A browser can fake its WebRTC address — it can't fake the packet

Every WebRTC leak check reads a value the browser reports, and an anti-detect browser reports whatever keeps you happy. So I stopped reading its answer and started checking mine: run the STUN server yourself, and whether a packet actually arrived becomes the one thing the browser can’t forge. Here’s the idea, a widget to test your own browser, and an honest tour of everywhere it fails.

July 22, 2026 · 8 min · Vitalii Zaiats

A TLS fingerprint won't tell you it's a bot — what it reaches for will

Most tools ask whether a TLS fingerprint resembles Chrome. I wanted a different question — how does it behave? So I sat inside a residential proxy network, named a million handshakes, and found the bulk of the ‘bot’ traffic isn’t faking Chrome. It’s driving it.

July 19, 2026 · 9 min · Vitalii Zaiats

The iOS proxy ghost: why you can't find an iPhone in a residential pool

Turns out the iPhone on every proxy provider’s landing page is the one device that basically can’t be in the pool — and that absence is exactly what makes a real iOS fingerprint a trustworthy “human here” signal.

April 3, 2026 · 4 min · Vitalii Zaiats

TCP-fingerprinting 300K residential proxy IPs: 98% are Linux

Probed 319,706 residential-proxy exits by their TCP SYN fingerprints — 98% Linux, two kernel defaults covering 70%+, MSS leaking the real link, and a handful of big ISPs — showing the “real user devices” are mostly a rack of Linux boxes.

March 26, 2026 · 4 min · Vitalii Zaiats