More from the field

Additional essays, operational notes, and research observations.

Good bots, bad bots, and the gray area
taxonomythreat-modelinghistory

Good bots, bad bots, and the gray area

Why bot classification depends on intent, authorization, behavior, and business context rather than a simple allow or block label.

Earl Potters
Playwright detection: what still leaks
automationheadlesschallenges

Playwright detection: what still leaks

An overview of the automation indicators that can remain visible even when browser automation is carefully configured.

Earl Potters
IP reputation is context, not verdict
networkip-intelligenceproxy

IP reputation is context, not verdict

A production-focused note on using IP reputation as supporting evidence instead of a standalone block decision.

Earl Potters
Feature engineering for bot behavior models
behaviormachine-learninganalytics

Feature engineering for bot behavior models

How to turn raw interaction traces into features that are useful for bot classification and operational review.

Earl Potters
Fingerprint entropy after the anti-detect wave
fingerprintingevasionresearch

Fingerprint entropy after the anti-detect wave

Why high-cardinality signals still matter, where they collapse, and how defenders should think about coherence rather than novelty.

Earl Potters
CAPTCHA bypass claims need threat models
captchaapi-securitychallenges

CAPTCHA bypass claims need threat models

Why claims about CAPTCHA strength or bypass only make sense when tied to the attacker model and production workflow.

Earl Potters
API abuse patterns beyond rate limits
api-securityrate-limitingaccount-takeover

API abuse patterns beyond rate limits

A field guide to API abuse patterns that survive simple rate limiting and require session, identity, and intent signals.

Earl Potters
Where bot detections belong in production
productionwafobservability

Where bot detections belong in production

How to decide whether a bot detection belongs at the edge, in application code, in session state, or in analyst workflows.

Earl Potters
Logging bot defense for SOC review
productionobservabilitytuning

Logging bot defense for SOC review

What bot defense logs need to contain so security teams can investigate incidents instead of reading opaque scores.

Earl Potters
What a good bot defense capstone proves
capstonedeliverablescommunication

What a good bot defense capstone proves

A rubric-style note on the evidence a capstone project should produce to be credible, useful, and safe to share.

Earl Potters
Challenge systems fail when telemetry is thin
challengesheadlesstelemetry

Challenge systems fail when telemetry is thin

A JavaScript challenge by itself is rarely enough; the value comes from joining challenge outcomes to network, session, and behavioral context.

Earl Potters