3 ms·
Ok so the library performs a kind of timing attack to detect whether it runs in a legitimate browser or not, and phones home { bot: true }. I make a bot that de
by thibauts 12y ago
Ok so the library performs a kind of timing attack to detect whether it runs in a legitimate browser or not, and phones home { bot: true }. I make a bot that detects the script on the page and sends { bot: false }. You could try to obfuscate the signal by sending the raw collected browser behavior data but I still could reverse engineer its format or replay data from a legitimate session. I still don't understand how this could possibily work.