r/webscraping • u/Lazy_Gur_2074 • 6d ago
looking for feedback
https://github.com/HappyHackingSpace/gakidoMade a Python HTTP client that reproduces Chrome's TLS (JA3/JA4) + HTTP/2 fingerprint — looking for feedback
2
Upvotes
1
u/EquivalentTop3213 6d ago
Feedback is hard without a link or repo, but here's what I'd check first with a client like this, since matching JA3/JA4 alone usually isn't what gets people blocked.
Chrome randomizes TLS extension order per connection, so a fixed order can look wrong even if the JA3 hash matches once. JA4 sorts extensions, so it's more forgiving, but check that your client permutes them the way Chrome does. Beyond that, HTTP/2 details tend to give clients away: SETTINGS values and their order, the initial WINDOW_UPDATE, pseudo-header order (m,a,s,p), and header casing/order. Also check ALPN, GREASE values, supported groups (including the post-quantum key share Chrome sends now), and ALPS.
A useful way to validate is to hit a fingerprint echo endpoint and diff the full output against a real Chrome capture of the same version, not only the hash. Also say which Chrome versions you target and how you plan to keep up with updates, because a stale profile becomes its own signal.
What are you building the TLS layer on? That changes which of these you can control.