4 ms·
I've encountered some APIs that use this. My question is, why? It doesn't really improve security - someone determined enough can match the fingerprint or send
by x3sphere 4y ago
I've encountered some APIs that use this. My question is, why? It doesn't really improve security - someone determined enough can match the fingerprint or send requests using the same library that the originating app uses. It feels like a security through obscurity tactic to me.
- booi 4y agoIt feels like something similar to running sshd on a different port. Yes, it is security through obscurity and not really any more secure.. but practically speaking it might filter out tons of unsophisticated/spamming scripts that won't be bothered to take the extra step. Depending on how easy and how accurate it is, I can easily see this being included by default in security libraries.