3 ms·
It's somewhat interesting to see the FSF's approach to this. From what I understand they can't really use something like anubis since they want their websites
by wasmperson 3mo ago
It's somewhat interesting to see the FSF's approach to this. From what I understand they can't really use something like anubis since they want their websites to be accessible without javascript:
https://www.gnu.org/philosophy/javascript-trap.html https://www.gnu.org/philosophy/javascript-trap.html
Users can't consent to running a page's javascript the way they can consent to running a program they've intentionally downloaded, so it's effectively "non-free" regardless of license.
- superkuh 3mo agoAnubis does support the no-JS HTTP meta-redirect proof of work but few know about it and fewer enable it. And it may not block everything.
- wasmperson 3mo agoI indeed did not know about this. There seem to be some caveats: https://anubis.techaro.lol/docs/admin/configuration/challenges/metarefresh https://anubis.techaro.lol/docs/admin/configuration/challeng... I guess for the meta refresh challenge it's less "proof of work" and more "proof of patience".
- xena 3mo agoThe meta refresh challenge actually uses time as the proof! It makes sure you wait for at least 75% of the time the administrator configured and adds client side smear to ensure that browser temporal randomization doesn't trigger a false failure.
- perching_aix 3mo agoDoes it still need a cookie though? Another thing I have disabled by default.
- xena 3mo agoFor what it's worth, Anubis supports LibreJS: https://github.com/TecharoHQ/anubis/blob/main/web/build.sh#L7-L36 https://github.com/TecharoHQ/anubis/blob/main/web/build.sh#L...
- BigTTYGothGF 3mo ago> can't Won't, they call it malware: https://www.fsf.org/blogs/sysadmin/our-small-team-vs-millions-of-bots https://www.fsf.org/blogs/sysadmin/our-small-team-vs-million...