It is especially for someone like DarkstaR, it's really just a matter of figuring out exactly what data is sent and ensuring the spoofed data is correctly formatted with how the client would send it, particularly the CPU and GPU model strings. The big question is whether it's actually worth the effort to implement as we have really have no idea how or even if CIP are using the data with regards to detection as it certainly wasn't its initial purpose considering the kind of data being collected, I do think it is definitely worth considering as at the very least it will somewhat reduce your risks but of course by no means would it mean you are safe.