In the summer of 2021, I was working at Shujinko, talking with a DevSecOps teammate about buying a GPU for our gaming PCs. I couldn’t find one. Newegg, Amazon, Best Buy, B&H — all completely out of stock. At the same time, GPUs were selling for exorbitant prices on secondary markets like eBay. It didn’t make sense.
What was happening?
We now know it was a textbook case of supply and demand in 2021, affecting products and sectors across the board: a global pandemic, supply-chain constraints, and a surge in Web 3.0 crypto mining and prospecting. Those forces led to significant stock shortages, inventory hoarding through botting software, and reseller price gouging in the GPU retail market.
As both a consumer and a security professional, I had questions. Where were the boundary defenses? Where were the bot-management solutions? Where were the customer-experience teams when we needed them most?
During my time on the security teams at Starbucks and CardFree, I got to know and respect the vendors who built solutions for exactly these challenges. My understanding was that those solutions were highly effective at preventing this kind of event. They aren’t.
Today these automated threats — often referred to collectively as bots — are incredibly successful at defeating boundary defenses like Web Application Firewalls, API security measures, and bot-management solutions at scale. In the infinite cat-and-mouse game, they continually improve and evolve, and many times they’re winning.
That means customers can’t get the products they want, whether it’s a signed Taylor Swift CD or a pair of Travis Scott Air Jordan 1 Lows. And companies’ data is being polluted by AI-powered bots. This is bad for customers and terrible for businesses.
For the past year and a half, I’ve been heavily researching this space and looking for a way to help protect companies from data-pollution attacks. To do it, I hopped over the fence and learned the ins and outs of retail bot operators, so I could start building better defenses against the natural byproduct of their activity: data pollution. Exploring the underbelly of the retail world has been eye-opening, and I’ve never been more motivated to help companies improve the integrity of their data — and help customers get the products they want. (I did get that GPU, by the way. It was painful; I’ll tell you about it over coffee.)
My team is building our MVP, along with a community for security, software-engineering, and product professionals to discuss these challenging issues. I’m excited to start writing more here and sharing what we learn. First up, we’ll be diving into the Bot Operators’ Tech Stack. Stay tuned.
