top | item 22149355

(no title)

CapacitorSet | 6 years ago

All the fingerprinting tools I've seen so far do not include JA3 signatures, which in my opinion make for an interesting bit of information - they introduce few bits of entropy since they depend on the TLS implementation, but for the same reason they can't be easily spoofed.

Plugging in an article and demo I wrote some time ago: https://jwlss.pw/ja3/

discuss

order

GordonS|6 years ago

I was going to mention the lack of TCP and TLS fingerprinting too - I wonder if those are actually used by rogue advertisers?

Also, I guess TLS fingerprints would change over time, with browser upgrades, although I'd expect changes to be relatively infrequent.