It seems like some FOSS websites started using a Proof of Work CAPTCHA called Anubis because they’ve been getting hit by crawlers to gather data for LLMs. It seems like it helps.

It does not stop them, but it does make it more expensive and slower for the attacker. At the moment, I haven’t seen any instance having this problem, but it most likely will be a problem someday and being praped for it is definitely not a bad thing.

Lemmy could benefit from this by maybe placing some invisible or auto PoW CAPTCHAs when doing some action like commenting, posting, etc.

  • drspod@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 day ago

    I frequently access Lemmy through quite old hardware, and I’d be a bit worried that these PoW scripts would make the site unusably slow for me.

    • poVoq@slrpnk.net
      link
      fedilink
      arrow-up
      2
      ·
      1 day ago

      You might have to sit through a slightly longer waiting time every now and then, but Anubis is not invoked on every connection and once your browser is found to be worthy you can surf as before.

      The bigger issue might be if that old hardware can’t run a modern up to date browser, because then it doesn’t work at all, which is the real down-side of Anubis.

      I tried it with the default settings of the Tor browser though and that worked ok surprisingly.