Earlier quoted context omitted.
Your idea works for generic crawlers. That doesn't work for targeted bots. A major benfit of device attestation is to stop the hordes of custom bot creators who try all sorts of ways to make a buck off of your platform such as sms toll fraud, credit card testing, ad fraud, account takeovers, stolen card laundering, gift card laundering, botting for pay for platform / ecosystem benefits, paid harassment, the list just…
> A major benfit of device attestation is to stop the hordes of custom bot creators Attestation is extremely ineffective at preventing this because it requires attackers be unable to compromise their own devices, even when they have permanent physical access to the hardware and can choose which model to buy and get devices known to be vulnerable. For example, CVE-2026-31431 is from only a week ago. It's a major local…
I don't consider it a panacea.
People with rooted android phones are a drop in the bucket compared to people running botnets using programming languages. I'd be super happy if I could force people to use low end rooted android phones for botting. It'd massively decrease the problem versus a EC2 instance running at full tilt.
Getting and managing a fleet of rooted phones is not a trivial task.