Devirtualizing nike.com's bot protection
nullpt.rs
nullpt.rs
Oftentimes, the obfuscation relies on turning strings into functions. You can watch all this happen with:
`monitor(eval); monitor(Function)`
That'll log out the arguments passed to eval and the Function constructor. https://imgur.com/hMbKQZA You can also use `debug()` to breakpoint on invocation. (Yes, this works with native fns as well as user-land fns)
Then, comparing memory snapshots can help illuminate the work that happened. Take a snapshot of about:blank, then another after evaluating the ips.js payload. Select comparison. Then look through the results, especially (string). This appears to be the same "VM's strings" called out in the post: https://imgur.com/2v58VM5
Can also see heavy use of WebGL and wasm based on allocations.
Also the memory snapshots, I've used that to try to debug memory leaks in the past but never thought about using it to RE. Super cool that you can also get the string that way.
You can definitely get the same results a lot faster via dynamic RE for most obfuscation methods, but what attracted me to Kasada was the challenge of writing a disassembler from a static RE perspective. I also don't think dynamic RE methods are super easy to apply here once you get into the VM logic though, as I've discovered while working on part 2.
If you want to chat with me about this more my socials are linked in the post, or you can message me on discord (umasi#3301) :)
(We're chatting now)
https://developer.chrome.com/docs/devtools/console/utilities... https://firefox-source-docs.mozilla.org/devtools-user/web_co... https://developer.apple.com/library/archive/documentation/Ap...
The most commonly used are copy(), $(), and $0.
Object.defineProperty(navigator, 'webdriver', {
get: () => {debugger; return false},
});https://github.com/ultrafunkamsterdam/undetected-chromedrive...
Several times I have given up trying to buy new running shoes directly from their site just because it is so frustrating to use.
If scalpers can get $1000, that means people will pay $1000; if the scalpers could get $2000,’that’s what they’d charge.
So if Nike raises their prices to $1000, I don’t see how that increases market price.
I think you’re saying auctions are less efficient for allocating goods and capital, which is contrary to everything I ever learned.
This is not true. Market price will not go up arbitrarily. Scalpers will not keep scalping if the retail price is greater than what they can sell it for, which will happen at some point.
Someone buys this stuff for the prices of the scalpers.
So someone will buy this stuff. Maybe it just takes longer. But I guess not even that.
How are you using such confident language on what the scalpers in this space will or will not do base on ... what looks like Econ 101 supply / demand curves? Do you have some expertise you're not including as context here?
I think this is not true, which can be seen if you make 2 basic assumptions: 1. Scalpers want to make money and 2. There is a max price people are willing to pay for shoes. Then there will be some price Nike can set which will cause scalpers to leave the market.
Similar with music tickets. Maybe musicians want everyday people to afford going to their shows, even if the market demand would price out many of them.
unethical_ban lists some of them.
There are others. For example, it is psychologically quite different to have scalpers say change prices every day or even every hour than to have a large company change prices every day or every hour for the same product. You can have considerable customer ire directed at the company in the latter case.
In a similar vein to what unethical_ban said about lotteries for everyday people, the hype that a company builds with products at "everyday prices" just in limited quantities is different and targets a different audience than products that are priced at luxury prices, even if the product on a secondary market commands the luxury prices.
Simply changing the price to try to deal with scalpers is an extraordinarily blunt tool that can run counter to many other priorities a company might have.
Nike then cashes out that value by making partner stores Buy their shitty products to get a chance to score the good stuff
https://www.npr.org/sections/money/2016/04/20/475023002/epis...
…until I saw that they re-implemented the same operations in some schema migration code without adding the magic ”obfuscate-me” annotations
The routines for communicating with sensors were heavily obfuscated in the main application... but the factory sensor test application had been left installed and was completely clear.
f(ingerprint)
Removing the top pixels from characters greatly reduces readability, which is not as significant if you remove the bottom ones. Then why does this happen? Any ideas?
It's the form of "f" used in italics, only un-italicized.
I think part of my brain keeps thinking it's the italic "f" in math notation "f(x)" and then gets confused to find it as part of a regular non-italic word.
Or it might be the fact that our brain relies heavily on word shape for fast reading, which is heavily dependent on the presence or absence of ascenders and descenders in lowercase, so adding a descender on a letter than shouldn't have one totally breaks our natural pattern recognition.
In any case, I've never come across it in any typeface before in my whole life. Now I'm starting to see why. :)
For now, at least, browsers still allow the end users to configure this stuff, so let's give them that opportunity.
This seems like it can't work. 50% of users are browsing from an iPhone. Every iPhone of the same model has the same fingerprint except for time of day and language preference. So for every time zone there are literally hundreds of thousands of devices that will have the same fingerprint.
> Within our dataset of several hundred thousand visitors tested in the past 45 days, only one in 32014.4 browsers have the same fingerprint as yours.
Buy 2 supposedly identical iphones. Take both to the site. Compare their information.
If you're confident they're wrong then please spell it out for us. What bits do they claim are unique, and why are they wrong?
But it also doesn't pass the sniff test. It tells me I'm unique. One of 185k. Let's break down that number. I'm in the PST time zone. There ~40 million people in the PST time zone. Divided by 185k is 216. They're basically claiming there are 216 iPhone 13 Pro in all of California + Oregon + Washington + British Columbia.
Bullshit!
It's basically fake news. The EFF should know better than to exaggerate with hyperbole. It might be true that almost no one visits https://coveryourtracks.eff.org/, but site that actually gets traffic is also a sight where it'd be closer to unique in 1 of 10.
It can be defeated by the client sending a specific list of ciphers in a specific order during the TLS handshake but in practice this can be difficult to do as it's typically implemented at a low level. Alternatively, creating a browser extension can also be used to defeat it as the request is running through the browser's code in that case.
This fingerprint suffices for that. They use small differences like the size of audio buffers, the exact capabilities of the GPU, etc.
Emulate any one of those slightly wrong and the fingerprint will differ and your bot will be revealed.
Fun fact, on my laptop I can hear websites who use audio APIs for fingerprinting because it causes the audio subsystem to wake up and the speakers make a small pop sound.
And that VM also uses a crypto challenge so you can't just replace the output of the VM
We used to work on a project where the traffic was inserted into a graph like data structure and we connected the known bot traffic nodes and calculated the fraud score based on that. It worked very well.
Absolutely. This is the best part. You do not impact the client side, no complexity pushed down to all of the clients, etc.
E.g. couldn't proof of work be used in order to complete the purchase process?
If it works for bitcoin on large scale it ought to work for a purchase form in small scale without all the distributed systems gotchas.
E.g. Nike could simply increase the difficulty whenever they see fit to tweak the amount of bots succesfully purchasing things.
Not really effective, youtube-dl for example just runs the scripts in order to generate the proofs required.
There seems to be a lot wrong with this situation. A group using free market, capitalist tools in a free market capitalist country seems the least wrong part.
The value isn't wasted — it's consumer surplus.
That value would otherwise have gone to the people. If all value is captured in this way, the marginal benefit of making a purchase becomes very, very low, and the stuff we actually care about (standards of living, happiness, liberty) become decoupled with economic metrics.
This is one of the situations where lotteries are fairer than auctions.
I disagree that all value would be gone though. People value things differently, the 'scalpers' are a mechanism to get the goods to those who value it most highly. I personally don't value these trainers for what Nike is asking, so I don't buy them. Should Nike be required to sell them to me for what I value them at? Or should people be able to set their own price, and others buy if that price is worth it to them? If you actually cared about happiness, liberty, etc, I don't see how a pair of trainers, expensive of otherwise is going to change that, but if it does become an issue, just don't by the sodding trainers then!
I don't see why a lottery is 'fairer'. the shortage is entirely synthetic, created by Nike. I'm not big on adding morality into business transactions, but all this stems directly from Nike's decision to create scarcity. The 'fairest' thing would be for Nike to satisfy demand. 'scalpers' are a just symptom of that.
I don't get why 'scalpers' are only deemed to be a problem when the scarcity in question is synthetic. If there's a corn shortage are farmers scalping? Are oil traders scalping when the price goes up? What about when the price of $stock goes up? Are the sellers scalpers? This is how free markets work. You could at least make a moral case for the price of corn being socially bad, you can't make that case for trainers or gig tickets or whatever.
The other obvious solution is for another company to come in and solve the supply constraint that nike created. Although that too is also apparently wrong. If I bought some 'Niko' trainers from the local market, who is being harmed here? I'm not being misled, Nike aren't losing sales, so why?
2. "prices go up when demand is high" makes sense to incentivize more production and reward those that produce thing we need the most. A farmer getting more for their corn during a shortage makes sense, because we'd be hungry if it weren't for them. A scalper, on the other hand, does not create any value. Neither does a stock trader when they buy low and sell high for that matter.
Even artificial scarcity of luxury items can be interpreted as creating some value - owning a limited edition shoe that they can brag about to their friends is valuable to some people. But buying something before others get to it, just to immediately sell it for a much higher price is just exploitation.
>2. "prices go up when demand is high" makes sense to incentivize more production and reward those that produce thing we need the most
Precisely, so why isn't Nike producing more? That is the issue. Again, scalpers are a symptom.
>A farmer getting more for their corn during a shortage makes sense, because we'd be hungry if it weren't for them.
One doesn't follow the other.
If a farmer gets £1 a tonne one year, why does it mean that them getting £10 a tonne the next mean that people won't go hungry. If there's a corn shortage, that implies there isn't enough, so people are going hungry. Further this seems to verging on a moral argument. If we go hungry if it isn't for farmers then that implies that the state should be stepping in to control their excesses, setting the price at £1 a tonne.
>Even artificial scarcity of luxury items can be interpreted as creating some value
And so can buying a good and selling it on for a higher price. Why does one person have the right to brag about owning a shoe, and not another, who just so happens to be willing to pay a higher price? Why is artificial scarcity acceptable, but creating a functional open market out of that not?
And a stock trader does create value. If a person can't buy stock and sell it on for a higher price, that stock is worth less, which means during an IPO a company can raise less money. It's not even clear to me if you could have PLCs at all, because eventually everyone dies, what happens to a company who is owned by a dead person(s) does it get taken over by the state?
If we were talking about actual necessities then I'd agree with you, although my solution would be to have Nike produce more, not hold people to ransom. But for trainers, a specific brand and model, let the free market function, it's the best we've got.
It's a luxury for poor people. Making it a market turns it into a luxury for rich people
2. Are you going to get any part of the market to admit to this?
You've conflated "communism" with "something disallowed by my preferred dogma". How very HN of you.
Americans using the word "communism" is invariably an indicator of fallacy.
Maybe you could develop some awareness of your own cultural baggage.
What dogma are you proposing I have? I know capitalism has its problems, I know communism has its problems, as does socialism and all the other isms. If capitalism is good at anything though, it's good at making trainers available. If youre saying it's unsuitable for that, then it's time to find something else.
It's ok saying the current system is bad, but if you're proposing to get rid of it, you need a replacement and as Churchill may have said, free market capitalism is the worst economic system, except for all the other economic systems.
So why don't you debate my position, rather than my assumed nationality, dogma and cultural baggage?
I guess the halo effect of releasing unobtainable shoes is worth more than all that? If so, why does it matter (to Nike) if bots buy all of them?
Just make more shoes, damnit…
You have absolutely hit the nail on the head; here.
I think - Ye aside - Yeezy is a great example of how there can be a balance between this like insane run of only 1000 shoes (which only sell for like $250-350 USD retail anyway…so - yeah - where’s the profit again?) - to mass market ‘Wal-Mary’ level availability.
The only people who benefit from limited releases are scalpers. Period. There’s no way the shoe company makes that much profit off a limited release because the limited releases are wildly somehow still usually at ‘regular’ prices.
A solid pair of YEEZY 350’s is not that hard to come by for any even half-committed sneakerhead, I’ve got 3 pairs and my girlfriend has two. We hardly tried. I won the lottery twice myself, and only ever entered 6 times.
It’s really a shame what happened with Ye, because despite all the drama; the Yeezy fashion project was actually an interesting one that had some real potential to find an actual, honest-to-God balance between artificial scarcity and actually selling the goddamn product.
"We'll just have a free-for-all (random distribution)"? Oh ok I'll register 2 million network participants (or IPs, or email addresses, or browser sessions, or privacy CC numbers, etc). Without some kind of outside oracle proving user uniqueness (and many many oracles that people think of, like CC number or billing address, are not actually unique!) it is extremely extremely difficult to construct this system.
NVIDIA distributing some 4090s via GeForce Experience is another interesting example of a hardware oracle, the telemetry is a fairly strong signal of hardware authenticity (as proven by Overwatch's fairly effective hardware bans).
He had apparently made enough money doing this to pull himself out of poverty and get a decent life going.
Question: With the Twitter RSVPs, do you think Nike implemented automation to automatically give you the code when you responded with the correct code in a fraction of a second? If so it implies that on some level Nike was fine what you were doing.
In general we thought that Nike was complicit to an extent. Especially with the on-site checkout and mining of product IDs, they could have cancelled orders done before they shared the link in public. I think on their end, it was a balance of guaranteeing a low supply while ensuring that normal customers did not feel like they were being screwed _all the time_. Yet, even nowadays with the SNKRS app some continue to call it a rigged ballot.
In hindsight, Nike is still positioned somehow uniquely in the sneaker community: it's not guaranteed that money alone will get you a pair. Compare this to luxury brands like Balenciaga, which retail sneakers with a price tag of $500-1000. With the latter everyone knows you have handed out a chunk of cash, but it's not the same thing as the story that you could have waited in line or woke up in the morning to enter a raffle, or been smart enough and early on to pay reseller prices to get a pair before stock ran out which you knew would become a coveted pair over time.
e-commerce sales open the gates to the shop at the same time for everyone. This incentivises massive parallelization of the purchases across accounts, IPs, and identities. Already back in 2017 [1] it's become known to the industry that bots are sniping the purchases faster than humans. Now, we're at a stage where retailers are adjusting their T&Cs to address the resell market [2]. StockX was valued at 2.8B in Dec 2020 [3] and they have to get stock somewhere, right?
The bot industry [4] also developed from simple scripts to SaaS offerings with multi-thousand $ subscription prices just to get access to a bot that's proven to work. The user has to provide a list of proxies that will be used to execute the scripting as these are not provided out of the box (and are hard to get). There are numerous guides on YT and advertising on Twitter that show how to use the bots and how they've been used for purchases. And of course, scarcity is not just for streetwear, but for any type of highly sought for products [5].
[1] https://www.esquire.com/style/mens-fashion/news/a55301/using...
[2] https://www.wsj.com/articles/nike-moves-to-crimp-resellers-a...
[3] https://techcrunch.com/2020/12/16/stockx-raises-275m-series-...
[4] https://www.complex.com/sneakers/how-to-use-sneaker-bots/
[5] https://www.wsj.com/articles/desperate-parents-turn-to-shopp...
I mean these people queue in lines so I would think not, and the new ID verification apps are pretty seamless (upload a pic of self and ID).
websites rate limit IPs -> bot developers start using proxies
websites block datacenter proxies -> bots use residential proxies
websites add captchas -> bots start solving them
websites inspect nuanced details of TLS fingerprints and header ordering -> bots start faking them
websites add browser fingerprinting -> bots reverse engineer it and start faking it
And so on. One thing these websites could do is place a lower limit on the total checkout time. Anyone who completes their checkout in less than 2-15 seconds (depending on the website) is quite obviously a bot.