Web Fingerprinting
Web fingerprinting is the process of identifying a browser, device, or automated bot by combining signals from multiple independent layers of a request. Modern anti-bot systems (Cloudflare, PerimeterX, DataDome, etc.) score all layers simultaneously — passing one is not enough. The Golden Rule: Every layer must tell the same consistent story. One mismatch = detection.The Three Layers
Layer 1: Network-Level (pre-JS)
Signals extracted before any browser JavaScript runs, at the TCP/TLS connection: TCP fingerprint (kernel-set, cannot be changed by proxies or browsers):- Initial window size, MSS, TCP options order, TTL
- Per OS: Windows 10/11=window 65535/TTL 128/options MSS+NOP+WS+NOP+NOP+SACK_PERM; Linux=29200/64/MSS+SACK_PERM+TS+NOP+WS; macOS=65535/64
- Detected with tools like p0f, Nmap OS detection
- HTTP and SOCKS proxies operate above TCP layer — they cannot modify TCP handshake characteristics; real OS always exposed to network observers
- Cipher suite list, TLS extensions, their order, ALPN protocols in the Client Hello
- JA3: MD5 hash of selected TLS fields; JA4: improved successor
- Set by the HTTP client library or browser’s TLS stack
curl-cffimimics Chrome’s TLS fingerprint from Python without a real browser
- SETTINGS frame parameter order, initial window size, HPACK header order
- Each browser/version has a characteristic pattern
Layer 2: Browser-Level (JS APIs)
Readable via JavaScript after the connection is accepted:playwright-stealth / playwright-extra patch these JS properties. CDP-native tools (Pydoll) avoid navigator.webdriver entirely.
Proxy Layer Positioning
Most proxies only handle TCP. UDP traffic (WebRTC, DNS, QUIC/HTTP3) bypasses proxy configuration entirely. Use
--disable-quic Chrome flag to force HTTP/2 over TCP for QUIC mitigation.
WebRTC IP Leak
The most common cause of IP leakage in proxied automation. WebRTC uses STUN servers over UDP to discover the real public IP — this happens below the browser’s proxy layer. JavaScript on the page can trigger discovery with ~10 lines viaRTCPeerConnection and Google STUN servers.
Mitigation (Pydoll API):
Layer 3: Behavioral
ML models trained on billions of human interaction events:- Mouse: trajectory curvature, velocity profile, Fitts’s Law compliance (larger targets = shorter movement time)
- Keystrokes: dwell time (key-down to key-up), flight time (between keys), bigram patterns
- Scroll: momentum, inertia, deceleration curves — human scroll has physical realism
- Event ordering:
mousemove → mouseover → mouseenter → clickis natural; bots often fireclickdirectly
Detection Is Holistic, Not Per-Layer
A request with:- ✓ Correct TCP fingerprint (macOS)
- ✓ Correct JA3 (Chrome 120)
- ✗
navigator.webdriver = true
navigator.webdriver does not help if your TLS fingerprint says Python requests.
Evasion Principles
- Consistency over perfection: a correctly configured Firefox fingerprint beats an “almost-right” Chrome fingerprint with one mismatch
- Holistic approach: align network, browser, and behavioral layers together
- Use a real browser: headless Chromium with CDP is better than
requests; non-headless is better than headless - Residential/mobile proxies: fix IP reputation and help match expected TLS from those ISPs
- Continuous adaptation: fingerprinting evolves monthly; static evasion setups degrade
Cloudflare Tiers
Standard Cloudflare (no Turnstile): Two flags defeat detection on most sites:headless: false forces a real visible browser process; --disable-blink-features=AutomationControlled removes the navigator.webdriver JS property.
Cloudflare Turnstile: Analyzes mouse trajectories, behavioral patterns, advanced fingerprinting. Cannot be passed programmatically. Workarounds: puppeteer-real-browser (community library, reported to solve Turnstile in some cases); Chrome Debug Port + MCP (attach to real user-profile Chrome instance with existing auth cookies — zero automation flags set).
Free vs. Hybrid Stack
Free stack: Playwright/Puppeteer (headless=false), playwright-stealth, free proxy lists, rotated user-agents, random delays 2–10s, human-like mouse/scroll.
Hybrid recommended: Playwright + playwright-stealth + mobile/4G proxies (Proxies.sx, VoidMob, Bright Data) + 2Captcha for CAPTCHA fallback.
Takeaway: free-only suits learning and prototypes. Paid proxies are the minimum addition for production reliability on anti-bot-protected sites.
Alternative Stealth Tools
- curl-cffi (Python) — mimics real Chrome TLS fingerprints; effective against basic detection without a headless browser
- Camoufox — stealth-optimized Firefox build
- playwright-extra / Patchright — extended stealth patches for Playwright
- nodriver / undetected-chromedriver — community alternatives; results vary by target site
- FlareSolverr — proxy service that solves Cloudflare challenges
Legal and Ethical Framework
hiQ v. LinkedIn (2022): Scraping publicly available data generally permitted; circumventing technological barriers may still violate CFAA.
QVC v. Resultly (2020): Excessive requests constitute trespass to chattels — volume and server impact matter, not just technical access.
Ethical minimum: respect
robots.txt; rate-limit (1+ second minimum between requests, ≤5 concurrent per site); collect only what you need.
High-risk targets to avoid: banking/financial (fraud detection), government portals (legal penalties), healthcare (HIPAA), e-commerce account creation (permanent bans).
Practical Tool Map
Related Pages
- Proxy Rotation — proxy types and their effect on network fingerprint
- WebRTC IP Leak — UDP-level bypass that defeats otherwise-correct proxy setup
- Pydoll — library with systematic fingerprint evasion support