I just don’t get why people would stay in reddit when lemmy exist :(
- 1 Post
- 165 Comments
daniskarma@lemmy.dbzer0.comto
Selfhosted@lemmy.world•Anubis is awesome and I want to talk about itEnglish
2·2 months agoI think the issue is that many sites are too aggressive with it. Anubis can be configured to only ask for challenges if the site is under unusual load, for instance when a botnet it’s actually ddosing the site. That’s when it shines.
Making it constantly ask for challenges when the service is not under attack is just a massive waste of energy. And many sites just enable it constantly because they can defer bot pings from their logs that way. That’s for instance what op is doing. It’s just a big misunderstanding of the tool.
daniskarma@lemmy.dbzer0.comto
Selfhosted@lemmy.world•Anubis is awesome and I want to talk about itEnglish
1·2 months agoI don’t know if “anything”. But surely people overestimate its capabilities.
It’s only a PoW challenge. Any bot can execute a PoW challenge. For a smal to medium number of bots the energy difference it’s negligible.
Anubis it’s useful when millions of bots would want to attack a site. Then the energy difference of the PoW (specially because Anubis increase the challenge if there’s a big number of petitions) can be enough to make the attacker desist, or maybe it’s not enough, but at least then it’s doing something.
I see more useful against DDOS than AI scrapping. And only if the service being DDOS is more heavy than Anubis itself, if not you can get DDOS via anubis petitions. For AI scrapping I don’t see the point, you don’t need millions of bots to scrape a site unless you are talking about a massively big site.
daniskarma@lemmy.dbzer0.comto
Selfhosted@lemmy.world•Anubis is awesome and I want to talk about itEnglish
7·2 months agoYou are right. For most self-hosting usecases anubis is not only irrelevant, but it actually works against you. False sense of security and making your devices do extra work for nothing.
Anubis is though for public facing services that may get ddos or AI scrapped by some not targeted bot (for a target bot it’s trivial to get over Anubis in order to scrap).
And it’s never a substitute of crowdsec or fail2ban. Getting an Anubis token it’s just a matter of executing the PoW challenge. You still need a way to detect and ban malicious attacks.
daniskarma@lemmy.dbzer0.comto
Selfhosted@lemmy.world•Anubis is awesome and I want to talk about itEnglish
401·2 months agoI don’t think you have a usecase for Anubis.
Anubis is mainly aimed against bad AI scrappers and some ddos mitigation if you have a heavy service.
You are getting hit exactly the same, anubis doesn’t put up a block list or anything. It just put itself in front of the service. The load on your server and the risk you take it’s very similar anubis or not anubis here. Most bots are not AI scrappers they are just proving. So the hit on your server is the same.
What you want is to properly set up fail2ban or, even better, crowdsec. That would actually block and ban bots that try to prove your server.
If you are just self-hosting with Anubis the only thing you are doing is deriving the log noise towards Anubis logs and making your devices do a PoW every once in a while when you want to use your services.
Being honest I don’t know what you are self hosting. But at least it’s something that’s going to get ddos or AI scrapped, there’s not much point with Anubis.
Also Anubis is not a substitute for fail2ban or crowdsec. You need something to detect and ban brute force attacks. If not the attacker would only need to execute the anubis challenge get the token for the week and then they are free to attack your services as they like.
daniskarma@lemmy.dbzer0.comto
Selfhosted@lemmy.world•How do you handle junk email?English
1·2 months agoMy “important” emails work on a white list basis. So every sender not approved by me goes to spam. When I’m waiting for an email I’ll check the spam folder for it and white list the sender.
daniskarma@lemmy.dbzer0.comto
Fediverse@lemmy.world•The highlighted division and factions of Lemmy.English
52·3 months ago“I’d rather die alone shot down by a fascist than teaming up with this pal that do not share 100% of my vision on what this dead dude did 100 years ago”
daniskarma@lemmy.dbzer0.comto
Fediverse@lemmy.world•Alternative app store AltStore raises $6M, connects with the fediverse | TechCrunchEnglish
5·3 months agoI suppose you can enforce additional politics into your store. Like forcing all apps being open source (like f-droid).
But everything will keep to be apple/google approved, at least until linux phone becomes more mainstream.
Until then I’m moving away from native app development, and focusing more on webapps and progressive apps.
daniskarma@lemmy.dbzer0.comto
Technology@lemmy.world•EU Chat Control didnt pass - proving the media got to alot of youEnglish
161·3 months agoI contacted my representatives in Spain and they gave two fucks about it, they still positioned as “in favour”.
They are closing the whole project.
Specifically they say that they are tired of pushing fixes and that they don’t find excitement in maintaining the project. With zero mentions at all to being scrapped or having any kind of AI related issue.
I don’t know if you knew the project before seeing this post. I did, I was considering between this and freshrss and chose freshrss specifically because I knew that the end of ttrss was close (this was like 2 years ago). There were a lot of signs that the development was ending and the project was on route to be abandoned.
First, source code is on github.
Second, RSS aggregators are self hostable, not a service provided by the dev. The dev would have not issues of a public instance of ttrss hosted by someone gets scrapped.
Third, RSS aggregators doesn’t really tend to be public facing. Due to their personal nature they don’t tend to be open. They are more account based.
Sorry, I really don’t see the case here.
It really doesn’t seem like that’s the case. It doesn’t even makes much sense. What do tou think was being AI scrapped? The source code?
You could want to have multiple clients in sync.
Also a web service could be fetching 24/7 and perform classification algorithms before serving to the client that will only connect a few times a day.
daniskarma@lemmy.dbzer0.comto
Technology@lemmy.world•Google's shocking developer decree struggles to justify the urgent threat to F-DroidEnglish
4·4 months agoNewpipe, now signed by Norman Reedus, verification picture and everything!
daniskarma@lemmy.dbzer0.comto
Technology@lemmy.world•Google says adblockers caused YouTube views count to drop - this is what adblockers told us really happenedEnglish
2·4 months agoMy despise to ads is so big that if someday ads are completely unavoidable I’ll settle for a system that just blackens the screen and mute the volume for the duration of the ads. It will still be worth it.
daniskarma@lemmy.dbzer0.comto
Technology@lemmy.world•Google says adblockers caused YouTube views count to drop - this is what adblockers told us really happenedEnglish
6·4 months agoIt’s true. Having to constantly update some adblockers and ways to evade ads in youtube made me realize shitty youtube videos are not worth the effort and I barely use it nowadays.
daniskarma@lemmy.dbzer0.comto
Fediverse@lemmy.world•What is happening? [UPDATE - SOLVED - HUGE DDoS Attack]English
6·4 months agoIt seems that there has been a massive short lived ddos attack all over the web.
There have been several in the later years. Sone of them are linked to a botnet called AISURU that it’s supposedly infected millions of devices worldwide.
Timing links most likely with an attempt at hybrid warfare against europe. My bet is israel or Russian linked due recent events.
daniskarma@lemmy.dbzer0.comto
linuxmemes@lemmy.world•What do you think about the fact that Google Pixel phones are being confiscated in Spain if they have GrapheneOS installed?
99·4 months agoHeadline is not true.
A police spokesperson from one Spanish region told that they suspect of people carrying google pixel phones because they are commonly used by drug dealers with GOS installed. It was made more as a comment than as a serious threat.
I have heard nothing about any actual confiscation based on phone OS being made.
daniskarma@lemmy.dbzer0.comto
Technology@lemmy.world•What would stop you from switching to a flip phone (or dumbphone) in 2025?English
18·4 months agoI’m closer to carrying around a cyberdeck than a dumbphone.
I don’t like either sms or phonecalls.
Update and shutdown?
What about update and I let your pc on all night without your knowledge?