How To Know If Ant-Detect Browser is 'Good'?

  • Thread starter Thread starter Deleted member 1734661
  • Start date Start date
D

Deleted member 1734661

Guest
I am currently using several anti-detect browsers but I am not sure how to test if it is good or not. Are there any websites that show some data that can help to see weither or not the anti-detect browsers isolate the instances correctly?
 
This site seems to give quite the information. I will have a look into it, I appreciate the suggestion.
 
Unfortunately, this is outdated and will give bad scores for regular browsers too.

Tests I like to do(will require clean proxy or your own 4G mobile):

- check what pixelscan website has to say
- check if gmail registration page will give PVA or not
- open nordstrom store and see if Shapes backend will let me through
- see if arkose labs(funcaptcha) will be triggered on twitter or tinder
 
Scamalytics is a good place to check if your connection is properly masked, on the other hand Panopticlick be where I would test my anti-detect browsers. Haven't used it again in some time so consider checking it from several different services.
 
- check what pixelscan website has to say
This one gives me "you're masking your fingerprint" even on my regular use firefox browser. CreepJS's scoring is a bit weird but they do check just about everything.
- check if gmail registration page will give PVA or not
Gosh I didn't know it was even possible to make a Gmail without phone verification these days.
 
Unfortunately, this is outdated and will give bad scores for regular browsers too.

Tests I like to do(will require clean proxy or your own 4G mobile):

- check what pixelscan website has to say
- check if gmail registration page will give PVA or not
- open nordstrom store and see if Shapes backend will let me through
- see if arkose labs(funcaptcha) will be triggered on twitter or tinder
What are you using these days or which one you can recommend for mobile usage?

The market is full of different AD providers and I'm starting to think it's the same group of people who are reskinning their product lol.
 
This one gives me "you're masking your fingerprint" even on my regular use firefox browser. CreepJS's scoring is a bit weird but they do check just about everything.
Heh, there should be no "even" in that statement, last few years firefox is more and more going route to protect their users privacy so a lot of stuff that usually you would get by custom extensions or stealth browsers - firefox offers that natively.

Gosh I didn't know it was even possible to make a Gmail without phone verification these days.
Oh yes, for sure it's possible. Clean IP and somewhat acceptable browser fingerprint and you can make gmails for free.

What are you using these days or which one you can recommend for mobile usage?

The market is full of different AD providers and I'm starting to think it's the same group of people who are reskinning their product lol.
Highly depends on your use case, for some only automated real mobile devices will work, for others there is no need for any AD at all.
 
I am currently using several anti-detect browsers but I am not sure how to test if it is good or not. Are there any websites that show some data that can help to see weither or not the anti-detect browsers isolate the instances correctly?

Well, let's rephrase the question in a much different manner so people can understand the current blocking system for bots.
There are generally 4 types of groups in the botting world.

The first group is what we called the vendors, they are the sites getting botted and are usually a mix of airlines, banks, retail sites, government sites, social media sites, etc. You get the point!

The second group is what we called the Anti-Bots, they are the groups in charged of protecting the endpoints and infrastructure of the vendors. They include companies like Akamai, Cloudflare, PerimeterX/Human, Imperva/Incapsula, Datadome, Kasada, ShapeSecurity, Hcaptcha, Recaptcha, Geetest etc. These groups usually deploy a sort of Nginx/Caddy/Apache plugin or SDK, and install their unique Javascript protection on the vendors site.With the exception of Google and a few other huge sites, almost every single site is protected by one of these Anti-Bots.It is also important to notice that I include the captchas companies with the anti-bot companies due to their similarities in functionality as they are there to protect their clients assets from cyber attacks.

The third group is what we called the Bot Tool Makers and they include things like github open-source projects, anti-bot api services by someone from sneaker dev, anti-detect browsers by someone from BHW, and the occasional bot you find on other forums and the open web. These tools are usually delivered through 2 ways, either through a custom build up chromium/firefox buildt into a branded application that is then sold thru various forums cough cough BHW cough cough, or through api services sold thru discord servers that provide the fingerprint/sensor data/ cookies for specific anti-bot apis.

The fourth group is the botters, these are the users that are trying to get something by force from the first group, whether that is publicly available data, automated checkout purchase, or something even more maliciously like account take overs.

This last group usually consists of 3 main people, the people that don't got time to spent bypassing an anti-bot and they have a business that depends on bypassing the people from the second group, the anti-bots, they are willing to throw money at solutions that gets them there. The people with no money to spent that usually come from 3rd world countries with a super low budget , they will usually resort to open-source solutions and then maybe end up paying for the low tier anti-detect browsers. The last person in this group are those that are usually doing massive amounts of web scraping on different web properties and that they are getting blocked by the anti-bots, they are anything from academics to someone with a massive scraping idea.
The problem with the people on the Fourth group is that majority of them are lacking self awareness of how clueless they are on how the people on the second group are blocking their futile attempts to get to the people on the first group. They resort to these open-source sites like retards where they check some imaginary score that makes them believe they are passing some sort of magical gate that will allow them to bot their site successfully.

Not all Anti-Bots are built the same, you have the suckiest ones from DataDome all the way to the gold-standard that is ShapeSecurity, a lot of them are in the middle in terms of difficulty. And there lies the problem, that the majority of the people on the fourth group have zero freaking idea of how these websites are protecting themselves from them. They think that by buying "anti-detect" browsers that they will be unable to get detected by the site's anti-bot measures.

Buying and anti-detect browser and expecting to bypass a site's security is like getting a lawyer and expecting it to be a 100% Get-Out-Of-Jail card. It just doesn't exist, that is a made believe lie that has propagated through many forums. In order to get through a site's honey you must first defeat the anti-bot systems, not change your browser properties a la dumb like a dummy would.
You need to check everything from you http2/tls fingerprint to your Javascript fingerprints for that SPECIFIC antibot. Let me rephrase FOR THAT SPECIFIC ANTIBOT, let me repeat it so it can be ingrained into your tiny brains people from the fourth group.

IN ORDER TO BYPASS A SITE'S PROTECTION YOU NEED TO BYPASS THE SPECIFIC ANTIBOT THAT IS FOUND ON THEIR SITE.
The beauty about this though is that because the web is usually protected by a handful of anti-bot companies, if you find a site that is protected by one anti-bot company and you can bypass that anti-bot, then you can usually bypass the other sites with that anti-bot company.
For example, if you can bypass Nordstrom's then you can also bypass END Clothing, Tiktok, Target, and some other important logins.
 
Unfortunately, this is outdated and will give bad scores for regular browsers too.

Tests I like to do(will require clean proxy or your own 4G mobile):

- check what pixelscan website has to say
- check if gmail registration page will give PVA or not
- open nordstrom store and see if Shapes backend will let me through
- see if arkose labs(funcaptcha) will be triggered on twitter or tinder
The fact that your good browser receives a "bad" score is not a direct indicative of the framework being outdated. In fact, when you see 100% trust-score is mostly sugar milk that anti-detect products will spoon-feed you for marketing purposes - no real browser would achieve 100%.

CreepJS is a debugging framework that serves a purpose. It's made for you to find inconsistencies in your fingerprint, and it does a very good job at doing so. If you can't figure it out, then rely on the percent-score as an indicator.
 
The fact that your good browser receives a "bad" score is not a direct indicative of the framework being outdated. In fact, when you see 100% trust-score is mostly sugar milk that anti-detect products will spoon-feed you for marketing purposes - no real browser would achieve 100%.

CreepJS is a debugging framework that serves a purpose. It's made for you to find inconsistencies in your fingerprint, and it does a very good job at doing so. If you can't figure it out, then rely on the percent-score as an indicator.
I disagree because the score is a measurement. If it's off with something that should be taken as "base" or "standard" for measuring things, then it's outdated and should be calibrated to match the new standard - a clean browser installation where it shouldn't detect any inconsistencies.
 
I disagree because the score is a measurement. If it's off with something that should be taken as "base" or "standard" for measuring things, then it's outdated and should be calibrated to match the new standard - a clean browser installation where it shouldn't detect any inconsistencies.
feel free to share your tool of trust that scores you 100% on your freshly installed copy of Chrome
 
feel free to share your tool of trust that scores you 100% on your freshly installed copy of Chrome
How it's even relevant here? I still use creepjs, just comparing the values with real chrome.
 
The quality of Ant-Detect Browser can be assessed through several factors. 1. Reliability 2. Compatibility

3. Updates and Maintenance 4. Performance 5. Security and Privacy
 
The fact that your good browser receives a "bad" score is not a direct indicative of the framework being outdated. In fact, when you see 100% trust-score is mostly sugar milk that anti-detect products will spoon-feed you for marketing purposes - no real browser would achieve 100%.

CreepJS is a debugging framework that serves a purpose. It's made for you to find inconsistencies in your fingerprint, and it does a very good job at doing so. If you can't figure it out, then rely on the percent-score as an indicator.
What is the point of CreepJS?

No antibot company that block bots uses CreepJS as a reference point of what are "good" or "bad" fingerprints.

Everybody who uses CreepJS as a reference has never ever seen what antibot scripts are fingerprinting, they have zero clue, because they either lack the expertise to deobfuscate their scripts or are too lazy.

CreepJS is next to useless in my opinion, as someone who has reversed a handful of antibots, I can tell you that I have seen not even 1/10th of the things CreepJS checks for in the actual antibot scripts. I can assure you Shape does not even use any of those things. So @exec , if you are using anti-detect browsers then I don't think you would have the expertise to know what actual fingerprints are being used on the actual anti-bot scripts.
 
Back
Top