A TLS fingerprint won't tell you it's a bot — what it reaches for will

Most tools ask whether a TLS fingerprint resembles Chrome. I wanted a different question — how does it behave? So I sat inside a residential proxy network, named a million handshakes, and found the bulk of the ‘bot’ traffic isn’t faking Chrome. It’s driving it.

July 19, 2026 · 9 min · Vitalii Zaiats

Detecting credential stuffing through encrypted traffic

Encrypted traffic still leaks its silhouette: near-identical response sizes (CV < 0.05) plus JA3 counts turn a sealed TLS tunnel into a credential-stuffing detector.

March 24, 2026 · 4 min · Vitalii Zaiats