I find this task to be an interesting engineering problem.
A related question is if there’s an unspoofable way to detect a client.
I find this task to be an interesting engineering problem.
A related question is if there’s an unspoofable way to detect a client.
Overall though, I would seriously ask why? Anti-cheat for a game maybe? It will cost you time/money to prevent, and it will hurt people that like your product enough to hack on it. As a user who rejoices in having APIs I can use to automate products I like, I'd be far more likely to pay you if you have an API I can use.
Found it:
https://moderncrypto.org/mail-archive/messaging/2014/000780....
If it's running in a browser, Google can simply disallow those domains to make API calls.
Also, at least Apple will block apps that make unauthorized API calls to third parties.
There are CORS rules, but those are enforced by the browser, a backend cannot prevent you from calling it, except by requiring an access token or something similar.
I suppose you can have a system which works like TOTP except for machine-to-machine. Although it would probably be broken since anything on the client side can be disassembled. The UX would likely suffer as a result as well.
I once saw a certificate-based implementation once where the server issued a temporary x509 cert to the client and then used mTLS[1]. It did reduce "unauthorized" clients by raising the bar, but it ended up making life way harder for their devs and the people they really wanted to stop just implemented the cert strategy and moved on.
[1]: https://freedomben.medium.com/what-is-mtls-and-how-does-it-w...
At that point anyone writing a library like this would need to actually pull in the rendered page on which the user is supposed to be navigated, scrape the field names off of that (which won't be easy), and only _then_ could they perform the form action.
But if you're a big enough site, someone will likely still take the time to do it.
Or only serve videos if they detect some kind of physical input(mouse/keyboard)
But they don't seem to care that much for non-mainstream tools, or this would be blocked already
For small scale sites it's definitely not easy to block
They may be some paid libraries that promises to do it, but I've never seen one that seemed really unbreakable
Even if you go all the way and block EVERY possible way of doing this, you can make a puppeteer script that could watch and record sound/video directly on the screen in like 15 lines of code, even if it would be really slow to get long videos
If you serve content, put it behind a paywall and rate-limit based on the maximum amount a human can reasonably consume and stop caring whether the user uses your own client or something like this - after all you’re getting paid either way.
The only businesses that are threatened by unofficial API clients are cancerous “growth and engagement” crap where the “value” is the wasting of the user’s time. Don’t be such a business and you’ll be fine.
I'm definitely curious if there's a way to do a rotation that resists easy automatic code analysis.
Anyone know if other websites put as much effort into anti-adblock engineering?
Once you’ve defeated obfuscation you’ll be dealing with DOM integrity-based defenses.
you'd basically have to make your own stealthy video format, otherwise you can just catch network requests