Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And, indeed, even if it wasn't, you could always do your malicious scraping et al using regular Chrome with a remote-control extension or OS Accessibility API-based automation. It's kind of pointless to detect headless browsers specifically, if you'll still have the same problems from automated headed browsers.

Still, I agree that if people are going to try detecting headless Chrome, Chrome should strive to thwart that. The attacks in the OP seem like low-hanging fruit; I was expecting something more akin to timing attacks on how long Ready events take to fire given delays from actual rendering. Writing the code to imitate that would be a fun week.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: