Skip to content

Comment on Curl-Impersonateparent

Comments

It could be that the TCP streams are the same, but packetiation is different.

It could mean that the packets are the same, but timing is off by a few milliseconds.

It could mean a single HTTP request exactly matches, but when doing two requests the real browser uses a connection pool but curl doesn't. Or uses HTTP/3's fast-open abilities, etc.

etc.

Two TLS streams are never byte-identical, due to randomness inherent to the protocol.

Identical here means having the same fingerprint - i.e. you could not write a function to reliably distinguish traffic from one or the other implementation (and if you can then that's a bug).

It replicates the browser at the HTTP/SSL level, not TCP. From what I know this is good enough to bypass cloudflare's bot detection.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.