Open Source Software Community - it's about ethics in Code of Conducts

  • 🔧 Site instability resolved. You can report double-posts and broken attachments. For bigger issues, use the Technical Grievances thread.
    🇵🇦 Nuestro primer dominio localizado está en español en kiwifarms.pa. Our first localized domain is on Spanish on kiwifarms.pa.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Whenever anyone mentions anubis i like to link this blog post by Tavis Omandy https://lock.cmpxchg8b.com/anubis.html. You may or may not know of him, he's a security researcher at google and has found numerous high profile vulnerabilities (such as cloudbleed). It's a good read,

twitter replies are fun too.
His article is actually cited a lot on the Anubis Wikipedia page under “Criticisms”. One of the few good Wikipedia articles
 

taviso dijo:
Do you think money can just buy any skill? For example, it doesn't matter what your salary is, you can't buy politeness 😛
mewtrino dijo:
Have you tried buying politeness? For example, maybe you could send some bitcorn to [BTC ADDRESS] to support a trans woman who could very likely be homeless in 10 days. Maybe then I'll be polite to you :D
taviso dijo:
Sorry to hear that, but I don't have any crypto sorry. I hope everything works out okay.
finitecrystal dijo:
Wait a minute, you have a well paying job at Google, just go on Coinbase and buy some.
taviso dijo:
I'm not into crypto sorry. Look, I wish you all well, but I'm not sending anyone bitcoin and I'm muting this thread.
finitecrystal dijo:
I don't care. You owe the woman money. Why don't you delete this thread, you fucking coward?

>money can't buy politeness
<gibs me money im trans!!1
>i don't want to
<you work at google now fork the money over
>leave me alone
<you owe "her" money now idc

Sides, meet orbit. :story:
 
Whenever anyone mentions anubis i like to link this blog post by Tavis Omandy https://lock.cmpxchg8b.com/anubis.html. You may or may not know of him, he's a security researcher at google and has found numerous high profile vulnerabilities (such as cloudbleed). It's a good read,

twitter replies are fun too.
Wow so Anubis is a massive waste of time and energy. Ironic, it's supposed to stop AI crawling but just increases the cost of it in automated compute terms. If they really cared about this stuff they would do something more akin to a CAPTCHA or delay as that article points out.
>money can't buy politeness
<gibs me money im trans!!1
>i don't want to
<you work at google now fork the money over
>leave me alone
<you owe "her" money now idc

Sides, meet orbit. :story:
Can you imagine if someone spoke that way to someone else in a public place? How pathetic. "She" has time to develop and argue about some ineffective anti AI scraping tool and demand money, but not enough time to make rent.
 
the actual mascot:
D4ehGXQW0AAzsq0.jpg DBwIBZlXYAAnxNl.jpg
 
All these anti-bot measures who want to "stick it to all the evil corporations" only lock out your average guy like me who wants to look at webpages without having to load 8768758544 .js files and use VPNs/Tor to at least somewhat protect their privacy. The corpos have the resources/ip ranges/manpower/etc. to circumvent all that shit easily anyways.
 
All these anti-bot measures who want to "stick it to all the evil corporations" only lock out your average guy like me who wants to look at webpages without having to load 8768758544 .js files and use VPNs/Tor to at least somewhat protect their privacy. The corpos have the resources/ip ranges/manpower/etc. to circumvent all that shit easily anyways.
Ah, but you see, it will cost them 20 cents a day more to keep scraping like this! :smug:
 
Whenever anyone mentions anubis i like to link this blog post by Tavis Omandy https://lock.cmpxchg8b.com/anubis.html. You may or may not know of him, he's a security researcher at google and has found numerous high profile vulnerabilities (such as cloudbleed). It's a good read,
Anyone who puts bot detection in front of (what should be) a static web page is the blackest retard gorilla nigger on earth. Modern hardware can serve tens of thousands of pages a second. Apparently they can serve the bot detection page to every visitor, why not directly serve the actual content?
 
All these anti-bot measures who want to "stick it to all the evil corporations" only lock out your average guy like me who wants to look at webpages without having to load 8768758544 .js files and use VPNs/Tor to at least somewhat protect their privacy. The corpos have the resources/ip ranges/manpower/etc. to circumvent all that shit easily anyways.
I imagine you're primarily talking about Anubis, which reminds me of this blogpost by Tavis Ormandy where he details how easy it is to bypass and how, by default, completing the challenge gets you access to the site being protected for seven days. So all a soulless AI vendor has to do is complete the challenge once (probably costing a fraction of a cent per completion) and they have unmitigated access to scrape whatever for a week.

Also this isn't related to the tech behind it but I really, really hate the forced tranime branding that means serious sites like the Linux Kernel Mailing List are plastered with some cunt's anime OC. They do offer a variant that doesn't have the branding but you need to be either a $50/mo Github sponsor or personally email the trannies for an invoice. And of course it's MIT licensed because everyone knows the best way to fight soulless scraping corpos is by bending over and letting them steal your code for free.

Honestly I can't bring myself to hate it too much because it's competition with Cloudflare and any tech that eats into Cloudflare's monopoly on anti-DDoS is always good even if it's tranny-branded.
 
I imagine you're primarily talking about Anubis, which reminds me of this blogpost by Tavis Ormandy
LMAO, I couldn't get past the part where he shows that they check the number of leading hex zeroes rather than the number of leading binary zeroes, because I was laughing too hard. They literally take the hash as a string of hex digits and count the leading zeroes! You can only increase or decrease difficulty by a factor of 16! I thought that standard hash-based proof-of-work was bad because you couldn't adjust difficulty by a factor less than 2, but this really takes the cake. This has to be some of the laziest troonslop to have ever been slopped out, since it wouldn't have been that hard to count the leading hex zeroes, multiply by four, and then add in the result of a table lookup on the next hex digit.
 
Honestly I can't bring myself to hate it too much because it's competition with Cloudflare and any tech that eats into Cloudflare's monopoly on anti-DDoS is always good even if it's tranny-branded.
But it's not competition, it doesn't actually do shit except annoy people and look faggy
 
Atrás
Top Abajo