Hacker News new | ask | show | jobs
by maxwellg 30 days ago
> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes.

This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The steganography cat-and-mouse game is valuable because it is much harder for a gateway to continuously reverse engineer all the fingerprinting mechanisms used. Sure, some malicious gateways will be able to stay on top of things, but not all - and not always.

2 comments

Seriously, the author has clearly never had to deal with client abuse.

This is a total non issue unless you are Chinese distilling lab.

Well, the first filter catches anyone whose timezone is set to mainland China. That includes presumably all individual devs just using a VPN, who have no desire to or knowledge of distilling.

(Again, could be trivially bypassed either by rewriting, mocking the timezone call, or just changing the timezone. But we are assuming no mitigation used.)

Old Marv from Cocke County, Tennessee had a distilling lab too. I'm not sure if he'd have issues too. Well, probably many issues but unrelated.
I wonder if he knows John Lee Pettimore? Grandaddy ran whisky in a big black dodge…
I would add that it would probably work even better than a KYC at least for some time until discovered, given that there is a very developed international market for KYC bypass services