Earlier quoted context omitted.
Not to detract from your work there, but there's actually some great research papers about how Botguard itself is easy to bypass and google cookies provide most of the heavy lifting when it comes to bot detection. I've snooped around a bit myself and it doesn't seem like botguard does anything much more advanced than other fingerprinting solutions. I just don't buy that this is all about detecting more bots; every so…
Ah, you're assuming it's the same strength on all places it's used - and also that it actually has been bypassed. There didn't used to be any public bots that can beat the strongest version and from a quick Googling around I don't see that it's changed. Someone took apart a single program manually, years ago, but the programs are randomly generated and constantly evolve. So that's not sufficient to be able to bypass…
In other words, the bot developers are still getting through, and meanwhile it's the actual humans who don't want JS which get screwed. Reminds me of DRM... honest customers are the most inconvenienced, while crackers still break it.