Tag

Everything on detection

Every guide, comparison and detector run we have published under detection.

Article 4 min

What a page can actually detect about headless Chrome

Old headless Chrome gave itself away through a UA token, empty plugin arrays and zeroed window dimensions, and new headless mode closed most of that. What is left to detect is almost always the absence of a real GPU, not a flag.

Article 4 min

How Cloudflare bot management decides to block you

Cloudflare scores IP reputation and TLS behaviour before your browser fingerprint is ever read, then layers a managed challenge and a behavioural score on top. Most blocks people blame on fingerprinting are actually decided one layer earlier.

Article 5 min

Why a correctly configured proxy still leaks your real IP over WebRTC

WebRTC gathers ICE candidates over UDP, outside the HTTP or SOCKS proxy path, so a site can read your real public IP with two lines of JavaScript regardless of what the address bar shows. Disabling WebRTC outright trades one tell for another.

Article 5 min

How JA3 and JA4 catch a scraper before the page even loads

The TLS handshake and HTTP/2 frame order reveal what software made a request, regardless of the User-Agent header. JA3 and JA4 hash that order, which is why a copied Chrome header over a Python handshake fails before content loads.

Article 4 min

Residential vs datacenter proxies, and the mistake that wastes both

Residential is not automatically better and datacenter is not automatically dead. What actually decides the outcome is whether the proxy is bound to the identity, and most setups get that part wrong in a way that is easier to detect than the IP itself.

Article 6 min

1,011 text measurements: how a signup flow proves your browser is lying about its OS

Detection stopped asking which fonts you have and started measuring how wide they are. A missing font is not hidden: it renders in the fallback and measures exactly like a family nobody has ever installed. If your persona claims Windows on a machine that is not Windows, that is a one-line contradiction, and no amount of aged profiles or clean residential exits talks you out of it.

Article 4 min

How to check a browser profile before you trust it with an account

A high anonymity score means little. What gets profiles flagged is contradiction between signals, not any single value. A checklist of the pairs that must agree, and how to test each one in a few minutes.

Article 4 min

How anti-bot systems decide you are a bot

DataDome, Kasada, Cloudflare and PerimeterX do not run one check, they score a risk profile from network, TLS, fingerprint, behaviour and history. Understanding which layer flagged you is the difference between fixing it and guessing.

Article 4 min

Why accounts still get flagged after you bought the antidetect browser

The most common complaint in this category is that people set up a fingerprint browser and residential proxies and got banned anyway. Usually the tooling was fine. Here is what the tooling never covered, ranked by how often it is the real cause.