The examples of people trying to spoof are:
> People or bots who want to get more elements specific to certain devices, or who want to break out of so-called ‘device ghettoes’ (eg they don’t want to have restricted possibilities due to being a mobile device)
OK, but does the website owner really care if a tiny fraction of people do this? Restrictions by device are usually for performance and ease of use reasons.
(And when content is limited to certain devices for legal reasons, like HDCP, this is accomplished with cryptography, not with device detection.)
> Likewise, some threat actors want to take advantage of the fact that some security measures are not as tight for some devices.
Seems like it would be better to patch the security hole instead? Or else deprecate support for old devices (e.g. stop serving HTTP, only HTTPS). Anti-spoofing seems like a terrible solution to security.
> Who can stop people from utilizing device spoofing if a website cannot show captcha to mobile devices even if some rate limits are exceeded...
Since when do CAPTCHA's not work on mobile devices? And if yours doesn't... switch to one that does?
> or if a company offers specific discounts or products only to some types of devices?
That's kind of a dark pattern anyways.
I mean, the article's interesting, and device detection is (sadly) super-necessary for progressive enhancement, as feature detection doesn't work in every case -- but you can assume honest users in that case. If they spoof their user agent and the site breaks, then the problem's on them.
But it seems a little bizarre to me to put development effort into anti-spoofing measures rather than addressing your actual problem directly. Is there a use case I'm missing where anti-spoofing really is the best or only possible approach?