Public methodology

Catalog duplicate-host signals

How two catalog signals test whether multiple hostnames may expose the same service.

What it measures

Publication limit: The source note explicitly blocks publication of any duplicate-rate claim. Its manual review found that a correctly counted collision can still represent a different phenomenon. This page documents the method, not a duplicate-rate result.

Two independent signals over the complete endpoints catalog: a payout destination declared under more than one host, and the same path, response-shape hash, and payment-required amount appearing under more than one host.

How it is produced

The canonical read-only script is version two of the duplicate-host measurement. It normalizes URL netloc values to lowercase, aggregates both hostnames and registrable domains, excludes unresolved URL templates, parses declared payout destinations from stored response payloads, and separately builds content-and-price signatures. It reports parsing failures and truncation rather than treating missing payload data as evidence of absence.

Canonical source

duplicate-hosts-measure-v2.py

Ad hoc queries and the deprecated version-one script are not cited sources for this measure.

Limits and assumptions

How to refute this

  1. Show that the largest Signal A cluster is one legitimate platform, making the aggregate a platform artifact rather than duplicate services. Always report the cluster-size distribution and name the concentration when publication is allowed.
  2. Run Signal A with the largest cluster excluded before publishing a result.
  3. Show that Signal B measures shared framework templates rather than duplicates. Review the top collisions manually; exclude a common SDK signature or lower the claim if it joins unrelated operators.
  4. Show that Signal B drifts by more than 10% between canonical runs one day apart. Before publication, use two runs at least 24 hours apart and cite both or the window median.

Last validated

2026-08-30

Run timestamp 13:58:15Z. This measure is citable only with its run time, because the catalog changes between runs.