There is a unfortunate incentive created when a "business" (MiTM) depends on "bot traffic", i.e., the continued nuisance of bot traffic, to make money If the "bot traffic" declines, then the "bot protection business" goes down with it Cloudflare communication are sometimes careful to refer to traffic _labeled as_ bot traffic versus actual bot traffic Because the "business" relies on the existance of "bot traffic", th…
>It can be used to force users to use certain software, e.g., certain browsers, and to enable Javascript subjecting users to data collection, surveillance and ads >Certainly the problem is not the individual www user who doesnt use an "approved" graphical, Javascript-enabled browser who gets blocked or fingerprinted trying to make a single request The alternatives to javascript fingerprinting are either ineffective (…
Javascript fingerprinting itself is ineffective, these kind of checks only stop the most basic bots and I'd argue the same for attestation.