> The resulting curl looks, from a network perspective, identical to a real browser.
How close is it? If I ran wireshark, would the bytes be exactly the same in the exact same packets?
How close is it? If I ran wireshark, would the bytes be exactly the same in the exact same packets?
It could mean that the packets are the same, but timing is off by a few milliseconds.
It could mean a single HTTP request exactly matches, but when doing two requests the real browser uses a connection pool but curl doesn't. Or uses HTTP/3's fast-open abilities, etc.
etc.
Identical here means having the same fingerprint - i.e. you could not write a function to reliably distinguish traffic from one or the other implementation (and if you can then that's a bug).