3 ms·
> That requires client-side SSL authentication, I do not think it requires client side SSL. See: https://engineering.salesforce.com/tls-fingerprinting-with-ja3
by komuW 4y ago
> That requires client-side SSL authentication,
I do not think it requires client side SSL. See: https://engineering.salesforce.com/tls-fingerprinting-with-ja3-and-ja3s-247362855967/ https://engineering.salesforce.com/tls-fingerprinting-with-j...
What is been fingerprinted is the TLS negotiation between client and server.
- mschuster91 4y agoThat fingerprints a piece of software (and, if SSL library versions or configurations change, the version), but not a specific client. It's virtually worthless as a security measure if the endpoint is a common browser.