4 ms·
Couldn't they just look at the user agent and know that the hit to their API is coming from an Android device rather than a server?
by immad 13y ago
Couldn't they just look at the user agent and know that the hit to their API is coming from an Android device rather than a server?
- RoboTeddy 13y agohttp://developer.android.com/reference/java/net/HttpURLConnection.html http://developer.android.com/reference/java/net/HttpURLConne... might not have a default User-Agent header that identifies android
- brown9-2 13y agoOf course a developer could change this, but yes the default user-agent string for an Android app using HttpURLConnection identifies it clearly as Android: http://www.gtrifonov.com/2011/04/15/google-android-user-agent-strings-2/ http://www.gtrifonov.com/2011/04/15/google-android-user-agen...
- alttab 13y agoMost probable.
- good_guy 13y agoThis is a bad idea.it's easy to change the user agent to whatever you want.
- Crito 13y agoThere is no reason why it would be a bad idea. False positives (people who are legitimately using AWS credentials from their phone for some reason, or somebody who is legitimately using AWS credentials from their computer but with an incorrect useragent for some reason) would cause an inconvenience as time is wasted to inspect it, but ultimately little harm would be done. False negatives (improperly using AWS credentials but with a useragent that looks reasonable) would not be a deviation from the status quo. You don't need 0% false negative and false positive rates to make this sort of sanity checking worthwhile. Even if you only find a few of the many instances of improperly used credentials, you're better off than if you had done nothing. (Of course there is the issue of correlating misused credentials with the specific application that is misusing them. I don't know how that is done if they are basing their investigation off of useragents.)