<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Peakhour.IO - TLS Fingerprinting</title><link>https://www.peakhour.io/</link><description></description><lastBuildDate>Sun, 06 Sep 2026 09:00:00 +1000</lastBuildDate><item><title>What an Open Network Fingerprint Database Should Publish</title><link>https://www.peakhour.io/blog/open-network-fingerprint-database-schema/</link><description>&lt;p&gt;A useful open fingerprint database needs provenance, competing labels, raw evidence, format versions and licences—not another unexplained hash list.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 06 Sep 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-09-06:/blog/open-network-fingerprint-database-schema/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA4</category><category>Cisco Mercury</category><category>Security Research</category></item><item><title>Public Fingerprint Databases Are Not Ground Truth</title><link>https://www.peakhour.io/blog/public-fingerprint-databases-are-not-ground-truth/</link><description>&lt;p&gt;We reviewed the main public fingerprint resources. The formats are open, but current application labels and auditable ground truth remain scarce.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 30 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-30:/blog/public-fingerprint-databases-are-not-ground-truth/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Threat Intelligence</category></item><item><title>Using Network Fingerprints in Bot and Rate-Limit Decisions</title><link>https://www.peakhour.io/blog/using-network-fingerprints-in-bot-and-rate-limit-decisions/</link><description>&lt;p&gt;A practical way to use network fingerprints for bot and rate-limit decisions without mistaking a shared client cohort for identity.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 23 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-23:/blog/using-network-fingerprints-in-bot-and-rate-limit-decisions/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA4</category><category>Bot Management</category><category>Rate Limiting</category></item><item><title>Does TLS Fingerprint Canonicalisation Hide Attacker Variation? How to Test It</title><link>https://www.peakhour.io/blog/tls-fingerprint-canonicalisation-attacker-variation/</link><description>&lt;p&gt;Sorting makes TLS fingerprints more stable, but it also removes ordering evidence. Here is how to test whether the discarded variation matters.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 16 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-16:/blog/tls-fingerprint-canonicalisation-attacker-variation/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>A Network Fingerprint Is a Cohort, Not a Client</title><link>https://www.peakhour.io/blog/fingerprint-is-a-cohort-not-a-client/</link><description>&lt;p&gt;TLS fingerprints group similar protocol implementations. They do not prove which application, device or person made a request.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 09 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-09:/blog/fingerprint-is-a-cohort-not-a-client/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Bot Management</category></item><item><title>From Joy to Mercury and EVE: Following Cisco's Network Fingerprinting Work</title><link>https://www.peakhour.io/blog/from-joy-to-mercury-and-eve/</link><description>&lt;p&gt;Cisco's open-source collectors, fingerprinting research and Encrypted Visibility Engine form a clear lineage, but they are not interchangeable parts of one public system.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 02 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-02:/blog/from-joy-to-mercury-and-eve/</guid><category>Security</category><category>Cisco Joy</category><category>Cisco Mercury</category><category>Encrypted Visibility Engine</category><category>TLS Fingerprinting</category><category>Network Fingerprinting</category><category>Encrypted Traffic</category></item><item><title>Two Lineages of TLS Fingerprinting: JA3, JA4 and Cisco Mercury</title><link>https://www.peakhour.io/blog/two-lineages-tls-fingerprinting/</link><description>&lt;p&gt;JA4 did not descend from Cisco Mercury. The two projects come from different strands of TLS fingerprinting research and solve different operational problems.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 26 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-26:/blog/two-lineages-tls-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Threat Detection</category></item><item><title>Before JA3: How TLS Handshakes Became Fingerprints</title><link>https://www.peakhour.io/blog/before-ja3-tls-fingerprinting-history/</link><description>&lt;p&gt;JA3 made TLS fingerprints easy to log and share, but the technical ideas behind it had already been tested in SSL Labs experiments, a p0f patch and FingerprinTLS.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 19 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-19:/blog/before-ja3-tls-fingerprinting-history/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>FingerprinTLS</category><category>p0f</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>One ClientHello, Three Fingerprints: JA3, JA4 and Mercury</title><link>https://www.peakhour.io/blog/one-clienthello-ja3-ja4-mercury-lab/</link><description>&lt;p&gt;A reproducible lab runs JA3, JA4 and Cisco Mercury against the same TLS ClientHello and compares what each fingerprint preserves.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 12 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-12:/blog/one-clienthello-ja3-ja4-mercury-lab/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>The Invisibility Cloak</title><link>https://www.peakhour.io/blog/bots-residential-proxies-anti-detect-browsers/</link><description>&lt;p&gt;Learn how attackers combine residential proxies and anti-detect browsers to evade detection and how modern security tools can fight back.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 01 Sep 2025 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-09-01:/blog/bots-residential-proxies-anti-detect-browsers/</guid><category>Security</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>Residential Proxies</category><category>Bot Management</category><category>TLS Fingerprinting</category><category>Credential Stuffing</category></item><item><title>How MTU Fingerprinting Identifies VPNs and Mobile Users</title><link>https://www.peakhour.io/blog/mtu-fingerprinting-vpn-mobile-detection/</link><description>&lt;p&gt;Learn how MTU fingerprinting reveals VPN usage, mobile connections, and network technologies through TCP handshake analysis. Discover practical SQL techniques for dynamic network intelligence.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 15 Jan 2025 14:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-01-15:/blog/mtu-fingerprinting-vpn-mobile-detection/</guid><category>Bots</category><category>Threat Detection</category><category>Fingerprinting</category><category>Networking</category><category>Residential Proxies</category><category>TLS Fingerprinting</category><category>DDoS</category></item><item><title>RFC 9460</title><link>https://www.peakhour.io/blog/rfc-9460-dns-evolution/</link><description>&lt;p&gt;Introducing SVCB and HTTPS records in DNS and their impact on web connectivity.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 16 Nov 2023 00:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-11-16:/blog/rfc-9460-dns-evolution/</guid><category>Interest</category><category>HTTP</category><category>Web Performance</category><category>Rate Limiting</category><category>TLS Fingerprinting</category><category>CDN</category><category>DDoS</category></item><item><title>JA4 and JA4+ Network Fingerprinting</title><link>https://www.peakhour.io/blog/overview-of-ja4-network-fingerprinting/</link><description>&lt;p&gt;How JA4 constructs a TLS client fingerprint, what JA4+ names, and which details sorting and hashing discard.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 25 Oct 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-25:/blog/overview-of-ja4-network-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>Fingerprinting</category><category>Browser Fingerprinting</category><category>TLS</category><category>SOC 2</category><category>Threat Detection</category></item><item><title>Efficiently Generating and Printing All IPv4 Addresses in a Random Order</title><link>https://www.peakhour.io/blog/linear-congruential-generator/</link><description>&lt;p&gt;Explains how to efficiently generate all IPv4 addresses in a random order using a Linear Congruential Generator (LCG), a memory-efficient method for tasks like security testing and network simulation.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 15 May 2023 13:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-05-15:/blog/linear-congruential-generator/</guid><category>Technical</category><category>Residential Proxies</category><category>Networking</category><category>DDoS</category><category>TLS Fingerprinting</category></item><item><title>Chrome's TLS Extension Randomisation Experiment</title><link>https://www.peakhour.io/blog/tls-extension-randomisation/</link><description>&lt;p&gt;Does TLS extension randomisation assist in hiding Chrome?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 02 Feb 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-02-02:/blog/tls-extension-randomisation/</guid><category>Security</category><category>TLS Fingerprinting</category><category>TLS</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>API Security</category></item><item><title>TLS Fingerprinting</title><link>https://www.peakhour.io/blog/tls-fingerprinting/</link><description>&lt;p&gt;What is fingerprinting, and in particular TLS fingerprinting?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 02 Feb 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-02-02:/blog/tls-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>TLS</category><category>HTTP</category><category>DDoS</category></item></channel></rss>