Ships passing in the night. I’m not disagreeing with any of this, and yall still miss the point.
I understand that individuals can make purchases with the DD API. People who want to buy things without seeing ads can always do that. Very few people will do that.
I’m referring to the obvious B2B2C use case where a company embeds DD functionality via the API. Then you’d have to teach the trick to everyone who uses your app or service and that’s not practical. If you skip at the server it’s trivially detectable.
> If you skip at the server it’s trivially detectable.
I don't see how. If I built a touchscreen-using robot, DD couldn't detect it. If some middleman business had a boiler room of 10 robots, it would be the same. All network requests identical to the official app. And if you think they'd look at IP addresses or something, how would they tell it apart from a college campus or a CGNAT gateway?
You can’t MITM your clients unless you root-cert them. The clients are independently attesting to DD, you can’t spoof it unless you’re the client. The B2B provider can’t do this without MITM attack. Any “legitimate” partner doing this is instantly banned & probably sued.
How will DD detect that I put a sticky note on my screen at the spot where ads are displayed?
How will DD detect if a robot is operating the touchscreen or a human finger?