logoalt Hacker News

maxwellgtoday at 6:52 PM1 replyview on HN

> If the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes.

This seems like a very naive response. If clients send explicit telemetry fields to the gateway, a malicious gateway can trivially strip or modify the field to conform to what normal traffic looks like. The steganography cat-and-mouse game is valuable because it is much harder for a gateway to continuously reverse engineer all the fingerprinting mechanisms used. Sure, some malicious gateways will be able to stay on top of things, but not all - and not always.


Replies

klntskytoday at 7:13 PM

I would add that it would probably work even better than a KYC at least for some time until discovered, given that there is a very developed international market for KYC bypass services