4 ms·
I'd be very interested in knowing more about how the technology works. It's pretty difficult to assess it without more information. Specifically it feels like t
by thibauts 12y ago
I'd be very interested in knowing more about how the technology works. It's pretty difficult to assess it without more information. Specifically it feels like the good old software protection conundrum where you have to give the keys along with the lock. How do you prevent a bot operator to send the right signal (or not send it) to the (whichever) measuring party ?
- paulgb 12y agoHere's a short explanation of spider.io's approach that might interest you: https://www.youtube.com/watch?v=RSWhvNdjAAE https://www.youtube.com/watch?v=RSWhvNdjAAE
- thibauts 12y agoOk so the library performs a kind of timing attack to detect whether it runs in a legitimate browser or not, and phones home { bot: true }. I make a bot that detects the script on the page and sends { bot: false }. You could try to obfuscate the signal by sending the raw collected browser behavior data but I still could reverse engineer its format or replay data from a legitimate session. I still don't understand how this could possibily work.