• nyan@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 days ago

    sure, but is that implying that 5% of this traffic is bad faith or rogue agents?

    Given the volume of requests that have been semi-DDOS’ing a lot of servers? 5% is probably an underestimate.

    the tools built into Claude Code and Codex surely have their own user-agent settings.

    “Surely” is like “assume”—it says more about the speaker than the entity being discussed. They almost certainly don’t use completely distinct strings (no one does—they all start with “Mozilla/5.0”); at most they might have tacked an additional bit on at the tail. And that’s if they’re being aboveboard.

    and why would they spoof Linux instead of Windows?

    Why not? But actually, this may be due to an incorrect assumption on the part of the stats collectors. Typical strings for bots that admit to being bots don’t specify an OS: “Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot” as opposed to, say “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 Edg/134.0.0.0” or “Mozilla/5.0 (Android 15; Mobile; SM-G556B/DS; rv:130.0) Gecko/130.0 Firefox/130.0”. If they’re dumping anything without OS markers into the “Linux” bucket, that might do it.

    • chrash0@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      6 days ago

      what i mean is that Claude Code wouldn’t report as a Linux desktop browser without some nefarious behavior. what i mean by “surely” is that it would be shitty of Anthropic or OpenAI to do that for no benefit on their part. curl, wget, httpie, xh, whatever client use a specific user-agent that would be a reasonable default to use for any agent without fucking around pretending just to skew metrics.

      those header report that they’re bots.