The state of HTTPS fingerprinting in 2025

No ratings

Presented at BlueHat IL 2025 by

As browsers and mobile devices push for privacy-first networking—with encrypted client hello, HTTPS-by-default, and stricter CA policies—it may seem like fingerprinting is a thing of the past. In this talk, we’ll show how TLS fingerprinting still thrives. By analyzing subtle variations in TLS handshakes, servers can still identify browsers, apps, and cryptographic libraries with surprising accuracy.