Comment by cobbzilla
13 hours ago
Whose DD API key is being used? This is not an anonymous access scenario. The DD API client is tied to some company, the behavior is detectable, they are banned.
Or do you give out KVMs to all your customers and say “place your DD orders with us this way”?
He's saying that some AI agent (with computer use capabilities, which the recent gpt model is supposedly good at) can at the very least, operate a browser (or phone) of the doordash website/app, scrape the contents via OCR, present them to the user, then relay any actions back to the website, all via KVM, making all of this undetectable to the site.
> the behavior is detectable, they are banned
How will DD detect that I put a sticky note on my screen at the spot where ads are displayed?
How will DD detect if a robot is operating the touchscreen or a human finger?
Ships passing in the night. I’m not disagreeing with any of this, and yall still miss the point.
I understand that individuals can make purchases with the DD API. People who want to buy things without seeing ads can always do that. Very few people will do that.
I’m referring to the obvious B2B2C use case where a company embeds DD functionality via the API. Then you’d have to teach the trick to everyone who uses your app or service and that’s not practical. If you skip at the server it’s trivially detectable.