frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Privacy Experiment – Rewriting HTTPS, TLS, and TCP/IP Packet Headers

1•un-nf•2h ago
The README: https://github.com/un-nf/404/blob/main/README.md

Or the LP: https://404-nf/carrd.co

Or read on...

In a small enough group of people, your TLS-handshake can be enough to identify you as a unique client. Around six-months ago, I began learning about client-fingerprinting. I had understood that it was getting better and more precise, but did not realize the ease with which a server could fingerprint a user - after all, you're just giving up all the cookies! Fingerprinting, for the modern internet experience, has become almost a necessity.

It was concerning to me that servers began using the very features that we rely on for security to identify and fingerprint clients.

- JS - Collection of your JS property values - Font - Collection of your downloaded fonts - JA3/4 - TLS cipher-suite FP - JA4/T - TCP packet header FP (TTL, MSS, Window Size/Scale, TSval/ecr, etc.) - HTTPS - HTTPS header FP (UA, sec-ch, etc.) - Much more...

So, I built a tool to give me control of my fingerprint at multiple layers:

- Localhost mitmproxy handles HTTPS headers and TLS cipher-suite negotiation - eBPF + Linux TC rewrites TCP packet headers (TTL, window size, etc.) - Coordinated spoofing ensures all layers present a consistent, chosen fingerprint - (not yet cohesive)

Current Status: This is a proof-of-concept that successfully spoofs JA3/JA4 (TLS), JA4T (TCP), and HTTP fingerprints. It's rough around the edges and requires some Linux knowledge to set up.

When there are so many telemetry points collected from a single SYN/ACK interaction, the precision with which a server can identify a unique client becomes concerning. Certain individuals and organizations began to notice this and produced sources to help people better understand the amount of data they're leaving behind on the internet: amiunique.org, browserleaks.com, and coveryourtracks.eff.org to name a few.

This is the bare bones, but it's a fight against server-side passive surveillance. Tools like nmap and p0f have been exploiting this for the last two-decades, and almost no tooling has been developed to fight it - with the viable options (burpsuite) not being marketed for privacy.

Even beyond this, with all values comprehensively and cohesively spoofed, SSO tokens can still follow us around and reveal our identity. When the SDKs of the largest companies like Google are so deeply ingrained into development flows, this is a no-go. So, this project will evolve, I'm looking to add some sort of headless/headful swarm that pollutes your SSO history - legal hurdles be damned.

I haven't shared this in a substantial way, and really just finished polishing up a prerelease, barely working version about a week ago. I am not a computer science or cysec engineer, just someone with a passion for privacy that is okay with computers. This is proof of concept for a larger tool. Due to the nature of TCP/IP packet headers, if this software were to run on a distributed mesh network, privacy could be distributed on a mixnet like they're trying to achieve at Nym Technologies.

All of the pieces are there, they just haven't been put together in the right way. I think I can almost see the whole puzzle...

Comments

un-nf•1h ago
What fingerprinting vectors am I missing? Are there tools that I'm overlooking? What are some next steps - places the architecture is lacking?

Same Car. Different Country. Deadlier in a Crash [video]

https://www.youtube.com/watch?v=dVI-vFq39-I
1•gmays•2m ago•0 comments

How to Become an Entry Level Birder

https://www.stumpedbynature.com/p/stumped-by-nature-9d25
1•EthanDBrooks•3m ago•1 comments

Navigating a webpage with a gamepad and JavaScript (2020)

https://www.voorhoede.nl/en/blog/navigating-the-web-with-a-gamepad/
1•DannyPage•4m ago•0 comments

Lab-on-a-Scalpel: 3D-Printed Electrochemical Cell for the Operating Theater

https://pubs.acs.org/doi/10.1021/acs.analchem.5c00599
2•PaulHoule•6m ago•0 comments

DEC Mini – computer inspired by one of the loveliest retro computers of the 80s

https://decmini.tin.cat/
2•pabs3•9m ago•0 comments

In a Skyscraper City, They Fix Cobblestone Streets by Hand

https://www.nytimes.com/2025/11/08/nyregion/nyc-cobblestone-streets.html
1•bookofjoe•13m ago•1 comments

The 'Toy Story' You Remember

https://animationobsessive.substack.com/p/the-toy-story-you-remember
1•ani_obsessive•16m ago•0 comments

Paramount Cuts 1,600 More Jobs as Part of Plan to Save $3B

https://www.bloomberg.com/news/videos/2025-11-10/paramount-cuts-1-600-more-jobs-in-cost-cutting-m...
3•mgh2•19m ago•0 comments

Recessions have become ultra-rare. That is storing up trouble

https://www.economist.com/finance-and-economics/2025/11/10/recessions-have-become-ultra-rare-that...
3•andsoitis•19m ago•0 comments

Happy 30th Birthday Task Manager

https://www.youtube.com/watch?v=yQykvrAR_po
2•quizme2000•21m ago•1 comments

Universal Basic Income in an AGI Future

https://substack.com/home/post/p-178560893
1•DalasNoin•23m ago•0 comments

Space Dj

https://magenta.withgoogle.com/spacedj-announce
1•frmssmd•24m ago•0 comments

The Definitive Classic Mac Pro (2006-2012) Upgrade Guide

https://blog.greggant.com/posts/2018/05/07/definitive-mac-pro-upgrade-guide.html
1•ibobev•27m ago•0 comments

Natural Language, Semantic Analysis, and Interactive Fiction (2006) [pdf]

https://worrydream.com/refs/Nelson_G_2006_-_Natural_Language,_Semantic_Analysis_and_Interactive_F...
2•vinhnx•31m ago•0 comments

Show HN: Data Modeling Ancient Chinese Logic (Bazi/Ziwei Doushu) with AI

https://suanmingzhun.com
1•Ethancurly5246•34m ago•0 comments

Precision Spindle Metrology Pt.1: Fundamental Concepts [video]

https://www.youtube.com/watch?v=gt2gK-oxy5s
1•pillars•40m ago•1 comments

State of Crypto

https://stateofcrypto.a16zcrypto.com/
1•gmays•40m ago•0 comments

Branches influence the performance of your code and what can you do about it

https://johnnysswlab.com/how-branches-influence-the-performance-of-your-code-and-what-can-you-do-...
2•vinhnx•43m ago•0 comments

Lloyd's Open Form

https://en.wikipedia.org/wiki/Lloyd%27s_Open_Form
3•thunderbong•45m ago•0 comments

Is Fast Charging Killing the Battery? A 2-Year Test on 40 Phones [video]

https://www.youtube.com/watch?v=kLS5Cg_yNdM
1•zdw•49m ago•0 comments

A Couple of Cool Neurotech Companies

https://thelightcone.substack.com/p/a-couple-of-cool-neurotech-companies
1•bci12333•51m ago•0 comments

We built a black box X-Ray for AI Agents

https://devhunt.org/tool/agent-compass-by-future-agi
1•nikhilpareek13•51m ago•0 comments

Virginia Teen Narrowly Defeats His Former Civics Teacher in County Election

https://www.nytimes.com/2025/11/07/us/politics/surry-county-virginia-supervisor-election.html
10•zdw•53m ago•1 comments

Dioxus 0.7: User interfaces in Rust that run anywhere

https://github.com/DioxusLabs/dioxus/releases/tag/v0.7.0
1•petralithic•53m ago•0 comments

Aussie Engineers, Get to the States

https://thundergolfer.com/blog/get-to-the-states
2•steveharrison•54m ago•4 comments

Dundee and US surgeons achieve world-first remote stroke surgery on a human body

https://www.bbc.com/news/articles/cjw983pvz6lo
2•1659447091•56m ago•0 comments

Ask HD: How should the UK Post Office problem be solved?

https://www.bbc.co.uk/news/articles/cz6n2v7ywgeo
3•IndySun•59m ago•1 comments

My Reporting on the Columbia Protests Led to My Deportation

1•computersuck•1h ago•0 comments

iPhone Air Sales Are So Bad That Apple's Delaying the Next-Generation Version

https://www.macrumors.com/2025/11/10/next-generation-iphone-air-delayed/
4•mgh2•1h ago•1 comments

Show HN: Typesafe async friendly unopinionated enhancements to SQLAlchemy Core

https://github.com/sayanarijit/sqla-fancy-core
1•sayanarijit•1h ago•0 comments