Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
avastel
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
From Puppeteer stealth to Nodriver: How anti-detect frameworks evolved over time
(blog.castle.io)
6 points
by
avastel
1y ago
|
0 comments
32.
▲
by
avastel
1y ago
Author here: There’ve been a lot of HN threads lately about scraping, especially in the context of AI, and with them, a fair amount of confusion about what actually works to stop bots on high-profile websites. This post uses TikTok’s obfusc
33.
▲
What TikTok's virtual machine tells us about modern bot defenses
(blog.castle.io)
4 points
by
avastel
1y ago
|
1 comments
34.
▲
by
avastel
1y ago
Reposting a similar point I made recently about CAPTCHA and scalpers, but it’s even more relevant for scrapers. PoW can help against basic scrapers or DDoS, but it won’t stop anyone serious. Last week I looked into a Binance CAPTCHA solver
35.
▲
by
avastel
1y ago
Yeah, not (too) surprising after a few years in the anti-bot industry. Last week I looked into a Binance CAPTCHA solver that didn’t use a browser at all, just a basic HTTP client. The attacker had reverse engineered the entire signal collec
36.
▲
What a Binance CAPTCHA solver tells us about today's bot threats
(blog.castle.io)
4 points
by
avastel
1y ago
|
1 comments
37.
▲
by
avastel
1y ago
Author here. A few weeks ago, someone posted a link on Reddit to an open-source CAPTCHA solver made for Binance’s slider challenge. It’s written in Python and works without using a browser. Just a custom HTTP client, some image matching, an
38.
▲
Detecting Hidemium: Fingerprinting inconsistencies in anti-detect browsers
(blog.castle.io)
2 points
by
avastel
1y ago
|
1 comments
39.
▲
by
avastel
1y ago
Hi, author here. I wrote a blog post where I analyze Hidemium, a popular anti-detect browser. I break down the techniques it uses to spoof fingerprints and show how JavaScript feature inconsistencies can reveal its presence. Of course, JS f
40.
▲
Detect and crash Chromium bots
(blog.castle.io)
146 points
by
avastel
1y ago
|
47 comments
41.
▲
by
avastel
1y ago
Using a 4G dongle makes it easier to hide in the crowd indeed. Since your traffic will go through heavily shared mobile IPs, probably with thousands of users behind them, anti-bot vendors won't/shouldn't block per IP, but per
42.
▲
by
avastel
1y ago
The DB contains different types of proxies: - Residential - ISP - Data center I don't include mobile proxies since they're heavily shared, so knowing that an IP address was used as a proxy at some point is basically useless. Regar
43.
▲
by
avastel
1y ago
I am working on a curated database of proxy IP addresses frequently used by bots: https://deviceandbrowserinfo.com/product/proxies-ips So far I have ~ 3M distinct IP addresses per 30 days, with a lot of fresh proxy IPs
44.
▲
by
avastel
1y ago
Author here: I've been in the bot industry/bot detection field for ~ 10 years. I frequently see strong opinion about bot detection on Reddit and HN, in particular why it doesn't make sense for bot detection companies (I won&#
45.
▲
How dare you trust the user agent for bot detection?
(blog.castle.io)
3 points
by
avastel
1y ago
|
1 comments
46.
▲
Traditional bot detection techniques are not enough and what you can do about it
(blog.castle.io)
1 points
by
avastel
2y ago
|
1 comments
47.
▲
by
avastel
2y ago
Author of the post: bot detection and bot-related topics are often discussed on HN, particularly lately with the increase of AI scrapers trying to scrape protected websites to gather training data for LLMs. Most of the time, people just rec
48.
▲
by
avastel
2y ago
Castle ( https://castle.io ) | Senior ML Engineer | Senior R&D Detection Engineer | REMOTE (Europe/EMEA) | Full-time Hi HN! I’m Antoine, Head of Research at Castle. We’re a YC-backed Series A startup helping companies lik
49.
▲
How to detect scripts injected via CDP in Chrome
(blog.castle.io)
2 points
by
avastel
2y ago
|
0 comments
50.
▲
Bot detection 101: How to detect bots In 2025?
(blog.castle.io)
1 points
by
avastel
2y ago
|
0 comments
51.
▲
by
avastel
2y ago
Author here: This is the 2nd blog post in a series about anti-detect browsers. Anti-detect browsers are browsers that integrate features that aim to bypass anti-fraud/bot detection systems, such as: - native proxies integration; - anti
52.
▲
Anti-Detect Browser Analysis: How to Detect the Undetectable Browser?
(blog.castle.io)
1 points
by
avastel
2y ago
|
1 comments
53.
▲
Canvas Fingerprinting in the Wild
(blog.castle.io)
3 points
by
avastel
2y ago
|
0 comments
54.
▲
Detecting Noise in Canvas Fingerprinting
(blog.castle.io)
41 points
by
avastel
2y ago
|
64 comments
55.
▲
Open source lists of proxy IP addresses used by bots
(github.com)
4 points
by
avastel
2y ago
|
0 comments
56.
▲
Iframes and when JavaScript worlds collide
(gregros.dev)
1 points
by
avastel
2y ago
|
0 comments
57.
▲
by
avastel
2y ago
I build a website related to fraud (detection), bot (detection), fingerprinting, email intelligence. You can test your browser fingerprint here https://deviceandbrowserinfo.com/info_device and get information about disposab
58.
▲
How to get started in bot detection and bot development?
(deviceandbrowserinfo.com)
1 points
by
avastel
2y ago
|
0 comments
59.
▲
Investigating the Puppeteer mode of Open Bullet 2 (credential stuffing tool)
(deviceandbrowserinfo.com)
2 points
by
avastel
2y ago
|
0 comments
60.
▲
Investigating Open Bullet 2's HTTP request mode (credential stuffing tool)
(deviceandbrowserinfo.com)
1 points
by
avastel
2y ago
|
0 comments
More ›