Two Lineages of TLS Fingerprinting: JA3, JA4 and Cisco Mercury
JA4 did not descend from Cisco Mercury. The two projects come from different strands of TLS fingerprinting research and solve different operational problems.
Tag
Related Peakhour notes, analysis, and field guidance.
JA4 did not descend from Cisco Mercury. The two projects come from different strands of TLS fingerprinting research and solve different operational problems.
JA3 made TLS fingerprints easy to log and share, but the technical ideas behind it had already been tested in SSL Labs experiments, a p0f patch and FingerprinTLS.
TLS fingerprints group similar protocol implementations. They do not prove which application, device or person made a request.
Cisco's open-source collectors, fingerprinting research and Encrypted Visibility Engine form a clear lineage, but they are not interchangeable parts of one public system.
A useful open fingerprint database needs provenance, competing labels, raw evidence, format versions and licences—not another unexplained hash list.
We reviewed the main public fingerprint resources. The formats are open, but current application labels and auditable ground truth remain scarce.
Sorting makes TLS fingerprints more stable, but it also removes ordering evidence. Here is how to test whether the discarded variation matters.
A practical way to use network fingerprints for bot and rate-limit decisions without mistaking a shared client cohort for identity.
A reproducible lab runs JA3, JA4 and Cisco Mercury against the same TLS ClientHello and compares what each fingerprint preserves.
Learn how attackers combine residential proxies and anti-detect browsers to evade detection and how modern security tools can fight back.
Infer an apparent path MTU from TCP handshake data, compare it with common tunnel overheads and use it as one bounded network-path signal.
Introducing SVCB and HTTPS records in DNS and their impact on web connectivity.
How JA4 constructs a TLS client fingerprint, what JA4+ names, and which details sorting and hashing discard.
Explains how to efficiently generate all IPv4 addresses in a random order using a Linear Congruential Generator (LCG), a memory-efficient method for tasks like security testing and network simulation.
Does TLS extension randomisation assist in hiding Chrome?
What is fingerprinting, and in particular TLS fingerprinting?
© PEAKHOUR.IO PTY LTD 2026 ABN 76 619 930 826 All rights reserved.