tls-reputation.comTLS fingerprint reputation

auth surface

auth.uber.com

Credential-stuffing shape

Many unrelated client stacks reach this auth endpoint in near-equal proportion — the credential-stuffing shape. The corpus records no per-connection identity and cannot confirm intent.

auth13 clients108 obs2026-07-19 → 2026-07-23
domain

explore in graph →

Read

client diversity
13 distinct client stacks reach this name.
concentration
0.656 traffic splits near-evenly across many unrelated stacks.
category
Looks like an auth endpoint — a hostname heuristic, high-precision / low-recall, not a verdict.
synthesis
Many unrelated stacks reaching an auth endpoint in near-equal proportion is the credential-stuffing shape. The corpus records no per-connection identity and cannot confirm intent.

Spread is entropy over the fingerprints reaching this domain, not over the domains a fingerprint reaches. It can’t distinguish one scraper from many people — it measures the mix of software, not who runs it.

Footprint

108
observations
13
distinct clients
2026-07-19
first seen
2026-07-23
last seen

Client stacks reaching this name

Busiest 13 client stacks on this page. Share is the fraction of this name’s observations. Many distinct fingerprints on a low-traffic name is itself worth a look; a blank JA3 is a permuting client — open the fingerprint for its variants.

clientJA3stabilitycountsharefirst seenlast seen
Google Chrome / Chromium
Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version
randomising5349%2026-07-192026-07-23
Google Chrome / Chromium
Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version
randomising1716%2026-07-202026-07-23
t13d2812h2_257f3…361b6bf9multi-build1413%2026-07-202026-07-20
Google Chrome / Chromium
Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version
multi-build76.5%2026-07-202026-07-20
Android (Conscrypt) / Flutter (BoringSSL)
mobile-BoringSSL cipher-suite signature — Android system TLS (Play Services, Firebase, OkHttp apps) and Flutter/Dart; any ALPN
multi-build54.6%2026-07-192026-07-20
Apple Safari / WebKit
Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated
multi-build32.8%2026-07-192026-07-20
Apple Safari / WebKit
Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated
multi-build32.8%2026-07-202026-07-20
Apple Safari / WebKit
Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated
multi-build10.9%2026-07-202026-07-20
Google Chrome / Chromium
Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version
0faf2a91…fca2fdfixed10.9%2026-07-202026-07-20
Android (Conscrypt) / Flutter (BoringSSL)
mobile-BoringSSL cipher-suite signature — Android system TLS (Play Services, Firebase, OkHttp apps) and Flutter/Dart; any ALPN
randomising10.9%2026-07-202026-07-20
Apple Safari / WebKit
Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated
66182318…3a0307fixed10.9%2026-07-202026-07-20
t13d2713h2_bd979…401ec68bc914b1b0…2103f5fixed10.9%2026-07-232026-07-23
Google Chrome / Chromium
Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version
randomising10.9%2026-07-202026-07-20