Even if BitNinja were spectacular on the client side of things – with the amount of totally non-actionable notices we receive – I couldn’t bring myself to even try it. Server administrators are busy enough – they don’t need to know every time your site gets a ping-back from one of our clients’ sites, or every time a bounce is received, etc. I’m sure they probably do a good job at stopping the real threats but they make a huge deal out of the most trivial issues as well.
An example is that we had one client that was using our services as well as the services of a provider that uses BitNinja. That client had designed their sites to interact with each other – to transmit data back and forth. We got pretty constant BitNinja notices over this normal, expected, and innocuous activity.
If it weren’t for the 1 in 100 reports that were actionable we would simply block their notices entirely.