4 ms·
I don't understand some of the ways you are using terms e.g. when you say "user agent" it sounds like you mean the User-Agent HTTP header, which is trivial to s
by photon12 4y ago
I don't understand some of the ways you are using terms e.g. when you say "user agent" it sounds like you mean the User-Agent HTTP header, which is trivial to spoof, but that isn't how I'm using the word user agent, which I'm saying means the agent that a given user acts with.
I also don't quite understand your threat model here and the details of what you're proposing is an attack. If you are a user who Google consistently knows has a persistent cookie at auth time, Google can expect that in the future and therefore use that as a data point in risk based authentication. If you are a user who Google consistently knows doesn't have a persistent cookie at auth time, Google can't rely on that data point providing any signal in risk based auth, and seems to be DoSing, or at least frustrating, users in that scenario.
I can't quite respond to your comment because I don't fully understand it.