It would be cool if the POW could be done ahead of time. That way I don't get stuck waiting while I'm working. Some type of credit/tokens that my browser could then spend.
That just creates another problem: if you're taking any measures to reduce tracking (ie. clearing cookies on shutdown or using temporary containers), this won't work. If anubis was being deployed on a site that a user visits often (eg. HN), the user might be convinced to whitelist it, but most anubis deployments are on random blogs or fediverse instances that I might not visit again in months. I'm certainly am not going to whitelist those sites, nor am I going to enable cookies wholesale just to avoid solving challenges.
Look, if you're going out of your way to break expected behaviour on websites you shouldn't be surprised when people code to the most common denominator and then you have weird subtle breakage as a result.
Gotta agree. Turning tracking cookies off? Sure! Turning session cookies off and then complaining that the server doesn’t remember you? Uhhh…
And while I’m sympathetic to the idea of not wanting to run JS, to a first approximation modern browsers are JS engines that have graphical displays. How things should be vs how they are is a classic is/ought problem. The world took a vote on what a browser’s meant for and we lost. Fighting it today is rough; tomorrow, futile.
There's no mechanistic difference between the two types of cookies, let's not pretend this is an actual config choice that people are making.
Whenever I hit Anubis, I simply go "keep your secrets then" and take my leave. The vast majority of the sites posted to HN (that catch my fancy) work fine or fine enough, and are better for it.
If I really, really desperately want to check something out, I can always just turn stuff back on. Turns out, I rarely do.
Shoutout to the particularly dogshit few that don't just require cookies and JS, but even third party JS. For reading a blogpost or a message thread!
The Anubis anime girl is an instant tab close for me, especially while in public. I dont like having to explain to people that I'm not one of those creepy anime guys.
That’s the most insecure thing I’ve heard in a while. What other things randomly flashing across your screen disturb you? Do you imagine your coworkers keeping count of which ads are displayed in your browsers? Do you imagine that they don’t also see the Anubis loading screens?
From someone who doesn't want to associate with it, I think 'anime girl' is fair. Even if people who consume it might (and do) categorize it otherwise.
Happy Eyeballs and switching to/from mobile are definitely hard problems to deal with in a privacy-friendly way, but I don't think IPv6 privacy extensions should really matter here. Just treat a /64 the same way you'd treat a /32 in IPv6-land. It may represent multiple users, but they're all sharing the same internet connection which is as much as the global internet really wants to tell you. Whatever's on the user-controlled side of the address is of course untrustworthy anyways.
Then we could implement an exchange, so that if you generate too much Anubis POW, you could exchange it with others.
We could link it to a site, you generate for HN, I for Reddit, but it so happens that you visited Reddit more and I HN, so we depleted our Anubis POW, so we could exchange some Reddit Anubis with some HN Anubis.