<?xml version="1.0" encoding="utf-8" ?><rss version="2.0" xmlns:tt="http://teletype.in/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>@exitanty</title><generator>teletype.in</generator><description><![CDATA[@exitanty]]></description><link>https://teletype.in/@exitanty?utm_source=teletype&amp;utm_medium=feed_rss&amp;utm_campaign=exitanty</link><atom:link rel="self" type="application/rss+xml" href="https://teletype.in/rss/exitanty?offset=0"></atom:link><atom:link rel="next" type="application/rss+xml" href="https://teletype.in/rss/exitanty?offset=10"></atom:link><atom:link rel="search" type="application/opensearchdescription+xml" title="Teletype" href="https://teletype.in/opensearch.xml"></atom:link><pubDate>Sat, 10 Oct 2026 11:54:34 GMT</pubDate><lastBuildDate>Sat, 10 Oct 2026 11:54:34 GMT</lastBuildDate><item><guid isPermaLink="true">https://teletype.in/@exitanty/hFRY--o0tbR</guid><link>https://teletype.in/@exitanty/hFRY--o0tbR?utm_source=teletype&amp;utm_medium=feed_rss&amp;utm_campaign=exitanty</link><comments>https://teletype.in/@exitanty/hFRY--o0tbR?utm_source=teletype&amp;utm_medium=feed_rss&amp;utm_campaign=exitanty#comments</comments><dc:creator>exitanty</dc:creator><title>New Fingerprint System</title><pubDate>Tue, 14 Apr 2026 09:41:53 GMT</pubDate><media:content medium="image" url="https://img1.teletype.in/files/81/e5/81e5cfe9-9143-40b8-87c4-3e0f919222ce.png"></media:content><description><![CDATA[<img src="https://img4.teletype.in/files/31/3d/313d7e5f-67a5-4b30-9daa-707f09d488ba.png"></img>Hi, this is the ExitAnty team.]]></description><content:encoded><![CDATA[
  <p id="1bLL"><strong>Hi, this is the ExitAnty team.</strong></p>
  <p id="Gtqx">We&#x27;d like to introduce the updated Fingerprint system in our application. In this release, we&#x27;ve reworked our previous approaches, improved the stability of parameter spoofing, and resolved the key desynchronizations that caused checkers like CreepJS to flag profiles as suspicious. The main issues we tackled first were related to Canvas and Workers.</p>
  <hr />
  <p id="j9Ay"><strong>Canvas</strong></p>
  <p id="Z3kR">Canvas is a browser technology used to render graphics, text, shadows, lines, and other visual elements via JavaScript.</p>
  <p id="PyDZ">For anti-fraud systems, Canvas matters not as a display tool, but as a source of device fingerprinting. Different operating systems, graphics chips, drivers, fonts, and rendering quirks can produce slightly different outputs even from identical code — and that output is what forms the canvas fingerprint.</p>
  <p id="fY0a">This is precisely why any instability in Canvas is quickly noticed. If the rendering result differs between environments or behaves unpredictably, a checker interprets this as a sign of spoofing.</p>
  <hr />
  <p id="8jpK"><strong>Workers</strong></p>
  <p id="KVFj">Workers are background browser contexts in which JavaScript runs separately from the main page. They exist to enable parallel processing without burdening the UI — but from an anti-fraud perspective, they&#x27;re also an independent fingerprinting zone.</p>
  <p id="hXO8">Modern checkers compare values collected from the main window, a Dedicated Worker, and a Shared Worker. If Canvas, GPU, language, timezone, or other parameters diverge across these environments, it looks like unnatural browser behavior and increases the risk of detection.</p>
  <hr />
  <p id="vfEQ"><strong>Why Service Workers are unavailable in our product</strong></p>
  <p id="2UP2">Service Workers deserve a separate note.</p>
  <p id="fNNB">We chose not to enable them just to tick a box on checker reports. In practice, activating them can lead to browser instability, session merging, and additional detection vectors. In our observation, this is exactly where some competing solutions run into problems — which we&#x27;ll return to below.</p>
  <p id="vVym">Our priority is not a &quot;pretty checkmark&quot; on a test, but genuine stability and session isolation.</p>
  <hr />
  <p id="hUwY"><strong>ExitAnty behavior on CreepJS</strong></p>
  <p id="jO7q">For testing, we used a session launched on an iPhone 15 Pro running iOS 26.2 with the following settings:</p>
  <ul id="CRZR">
    <li id="YJci">iOS 26.0</li>
    <li id="D2ju">Screen Resolution: 390×844</li>
    <li id="URMQ">Canvas: Noise</li>
    <li id="av5V">WebGL: Real</li>
  </ul>
  <p id="VLiU"><strong>ExitAnty test results</strong></p>
  <figure id="tS4l" class="m_retina">
    <img src="https://img1.teletype.in/files/0f/85/0f8541eb-c7cb-46ce-8929-2d82933e3244.png" width="1180" />
  </figure>
  <figure id="6ZKd" class="m_retina">
    <img src="https://img3.teletype.in/files/a5/56/a55661e3-122a-4f18-a020-d906e1cd06f1.png" width="590" />
  </figure>
  <hr />
  <p id="AXNk"><strong>Behavior of a similar solution on CreepJS</strong></p>
  <p id="KKx1">The results of testing the competing solution are shown in the video. The session was launched on an iPhone 15 Pro running iOS 26.2 with similar settings:</p>
  <p id="QnpS">UA: iOS 26.2<br />Screen Resolution: 390×844<br />Canvas: Noise<br />WebGL: Real</p>
  <figure id="RyYS" class="m_original">
    <img src="https://img4.teletype.in/files/77/42/77421346-9c0b-4014-868c-255df6fd3af8.png" width="2360" />
  </figure>
  <figure id="aLcA" class="m_original">
    <img src="https://img4.teletype.in/files/3b/b4/3bb40883-b075-4633-9cf7-9d9f8fbad805.png" width="2360" />
  </figure>
  <p id="I0RY">At first glance, the results of ExitAnty and the other solution may seem similar. However, even in the basic tests it is clear that with Canvas Noise enabled, the alternative solution gets a lied status for Canvas, while Service Workers remain available. This points to low-quality Canvas noise implementation in the competing solution.</p>
  <p id="D35t">Moreover, during testing we saw signs of domain-dependent behavior: on certain addresses, such as abrahamjuliot.github.io (CreepJS), Worker values suddenly become “ideal,” whereas if you deploy the exact same checker on your own domain, the picture changes. The video clearly shows that the fingerprint language differs on the same checker when deployed on different domains.<br /><a href="https://youtube.com/shorts/elDuoSjsAz8" target="_blank">Video with iPhone →</a></p>
  <hr />
  <p id="VSe4"><strong>Behavior of the competing solution on CreepJS on another domain</strong></p>
  <p id="xmIX">To confirm the domain dependency of the competing solution, we also ran tests on a MacBook. Another device immediately exposed not only the imitation of fingerprint language parameters, but a whole range of other ones as well. <a href="https://youtu.be/FJr1ebw25Ks" target="_blank">Watch the video →</a></p>
  <p id="9Wxm">That is where the differences became much more obvious. The testing indicates that the competing solution substitutes a certain set of parameters depending on the domain, but in reality the checker, just like real anti-fraud systems, still detects fingerprint mismatches. It is hard to call this anything other than misleading users, but we’ll let you judge for yourselves.</p>
  <p id="n1QH">Instructions for deploying CreepJS on your own domain are below.</p>
  <hr />
  <p id="YXow"><strong>Conclusion</strong></p>
  <p id="j0wd">The new ExitAnty Fingerprint system is built not around impressive results on a single public checker, but around the consistency of the entire environment: window, Canvas, Workers, WebGL, and other critical parameters.</p>
  <p id="naR6">Our goal is not simply to pass a test — it&#x27;s to deliver stable, predictable protection under real-world conditions.</p>
  <p id="x2Yd">To celebrate this update, we&#x27;re giving you <strong>50% off all plans</strong> through the end of the month with promo code: <strong>BIRD50</strong></p>
  <hr />
  <ul id="apbI">
    <li id="Ioeo"><a href="https://github.com/ExitAnty/DeployCreepJS" target="_blank">Deploy your own CreepJS →</a></li>
    <li id="2qtR"><a href="https://github.com/abrahamjuliot/creepjs" target="_blank">CreepJS source →</a></li>
    <li id="qfiC"><a href="http://testcreptest.cfd" target="_blank">CreepJS on an alternate domain →</a></li>
  </ul>

]]></content:encoded></item><item><guid isPermaLink="true">https://teletype.in/@exitanty/MQkdQI3W1MM</guid><link>https://teletype.in/@exitanty/MQkdQI3W1MM?utm_source=teletype&amp;utm_medium=feed_rss&amp;utm_campaign=exitanty</link><comments>https://teletype.in/@exitanty/MQkdQI3W1MM?utm_source=teletype&amp;utm_medium=feed_rss&amp;utm_campaign=exitanty#comments</comments><dc:creator>exitanty</dc:creator><title>Новая Fingerprint-система ExitAnty</title><pubDate>Tue, 14 Apr 2026 08:43:17 GMT</pubDate><media:content medium="image" url="https://img4.teletype.in/files/b8/7d/b87db673-3972-45a8-99be-60c1989bbd73.png"></media:content><description><![CDATA[<img src="https://img1.teletype.in/files/0f/85/0f8541eb-c7cb-46ce-8929-2d82933e3244.png"></img>Привет, это команда ExitAnty.]]></description><content:encoded><![CDATA[
  <p id="fB8v"><strong>Привет, это команда ExitAnty.</strong></p>
  <p id="VLBo">Мы хотим представить обновлённую Fingerprint систему в нашем приложении. В этой версии мы переработали прежние подходы, повысили стабильность подмен и устранили ключевые рассинхроны, из-за которых чекеры вроде CreepJS могли помечать профиль как подозрительный. Основные проблемы, над которыми мы работали в первую очередь, были связаны с Canvas и Workers.</p>
  <hr />
  <p id="TV7Z"><strong>Canvas</strong></p>
  <p id="pe9a">Canvas — это браузерная технология для отрисовки графики, текста, теней, линий и других визуальных элементов через JavaScript.</p>
  <p id="t3pv">Для антифрод-систем Canvas важен не как инструмент отображения, а как источник отпечатка устройства. Разные операционные системы, графические чипы, драйверы, шрифты и особенности рендеринга могут давать немного разный результат даже при одинаковом коде. На основе этого результата формируется canvas fingerprint.</p>
  <p id="WcYn">Именно поэтому любые нестабильности в Canvas быстро становятся заметны. Если результат отрисовки отличается между средами или ведёт себя непредсказуемо, чекер воспринимает это как след подмены.</p>
  <hr />
  <p id="DDAN"><strong>Workers</strong></p>
  <p id="WAHE">Workers — это фоновые контексты браузера, в которых JavaScript выполняется отдельно от основной страницы. Они нужны для параллельной работы без нагрузки на интерфейс, но с точки зрения антифрод-проверок это ещё и отдельная зона сбора fingerprint.</p>
  <p id="fWFf">Современные чекеры сравнивают значения, полученные в основном окне (window), Dedicated Worker и Shared Worker. Если между этими средами расходятся Canvas, GPU, язык, таймзона или другие параметры, это выглядит как неестественное поведение браузера и повышает риск детекта.</p>
  <hr />
  <p id="JxlB"><strong>Почему у нас недоступны Service Workers</strong></p>
  <p id="Sv7j">Отдельно стоит прокомментировать Service Workers.</p>
  <p id="ha1u">Мы не стали включать их только ради формального совпадения по чекерам. На практике их активация может приводить к нестабильной работе браузера, склеиванию сессий и дополнительным точкам детекта. По нашим наблюдениям, именно в таких местах у некоторых решений и возникают проблемы, к которым мы ещё вернёмся ниже.</p>
  <p id="Abnj">Для нас приоритетом является не «красивая галочка» в тесте, а реальная стабильность и изоляция сессии.</p>
  <hr />
  <p id="3sqI">Изначально мы не хотели переводить этот вопрос в публичную плоскость. Однако в поддержку и в чат регулярно поступали вопросы о продукте-копии, представители которого при этом позволяли себе некорректные комментарии в наш адрес. Поэтому мы решили показать сравнение на практике.</p>
  <p id="0NoM"><strong>Поведение ExitAnty на CreepJs</strong></p>
  <p id="GzUJ">Для проверки мы использовали сессию запущенную на iPhone 15 pro iOS 26.2 с такими настройками:</p>
  <blockquote id="6LQK">UA iOS 26.0</blockquote>
  <blockquote id="KY53">Screen Resolution: 390×844</blockquote>
  <blockquote id="A9Mp">Canvas: Noise</blockquote>
  <blockquote id="txHG">WebGL: Real</blockquote>
  <hr />
  <p id="jJH9"><strong>Результаты теста ExitAnty</strong></p>
  <figure id="X5Ox" class="m_retina">
    <img src="https://img1.teletype.in/files/0f/85/0f8541eb-c7cb-46ce-8929-2d82933e3244.png" width="1180" />
  </figure>
  <figure id="Ob3z" class="m_retina">
    <img src="https://img3.teletype.in/files/a5/56/a55661e3-122a-4f18-a020-d906e1cd06f1.png" width="590" />
  </figure>
  <p id="roMq"><strong>Поведение аналогичного решения на creepJs</strong></p>
  <p id="PXyF">Результаты тестирования решения-аналога на видео. Сессия была запущена на iPhone 15 Pro iOS 26.2 с аналогичными настройками:</p>
  <p id="SdqH">UA iOS 26.2</p>
  <p id="Vbz4">Screen Resolution: 390×844</p>
  <p id="g3VV">Canvas: Noise</p>
  <p id="823v">WebGL: Real</p>
  <figure id="hDjI" class="m_retina">
    <img src="https://img4.teletype.in/files/77/42/77421346-9c0b-4014-868c-255df6fd3af8.png" width="1180" />
  </figure>
  <figure id="Y3Nj" class="m_retina">
    <img src="https://img4.teletype.in/files/3b/b4/3bb40883-b075-4633-9cf7-9d9f8fbad805.png" width="1180" />
  </figure>
  <p id="tMMl">На первый взгляд результаты ExitAnty и другого решения могут казаться похожими. Однако уже в базовых тестах видно, что при включённом Canvas Noise у альтернативного решения Canvas получает статус lied, а Service Workers при этом доступны. Это указывает на некачественное зашумление Canvas у решения-аналога.</p>
  <p id="rghq">Более того, в ходе тестов мы увидели признаки доменно-зависимого поведения: на определённых адресах — таких как abrahamjuliot.github.io (creepjs) — значения в Workers внезапно становятся «идеальными», тогда как если развернуть тот же самый чекер на собственном домене картина уже отличается. На видео отчетливо видно что язык отпечатка отличается на одном и том же чекере развернутом на разных доменах.<br /><a href="https://youtube.com/shorts/elDuoSjsAz8" target="_blank">Видео с iPhone →</a></p>
  <p id="2S0A"></p>
  <hr />
  <p id="gGEg"><strong>Поведение аналогичного решения на CreepJs на другом домене</strong></p>
  <p id="yNQL">Чтобы удостовериться в доменной зависимости аналогичного решения были проведены тесты на MacBook. Другое устройство сразу вскрыло не только имитацию языковых параметров отпечатка, но и целый набор остальных.  <a href="https://www.youtube.com/watch?v=FJr1ebw25Ks" target="_blank">Смотреть видео →</a></p>
  <p id="kcVP">Именно после этого различия стали заметны гораздо яснее. Тестирование указывает на то, что решение-аналог подставляет определенный набор параметров по домену, но в реальности чекер (как и настоящие антифрод-системы) детектит несовпадения в отпечатке. Трудно назвать это иначе как обманом пользователей — но судить вам.</p>
  <p id="sJHI">Инструкция по развертыванию СreepJs на собственном домене ниже.</p>
  <hr />
  <p id="9IUb"><strong>Вывод</strong></p>
  <p id="7U9g">Новая Fingerprint система ExitAnty строится не вокруг показательных результатов на одном публичном чекере, а вокруг согласованности всей среды: window, Canvas, Workers, WebGL и других критичных параметров.</p>
  <p id="Lr6J">Наша задача — не просто пройти тест, а обеспечить стабильную и предсказуемую защиту в реальных условиях использования.</p>
  <p id="raU9">В честь обновления дарим промокод на <strong>скидку 50% на все планы</strong> до конца месяца: <strong>BIRD50</strong></p>
  <hr />
  <ul id="5S00">
    <li id="rljT"><a href="https://github.com/ExitAnty/DeployCreepJS" target="_blank">Деплой своего CreepJS →</a></li>
    <li id="jIDZ"><a href="https://github.com/abrahamjuliot/creepjs" target="_blank">Сам CreepJS →</a></li>
    <li id="c8MX"><a href="http://testcreptest.cfd" target="_blank">CreepJS на другом домене →</a></li>
  </ul>

]]></content:encoded></item></channel></rss>