← Back to context

Comment by petre

3 years ago

Isn't the client's IP address a sufficient unique identifier?

Absolutely not. Dozens if not hundreds of legitimate clients can appear on the same public IPv4 address, being home internet customers behind a NAT. The same client can trivially change their IPv4 and likely IPv6 address on a mobile network by toggling flight mode to reconnect.