Fingerprinting browser-impersonating bots w/o JavaScript (open spec)
Details
- External ID
- 47583988
- Source
- HN
- Company
- —
- Product
- Fingerprinting browser-impersonating bots w/o JavaScript (open spec)
- Website domain
- github.com
- Launched
- March 31, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.2853628536285363
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
I've published an open specification for a detection method I'm calling RQ4 (Request Context Fingerprinting). It analyzes whether HTTP request headers are logically consistent with real browser behavior - not just what headers are present, but whether they make sense together given the request context.
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Security
- Function
- —
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- fingerprinting bot detection without javascript
- Manually corrected
- False
Could you build this?
No Designing and proving an novel, open bot detection specification based on HTTP header consistency without JavaScript requires deep empirical network telemetry data and anti-fraud domain expertise.
What it would actually take: Building an effective Request Context Fingerprinting engine involves analyzing massive datasets of legitimate browser traffic against malicious bot traffic to map valid permutations of HTTP/2 and HTTP/3 headers, pseudo-headers, and client hints. The implementation requires high-throughput reverse proxy middleware (Envoy, OpenResty, or Rust-based proxies) capable of wire-speed state tracking and heuristic scoring. Validating and continuously tuning such rules against stealthy botnets requires deep networking protocols expertise and large-scale threat intelligence.
Discussion
4 comments analyzed.
Concerns raised: Example site fails without JavaScript despite claiming no JS needed
Competitors
Other products that read as similar to this one — 30 launches clear the similarity bar, closest 8 shown.
Attention rank: #21 of 31 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 153 days after the earliest competitor.
- CreepJS Browser Fingerprinting · hn · 2026-04-23 · 5 upvotes · similarity 0.50
- laravel-visitor-fingerprint · github · 2026-09-11 · 7 upvotes · similarity 0.40
- Prompt-injection firewall for OpenClaw agents · hn · 2026-02-02 · 6 upvotes · similarity 0.39
- I built a cross-browser extension that controls fingerprinting surfaces · hn · 2026-07-31 · 20 upvotes · similarity 0.37
- surfacemap · github · 2026-09-16 · 9 upvotes · similarity 0.36
- OpenBotAuth · hn · 2025-11-20 · 6 upvotes · similarity 0.36
- Server Config Generator · ph · 2026-09-29 · 2 upvotes · similarity 0.34
- The Only Safe Scanner · ph · 2026-09-13 · 3 upvotes · similarity 0.33
Other launches for this product
- No other launches for this product.