4 ms·
> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy v
by maxwellg 3mo ago
> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes.
This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The steganography cat-and-mouse game is valuable because it is much harder for a gateway to continuously reverse engineer all the fingerprinting mechanisms used. Sure, some malicious gateways will be able to stay on top of things, but not all - and not always.
- klntsky 3mo agoI would add that it would probably work even better than a KYC at least for some time until discovered, given that there is a very developed international market for KYC bypass services
- solenoid0937 3mo agoSeriously, the author has clearly never had to deal with client abuse. This is a total non issue unless you are Chinese distilling lab.
- felooboolooomba 3mo agoOld Marv from Cocke County, Tennessee had a distilling lab too. I'm not sure if he'd have issues too. Well, probably many issues but unrelated.
- transcriptase 3mo agoI wonder if he knows John Lee Pettimore? Grandaddy ran whisky in a big black dodge…
- morpheuskafka 3mo agoWell, the first filter catches anyone whose timezone is set to mainland China. That includes presumably all individual devs just using a VPN, who have no desire to or knowledge of distilling. (Again, could be trivially bypassed either by rewriting, mocking the timezone call, or just changing the timezone. But we are assuming no mitigation used.)