> At the moment, it seems Basic mode is so basic that it allows everything to pass as human. That’ll likely change as they gather more telemetry to better identify what a bot signal looks like. So they are basically collecting telemetry in the name of "free basic anti-bot" solution.
Reverse Engineering Vercel's BotID
11–20 of 21 posts
Re: Reverse Engineering Vercel's BotID
#12why is bot detection even happening at render time instead of request time. why can't tell you’re a bot from your headers, UA, IP, TLS fingerprint. imo making it a surveillance. 'you're a bot, ok not just go away, let’s fingerprint your GPU and assign you a behavioral risk score anyway'
It's really hard to detect it at request time. It's practically trivial for an attacker to fake headers to resemble a real browser.
Re: Reverse Engineering Vercel's BotID
#13why is bot detection even happening at render time instead of request time. why can't tell you’re a bot from your headers, UA, IP, TLS fingerprint. imo making it a surveillance. 'you're a bot, ok not just go away, let’s fingerprint your GPU and assign you a behavioral risk score anyway'
It's really hard to detect it at request time. It's practically trivial for an attacker to fake headers to resemble a real browser.
You can fingerprint the originating TCP stack with some degree of confidence. If the request looks like it came from a Linux server but the user agent says Windows, that's a signal.
Likewise, the IP address making the request has geographic information associated with it. If my IP address says I'm in Romania but my browser is asking for the English language version of the page... That's a signal.
Similar to basic IP/Geo, you can do DNS and STUN based profiling, too. This helps you catch people that are behind proxies or VPNs.
To blur the line, you can use JavaScript to measure request timing. Proxies that are going to tamper with the request to hide its origins or change its fingerprint will add a measurable latency.
Re: Reverse Engineering Vercel's BotID
#14Earlier quoted context omitted.
It's really hard to detect it at request time. It's practically trivial for an attacker to fake headers to resemble a real browser.
You absolutely have options at request time. Arguably, some of the things you can only do at request time are part of a full and complete mitigation strategy. You can fingerprint the originating TCP stack with some degree of confidence. If the request looks like it came from a Linux server but the user agent says Windows, that's a signal. Likewise, the IP address making the request has geographic information associat…
Re: Reverse Engineering Vercel's BotID
#15Earlier quoted context omitted.
It's really hard to detect it at request time. It's practically trivial for an attacker to fake headers to resemble a real browser.
You absolutely have options at request time. Arguably, some of the things you can only do at request time are part of a full and complete mitigation strategy. You can fingerprint the originating TCP stack with some degree of confidence. If the request looks like it came from a Linux server but the user agent says Windows, that's a signal. Likewise, the IP address making the request has geographic information associat…
jesus christ don't give them ideas. it's annoying enough to have my country's language forced on me (i prefer english) when there's a perfectly good http header for that. now blocking me based on this?!
Re: Reverse Engineering Vercel's BotID
#16Note that the bot detection script uses WebGL to obtain GPU name. I assume this (fingerprinting) is the most popular use of WebGL. Sad that independent browsers like Firefox do not supply fake values.
Re: Reverse Engineering Vercel's BotID
#17Earlier quoted context omitted.
It's really hard to detect it at request time. It's practically trivial for an attacker to fake headers to resemble a real browser.
Anubis does it pretty decently.
Re: Reverse Engineering Vercel's BotID
#18Earlier quoted context omitted.
Sadly, spoofing GPU vendor & renderer can be an even larger flag since they can hash the resulting image of the canvas to compare it with a database of collected fingerprints[0] [0]: https://research.google/pubs/picasso-lightweight-device-clas...
Until a major player gets on board. Then it works. Apple does this by sending an imposter user agent from Safari on iPads. If only that was expanded to iPhones, too. And then send rotating, or randomized user agents.
Re: Reverse Engineering Vercel's BotID
#19Note that the bot detection script uses WebGL to obtain GPU name. I assume this (fingerprinting) is the most popular use of WebGL. Sad that independent browsers like Firefox do not supply fake values.
IMO the use of needs to be behind a permission prompt, the same as e.g. geolocation or WebRTC. Few websites actually need canvas/WebGL for legitimate purposes.
For example, almost every major Japanese book/comic site uses canvas in their e-reader
Re: Reverse Engineering Vercel's BotID
#20Earlier quoted context omitted.
Until a major player gets on board. Then it works. Apple does this by sending an imposter user agent from Safari on iPads. If only that was expanded to iPhones, too. And then send rotating, or randomized user agents.
Doesn't that just move the goal post though? Instead of using your GPU vendor for the fingerprint they can just hash the output canvas after they a bunch of odd rendering calls, getting a hash from the quirks of your graphics driver and GPU hardware.