Introducing JA5: A Stable, Collision-Resistant Successor to JA4
TLS client fingerprinting has become one of the workhorse techniques in network security, and JA4 (FoxIO) has been the de facto standard for identifying TLS clients from their ClientHello messages. But recent production experience at ntop surfaced two real limitations, and today we’re announcing JA5, an open, patent-free extension of JA4 that addresses both. Ephemeral Extensions Break Hash Stability JA4 builds its fingerprint from the full set of TLS extensions a client presents, hashed together with the cipher suite list. The trouble is that not every extension reflects something stable …
