3 ms·
Here's my take: * JA3s are mostly useless. JA4s supersede them entirely. * Using JA4s in rate limits is pretty useful and helps a lot against proxy scraping.
by davidfischer 26d ago
Here's my take:
* JA3s are mostly useless. JA4s supersede them entirely.
* Using JA4s in rate limits is pretty useful and helps a lot against proxy scraping. It was not very helpful in this attack.
* Bot detections are somewhat helpful but they don't solve scrapers/attacks by themselves. They're useful as a 2nd/3rd data point (eg. low bot score + bot detection + something else)
- cute_boi 26d agoisn't JA4 also useless because it is so easy to spoof tls. For eg. cycletls for nodejs etc..
- davidfischer 26d agoIt will probably be useless one day. In practice, it is still useful today though not for this attack.
- johneth 26d agoThere's also the JA4+ suite (https://github.com/FoxIO-LLC/ja4 https://github.com/FoxIO-LLC/ja4), in addition to standard JA4.
- arbol 21d agoYep curl cffi accurately spoofs JA4 for chrome. You need to detect client side as well.