JBrowser Source Docs
You are reading the documentation for JBrowser 1.4.0. The newest release is 1.5.4. Go to the latest documentation

Fingerprinting and bot checks

Two goals pull in opposite directions. Fingerprinting protection wants the browser to look different on every site, so sites can't recognise the user. Bot checks (Google's "unusual traffic" page, Cloudflare's "Checking your browser", reCAPTCHA, hCaptcha) look precisely for browsers that don't look like ordinary Chrome, because automation tools are the ones that change things.

What this version changes#

fingerprint_js() (engine/js.py), installed as jb:fingerprint in the page's main world when privacy.fingerprint_protection is on:

  • per-site, per-session noise in canvas read-backs (getImageData, toDataURL, toBlob);
  • a generic WebGL vendor and renderer ("Google Inc.", "ANGLE (Generic Renderer)");
  • 4 CPU cores (navigator.hardwareConcurrency) and 8 GB of memory (navigator.deviceMemory).

GPC_JS and DNT_JS set navigator.globalPrivacyControl and navigator.doNotTrack. Sites on the allowed list are skipped.

Known issue

Bot checks detect these main-world changes: the patched functions don't report [native code], and workers see the real CPU and memory values while the page sees the fake ones. Google and Cloudflare then show CAPTCHAs far more often. 1.5.0 keeps only the (masked) canvas noise, adds a Chrome-like Accept-Language header and exempts sign-in and bot-check sites.