As an aside, I’ve fought credential stuffers by returning real looking but actually false data, and initiating password resets... start serving different data on each hit, you may need to be annoying enough that they give up.
62 karma · joined May 28, 2013
As an aside, I’ve fought credential stuffers by returning real looking but actually false data, and initiating password resets... start serving different data on each hit, you may need to be annoying enough that they give up.
...sorry to be that guy.
Since a customer pays the same usual prices (+ a delivery fee), the brand has the same value on their next in-person visit.
The services are cut throat, they push for massive %'s and expect the retailer to push a 'Get delivery through xxx' message. I know of one service with an EPOS integration, they must be waking up to it now their business is proven.
In those blocks could be anything, detailed gps co-ords, device details, there's a fair chance they can ban all these API users at the push of a button based on whatever's in those blocks.
Everything else is unencrypted - sent back and forth using the protobuf format, the formatting of the protobuf's were dropped on pastebin a few weeks ago.