Earlier quoted context omitted.
Here's my take: * JA3s are mostly useless. JA4s supersede them entirely. * Using JA4s in rate limits is pretty useful and helps a lot against proxy scraping. It was not very helpful in this attack. * Bot detections are somewhat helpful but they don't solve scrapers/attacks by themselves. They're useful as a 2nd/3rd data point (eg. low bot score + bot detection + something else)
isn't JA4 also useless because it is so easy to spoof tls. For eg. cycletls for nodejs etc..
Yep curl cffi accurately spoofs JA4 for chrome. You need to detect client side as well.