12/12/2025 at 8:25:26 PM
> The default TLS Client Hello has been modified. If your app or website communicates with servers configured with strict bot-detection or security policies that only allow traffic with known TLS fingerprints, then users might be unable to login or perform other actions.Wonder if that's what they do on their own services? Seems a little odd they'd have an outage a few days before release and then this shows up in their release notes.
by joecool1029
12/12/2025 at 10:45:13 PM
This has been in the developer release notes since the first 26.2 beta so I doubt it’s related.by krelas
12/12/2025 at 8:38:58 PM
I hope they randomize it in the future like they do it for mac addresses.by kasabali
12/12/2025 at 11:07:19 PM
GREASE already randomizes the handshake to an extent, and I think whatever TLS stack chrome uses also shuffles the cipher order. In response newer TLS fingerprinting algorithms (ja4?) sort the cipher list first to mitigate this.by gruez