You Don't Need Anubis

Creators are ditching the puzzle wall as readers rage while devs argue bots got smarter

TLDR: Anubis’s puzzle walls aren’t stopping scrapers; a simple cookie page blocks most non‑JS bots, with Cloudflare the reliable option. Comments clash over bad math, bots running JavaScript, and real-user pain, splitting the crowd between “ditch Anubis” and “keep it for attacks”.

Web owners are fed up with Anubis, the “solve-a-puzzle before you enter” gate meant to stop scrapers from copying their sites. The hot take of the day: you don’t need Anubis if your only worry is AI scrapers, because most of them don’t run JavaScript—and a tiny cookie trick works just as well. Cue chaos. Security legend tptacek drops the hammer: “the PoW thing Anubis uses doesn’t make sense,” arguing the math behind those compute puzzles is misapplied. Then uqers storms in waving receipts: the cost math is wrong, calling out the claim that scraping Anubis costs “$0.00” as bad accounting. Meanwhile, gucci-on-fleek says when Anubis switched to a JavaScript challenge, “my server got overloaded,” turning the “bots don’t run JS” claim into a cliffhanger. And indrora warns: the bots are learning—they’re increasingly running JS, so this cookie trick is just the latest speed bump.

The users? Furious. yellow_lead says Anubis “fails completely” way too often, and even when it works, it delays real people, creating a meme-y vibe of “solve a Sudoku just to read a blog.” The community splits into camps: Team Ditch-It wants a barely-there JS cookie check, Team Keep-It says Anubis still helps during real attacks, and Team Cloudflare shrugs: use the big shield when things get serious. Drama, math fights, and CAPTCHA fatigue—peak internet energy.

Key Points

  • The article claims Anubis’ proof‑of‑work is overused for anti‑scraping and offers limited value against LLM scrapers.
  • It argues Anubis primarily blocks bots because many do not execute JavaScript, while slowing real users.
  • A 12‑line Caddy configuration using a JavaScript‑set cookie is presented as an effective, low‑friction alternative.
  • The author reports this method resolved scraper‑driven rate limiting on a self‑hosted Redlib instance.
  • Cloudflare is described as the most reliable solution for real DDoS protection; Anubis’ README recommends Cloudflare in most cases.

Hottest takes

"the PoW thing Anubis uses doesn't make sense" — tptacek
"The math on the site linked here as a source for this claim is incorrect" — uqers
"it fails completely" — yellow_lead
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.