JA4, TLS and CC defense: fingerprints are signals, not identity

Combine TLS fingerprints with behavior while treating certificate validation as a separate control.

Contents of this article

Fingerprints describe connection characteristics

JA4 groups TLS clients by connection characteristics. Shared software can share a fingerprint, and client changes can alter observations. Use it with behavior signals, not as a verified identity or a verdict on a request.

Handle missing and shared signals

For products supporting fingerprints, confirm field availability and missing-value behavior. Review samples and correlate paths, rates, success and sessions before enforcement. A broad fingerprint rule may affect many legitimate users.

Encryption does not authorize behavior

TLS protects transport and validates endpoints through mechanisms including certificates. It does not determine object permissions or resource abuse. Fingerprint rules also do not fix expired certificates or incorrect origin validation. Test these controls separately.

Validate the capabilities you deploy

Confirm TLS, JA4 and policy capabilities for the selected plan rather than importing another vendor’s field names. Test browsers, apps, WebSocket and APIs, preserving rule rollback and certificate-renewal checks.

References

Cloudflare JA3/JA4 documentation

IETF TLS 1.3

Continue reading

Read related content

Back to industry insights Contact technical support