Mimicking Chrome's TLS handshake cut web request refusals by 38% in study
A developer tested how websites respond to three types of HTTP clients across 500 domains using servers in New York, Frankfurt, and Singapore. Honest Python requests were refused 35.1% of the time, while adding a Chrome user-agent string dropped refusals to 26.9%, and fully copying Chrome's TLS handshake reduced them further to 20.2%. Eighteen domains, including Facebook, WordPress, Cisco, and W3.org, consistently blocked the Python-handshake client but served the Chrome-fingerprinted one across all three regions. Notably, W3.org — which publishes the HTTP and TLS specifications — refused a standards-compliant Python client until it mimicked Chrome's handshake. The researcher noted that IP address reputation acts as a separate, deeper filter that TLS fingerprint mimicry alone cannot bypass.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in