<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Anthony T. D&apos;Ambrosio · Research</title><description>Detection and threat research portfolio. Client-side attestation, behavioral-signal integrity, and defensive analysis of anti-automation systems.</description><link>https://anthonytdambrosio.com/</link><language>en-us</language><item><title>Bots Break When You Change Things. AI Agents Don&apos;t.</title><link>https://anthonytdambrosio.com/writeups/detection-in-the-age-of-ai-agents/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/detection-in-the-age-of-ai-agents/</guid><description>For years, a quiet advantage propped up bot detection: bots were brittle. Change the flow and their hardcoded logic shattered until a human rebuilt them. AI agents remove that brittleness — they adapt in real time, and anyone can deploy one. That&apos;s the real shift.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate><category>ai-agents</category><category>bot-detection</category><category>anti-bot</category><category>detection-engineering</category><category>adaptability</category></item><item><title>One Customer, Fifty Orders: How Address Tricks Beat Quantity Limits — and How to Stop Them</title><link>https://anthonytdambrosio.com/writeups/how-address-tricks-beat-quantity-limits/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/how-address-tricks-beat-quantity-limits/</guid><description>&quot;Limit one per customer&quot; is easy to say and hard to enforce, because online, one customer can look like fifty. A look at how fake accounts and spoofed addresses defeat purchase limits, and how address validation and payment checks quietly shut it down.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>fraud-prevention</category><category>e-commerce</category><category>address-validation</category><category>account-abuse</category><category>detection-engineering</category></item><item><title>Ghidra and the Double Edge of Reverse Engineering</title><link>https://anthonytdambrosio.com/writeups/ghidra-and-the-double-edge-sword/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/ghidra-and-the-double-edge-sword/</guid><description>What Ghidra is, why the NSA built it and gave it away, why it&apos;s indispensable to defenders — and why the same capability demands judgment about how it&apos;s used.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>reverse-engineering</category><category>ghidra</category><category>tooling</category><category>security-research</category><category>ethics</category></item><item><title>TLS Fingerprinting: How a Handshake Gives the Bot Away</title><link>https://anthonytdambrosio.com/writeups/what-is-tls-protocol/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/what-is-tls-protocol/</guid><description>Before a browser sends a single byte of HTTP, its TLS handshake has already announced what software is really making the connection. Here&apos;s how ClientHello fingerprinting works, why it&apos;s tied to specific Chrome versions, and why a mismatched User-Agent is one of the cleanest tells in bot detection.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>tls</category><category>fingerprinting</category><category>ja3</category><category>ja4</category><category>bot-detection</category></item><item><title>Proxies, Explained: Why Residential Ones Are So Hard to Stop — and Where They Come From</title><link>https://anthonytdambrosio.com/writeups/what-are-proxies/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/what-are-proxies/</guid><description>Proxies are how one actor becomes a thousand. A tour of datacenter, residential, and mobile proxies, why the residential kind defeats IP-based defense by design, and the uncomfortable supply chain that produces them — often from the phones of people who have no idea.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>proxies</category><category>residential-proxies</category><category>bot-detection</category><category>supply-chain-security</category><category>fraud-prevention</category></item><item><title>What Is a JavaScript VM? Hiding Code Inside a Machine That Doesn&apos;t Exist</title><link>https://anthonytdambrosio.com/writeups/what-is-a-javascript-vm/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/what-is-a-javascript-vm/</guid><description>The strongest form of JavaScript obfuscation doesn&apos;t scramble your code — it invents a whole fake computer to run it on. Here&apos;s what a JS VM is, why anti-bot and DRM vendors rely on it, and what it can and can&apos;t actually protect.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>javascript</category><category>obfuscation</category><category>reverse-engineering</category><category>anti-bot</category><category>software-protection</category></item><item><title>Why CAPTCHAs Don&apos;t Stop Bots — and Who They Actually Stop</title><link>https://anthonytdambrosio.com/writeups/why-captchas-do-not-stop-bots/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/why-captchas-do-not-stop-bots/</guid><description>CAPTCHAs increasingly fail against the automation they&apos;re meant to block, while taxing the humans they&apos;re meant to protect. A look at why, and what actually raises the cost of abuse.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>captcha</category><category>bot-detection</category><category>fraud-prevention</category><category>accessibility</category><category>detection-engineering</category></item><item><title>What Is &apos;Sensor Data&apos;? The Telemetry Behind Bot Detection</title><link>https://anthonytdambrosio.com/writeups/what-is-sensor-data-and-how-does-it-work/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/what-is-sensor-data-and-how-does-it-work/</guid><description>The client-side script on a protected site quietly takes a reading of your device and behavior, bundles it, and ships it off to be scored. Here&apos;s what&apos;s actually in that reading — and why the most powerful signals are also the most invasive.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>sensor-data</category><category>fingerprinting</category><category>bot-detection</category><category>privacy</category><category>gpu-fingerprinting</category></item><item><title>What Is Frida? Why Your App Needs to Assume It&apos;s Being Watched</title><link>https://anthonytdambrosio.com/writeups/what-is-frida-and-why-you-should-assume-your-app-is-being-watched/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/what-is-frida-and-why-you-should-assume-your-app-is-being-watched/</guid><description>Frida turns a running app inside-out at runtime — reading memory, hooking functions, bypassing client-side checks. Here&apos;s what it is, why obfuscation doesn&apos;t stop it, and why Frida, root, and jailbreak detection are a treadmill you can never step off.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>frida</category><category>mobile-security</category><category>rasp</category><category>reverse-engineering</category><category>app-hardening</category></item><item><title>Why Drop Queues Often Help the Bots They&apos;re Meant to Stop</title><link>https://anthonytdambrosio.com/writeups/why-drop-queues-hurt-real-customers/</link><guid isPermaLink="true">https://anthonytdambrosio.com/writeups/why-drop-queues-hurt-real-customers/</guid><description>Virtual waiting rooms are supposed to give real customers a fair shot at limited stock. But when a queue orders people by who joined first, it just re-runs the exact speed race bots always win. The fix is in the ordering.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>bot-mitigation</category><category>queue-design</category><category>e-commerce</category><category>fairness</category><category>detection-engineering</category></item></channel></rss>