Alex Spring

149 posts

Alex Spring banner
Alex Spring

Alex Spring

@_alexspring

Founder: @driverdotdev Prev: 2x exits in web infra

Katılım Temmuz 2023
147 Takip Edilen689 Takipçiler
Alex Spring
Alex Spring@_alexspring·
@0x1_0xyd3 I think we're still early on seeing antibots in prod requiring key attestation. It has been mocked up by some, but Google seems to be one of the first indicating things are moving this direction. I'd say 6-12 months before others start implementing variations.
English
0
0
1
96
Per0x1d3
Per0x1d3@0x1_0xyd3·
@_alexspring any antibots which are checking real hardware key ?? I only know about google as it checks during creating a account as it requires a real phone for account creation.
English
1
0
1
165
Alex Spring
Alex Spring@_alexspring·
Scraping the web is about to require buying phones. Antibots want to know if it's a real device, not a real browser. Google's recaptcha QR code is the canary. Patched chromium dies. No more web agents, no more automation. The next moat is real phones and arm servers.
Alex Spring tweet media
English
5
0
25
9.5K
Lakshman Turlapati
Lakshman Turlapati@parzival1213·
@_alexspring Agree. Browser agents win when they use a normal user Chrome profile, not patched headless Chromium. Auth state, visible proof, approvals, and cleanup matter as much as the model. That is the layer FSB is built around github.com/LakshmanTurlap…
English
1
0
4
493
Alex Spring
Alex Spring@_alexspring·
This $200 Android box has better stealth than any browser infra provider. Don’t pay a browser service $500/mo to fake hardware on EC2 instances.
Alex Spring tweet media
English
3
0
16
1.2K
Kory Mathewson
Kory Mathewson@korymath·
i'm looking for great founders and early stage companies across canada. who should I talk to in montreal, toronto, waterloo and east, edmonton, calgary, vancouver and west?
English
81
5
138
12.8K
Alex Spring
Alex Spring@_alexspring·
@N104AP Good to know, thanks for sharing. What site are you reproducing the on? It's still early rollout. Wouldn't surprise me if Play Integrity integrated in future.
English
1
0
3
228
Ellie Winters
Ellie Winters@N104AP·
felt inclined to share play integrity doesnt matter, my device runs gms but isnt play certified in the slightest, only achieving basic integrity still really shitty though
Ellie Winters tweet mediaEllie Winters tweet mediaEllie Winters tweet media
Alex Spring@_alexspring

@ArieWindmill I've seen discussions mentioning it on archive.today, but I haven't been able to reproduce yet. That QR code on the image is valid as well.

English
3
1
35
2.1K
Alex Spring
Alex Spring@_alexspring·
Google's next evolution of reCAPTCHA is QR codes. An effort to block web infra companies. It will be interesting to see if they tie in Play Integrity.
Alex Spring tweet media
English
46
6
156
215.4K
Robin Blix
Robin Blix@robin_blix·
@_alexspring How would a captcha help with that? Just enable 3-D secure or whatever the credit card company calls it when you have to login to verify your transaction
English
1
0
8
206
Robin Blix
Robin Blix@robin_blix·
@_alexspring A shopping site is a weird example pick because why would they care if I'm human during checkout? The verification method is payment
English
1
0
5
1.3K
Alex Spring
Alex Spring@_alexspring·
@ArieWindmill I've seen discussions mentioning it on archive.today, but I haven't been able to reproduce yet. That QR code on the image is valid as well.
English
2
0
2
3.1K
Alex Spring
Alex Spring@_alexspring·
@strajk_ It's likely backed by Play Integrity. Meaning you'll need an Android device with Google certified attestation keys.
English
2
1
30
3.1K
strajk-
strajk-@strajk_·
@_alexspring What happens after scanning the code? Because parsing that is way easier than solving a captcha. I can shit out a browser extension in 5 minutes that does that for me with easy. There has to be something like a secondary captcha or device informations that get uploaded to verify
English
2
0
36
4.6K
Jaws
Jaws@jawschamp·
@_alexspring Does it successfully deal with the QR code
English
1
0
2
97
Josh Pigford
Josh Pigford@Shpigford·
okay, what's the secret to getting browser automation to work on hermes that doesn't constantly get tripped up by fancy javascript forms and/or anti-bot tooling? i've tried @browserbase (with residential proxy) to no consistent effect. (hermes is on a mac mini, fwiw)
English
18
1
22
7K
Alex Spring
Alex Spring@_alexspring·
Browser automation has a GPU fingerprint problem. Pre-baked canvas pixels are duct tape. GPU-over-IP fixes it at the layer below. Real rendered pixels. One company nailed it. HP just acquired them, so good luck to all 🫡
Alex Spring tweet media
English
1
1
11
1K
Alex Spring
Alex Spring@_alexspring·
Your "stealth" browser fakes a GPU and it gets detected by pixels. Antibot scripts draw test scenes through WebGL and Canvas APIs, then read back the pixel output. They're checking the rendered pixels, not your spoofed renderer string. Fake GPU = SwiftShader. String says NVIDIA. But pixels say software. Detected. GPU-over-IP forwards calls from a CPU-only machine to a real GPU over TCP. Real hardware, real pixels. You can fake the string. You can't fake the pixels.
Alex Spring tweet media
English
10
12
168
15K
Alex Spring
Alex Spring@_alexspring·
At driver.dev we build and run our own hardware. Not replayed fingerprints sourced from sketchy vendors. If you want a cabinet like our shoot me a msg
Alex Spring tweet mediaAlex Spring tweet media
English
0
0
2
285
Alex Spring
Alex Spring@_alexspring·
Your device fingerprint is being sold to browser providers. You visit a normal website. Nothing shady. Hidden “stealth” scripts quietly collect your Canvas, WebGL, fonts, and hardware profile. Browser companies purchase access behind closed doors. $5 per 1,000 prints. They replay your exact fingerprint and sell it as infrastructure. It passes antibot checks because it came from a real device. The fix: defenses need to assume replay.
Alex Spring tweet media
English
2
0
7
481