For IBM owned* 9.0.0.0/8 which has 16,777,214 (and when I worked there twenty years ago there were a few hundred other ranges that they owned/acquired).
I think the next step is we force the JS through a halting verifier a-la BPF and fake all the fingerprinting API's. The browser vendors are not going to do it, and they cant be trusted anyway.
Comments
Does Google have only one AS? I would expect they have many. (Serious question, I have never worked anywhere close to Internet routing.)
I know they have at least two ASNs for peering (AS15169 and AS36040 - source at https://peering.google.com/#/options/peering)
Peering database shows a number of others though (excludes google fiber and some other properties):
https://www.peeringdb.com/net/433
Hard part with ASNs is keeping track across legal business entities of what we consider a single company.
For IBM owned* 9.0.0.0/8 which has 16,777,214 (and when I worked there twenty years ago there were a few hundred other ranges that they owned/acquired).
* Turns out they freed this up a while back (good!): https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...
Apple has 17.0.0.0/8 and then some https://bgp.he.net/AS714
https://en.m.wikipedia.org/wiki/List_of_assigned_/8_IPv4_add...
One more of the ever growing number of websites that require Javascript to browse.
I'm reading, what's the justification for Javascript to be running?
I think the next step is we force the JS through a halting verifier a-la BPF and fake all the fingerprinting API's. The browser vendors are not going to do it, and they cant be trusted anyway.
And stop sending the user-agent.
Anti-bot/scraping.
Selenium has allowed scraping of JavaScript generated content for a long time, to say nothing of other options like headless Chrome.