Earlier quoted context omitted.
It's not just the user-agent, it is definitely doing non-trivial fingerprinting (both linked projects also had UA mitigations before). We don't have an easy workaround (besides a sketchy cookie hack that took hours to reverse engineer) right now and have been trying to get in touch with them.
> it is definitely doing non-trivial fingerprinting Can confirm. To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output ho…
Total coincidence that it's also "you're not being a good little data source", I'm sure.
I use a privacy-oriented browser on my cell phone to load amazon's website to get that stupid whole foods QR code for the checkout, because I'm not installing their fucking app so it can collect more data on me.
Guess what? Every single time, I'm presented with a "we've emailed you a link" error, and that link is difficult to open in my preferred browser because iOS doesn't offer it as a choice for opening links...