a lot of work over the past months. We are not happy about it being open core or using GitHub sponsors, but we acknowledge the position from the maintainer: https://codeberg.org/forgejo/discussions/issues/319#issuecomment-6382369 Calling our usage of anubis an attack on our users is far-fetched. But feel free to move elsewhere, or host an alternative without resorting to extreme measures. We're happy to see working proof that any other protection can be scaled up to the level of Codeberg. ~f

Replies (2)

  • @Codeberg@social.anoxinon.de 2025-08-15 17:12

    @Suiseiseki@freesoftwareextremist.com BTW, we're also actively following the work around iocaine, e.g. https://come-from.mad-scientist.club/@algernon/statuses/01K2N54XEVTEYYAASHZ0P48FBT However, as far as we can see, it does not sufficiently protect from crawling. As the bot armies successfully spread over many servers and addresses, damaging one of them doesn't prevent the next one from doing harmful requests, unfortunately. ~f

    Open ##2836501

  • @SuperDicq@minidisc.tokyo 2025-08-15 17:40

    @Codeberg@social.anoxinon.de @Suiseiseki@freesoftwareextremist.com A lot of users can not pass Anubis challenges because Anubis does not support every browser and is also incompatible with popular security focussed browser extensions such as JShelter. Asking your users to enable JavaScript and to disable security extensions like JShelter in order to visit your website is very bad, don't you agree? I don't think it is far-fetched to call it an attack on your users at all.

    Open ##2836503