If that's all so, could the PoGo devs simply enforce some type of device authentication to 'shut down' these APIs, or otherwise take different steps to make unofficial APIs less compatible/more difficult/effectively impossible?
If that's all so, could the PoGo devs simply enforce some type of device authentication to 'shut down' these APIs, or otherwise take different steps to make unofficial APIs less compatible/more difficult/effectively impossible?
That's impossible. If you try this you'll either have a bunch of false positives or even more likely a patched api around 12 hours later. Never underestimate the dedication of botters. There are multiple headless WoW Apis around for 10 years now and Blizzard isn't able to close them out.
When that changes, watch out.
I sincerely hope that they don't do that, or at least not 'shut it down' completely. The reason is that there are some use cases for this API which don't involve cheating, for example the many different Pokemon Go server status pages including one that I built myself [1].
In those blocks could be anything, detailed gps co-ords, device details, there's a fair chance they can ban all these API users at the push of a button based on whatever's in those blocks.
Everything else is unencrypted - sent back and forth using the protobuf format, the formatting of the protobuf's were dropped on pastebin a few weeks ago.
It seems that the devs are firefighting scalability issues atm, and it would make sense that unsanctioned 3rd party APIs will be targeted Soon™ but probably heuristically.
They're also in violation of the ToS I believe, but bans in their previous title came in waves, and I've not heard of any pogo banwaves yet.
Only if they signed up to it ;o)
If you're reverse engineering an app and someone else is using the device with the app installed there's no need for you to have submitted to a contract of obligations to the app provider. Depending how you orchestrate things the signee might be guilty of giving their credentials away. It would probably come in as unauthorised access of a computer system with respect to USA/England&Wales legislation.
See: https://www.fknsrs.biz/blog/reverse-engineering-pokemon-go.h...
All that can be spoofed tho, and whether they have the resources to apply that level of analysis to XXX million users is questionable.
It might be a nice problem for Niantic if that means non-hacking users pay to improve their own pokemon to try and beat the botted gym users? Provided the numbers of bots is relatively low it probably won't be a problem they feel needs fixing. I guess if someone is claiming more than a few gyms it's going to get flagged and they can probably easily spot if it's genuine or not?!?
That said, you only really need to hold it long enough to claim your coins, and the XP for fighting rival gyms is probably more valuable in the long run.