← Back to context

Comment by jchw

3 days ago

> We have been seeing our clients' sites being absolutely hammered by AI bots trying to blend in. Some of the bots use invalid user agents - they _look_ valid on the surface, but under the slightest scrutiny, it becomes obvious they're not real browsers.

Yep. I noticed this too.

> That said they could even run headless versions of the browser engines...

Yes, exactly. To my knowledge that's what's going on with the latest wave that is passing Anubis.

That said, it looks like the solution to that particular wave is going to be to just block Huawei cloud IP ranges for now. I guess a lot of these requests are coming from that direction.

Personally though I think there are still a lot of directions Anubis can go in that might tilt this cat and mouse game a bit more. I have some optimism.

I haven't seen much if anything getting past our pretty simple proof-of-work challenge but I imagine it's only a matter of time.

Thankfully, so far, it's still been pretty easy to block them by their user agents as well.