1 comment

[ 1.9 ms ] story [ 14.2 ms ] thread
Doesn't the fingerprint also cluster the other non-malicious Go HTTP clients on the internet? Seems though TLS gave the grouping, and the GCP hosting and filename guessing is what I think made it malicious. They are two different things, am I right?