Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Tool suggestion: AntiBrow - keeps each research profile's cookies, fingerprint and proxy separate at the engine level

Aperta
#899 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
48/100
Tipo di issue
Documentazione
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
playwright, python, typescript
Ambito
documentation

Direzione di ricerca

Esamina le pagine degli strumenti esistenti Stay Safe e Data Organization & Analysis, insieme alle pagine degli strumenti già presenti nel repository, per comprenderne la struttura e l’ambito. Conferma se gli strumenti browser o opsec e i kernel closed-source rientrano nel toolkit; il lavoro è completato quando viene registrata una decisione chiara di accept-or-close e, se accettati, viene identificata la sezione appropriata per AntiBrow.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Disclosure: I maintain AntiBrow. Submitting our own tool, and flagging upfront that part of it is not open source (details under Cost and Limitations).

Name: AntiBrow
URL: https://antibrow.com
Docs: https://antibrow.com/docs
Source: https://github.com/antibrow/antibrow (SDK, MIT)
Suggested section: Stay Safe, or Data Organization & Analysis - see the note at the end, I am not sure this fits the toolkit's scope and would rather ask than assume.
Cost: Free tier is unlimited local profiles with one concurrent browser, no account needed to start. Paid tiers price concurrency. The SDK is MIT; the browser kernel it downloads is closed source under separate terms.

What it does

A Chromium fork where a browser profile is a persistent, isolated identity: its cookies, local storage and fingerprint configuration survive between runs, and each profile answers its own proxy inside the engine rather than through an extension or a system-wide setting. Several profiles can be open at once without sharing state.

It can be driven by hand, from TypeScript or Python through the Playwright API, or from a local MCP server when an agent is doing the work.

Why it may be relevant to open source research

Research accounts are documented practice in this field - Bellingcat's own community has written about them, and so have SANS and OSINT Curious. The failure mode is not exotic: an investigator's research identity and personal identity end up sharing a cookie jar, a fingerprint, and a home IP address. The usual mitigations are a separate browser profile (shares the fingerprint and the IP), a separate VM (heavy, and one per identity gets expensive), or a VPN (system-wide, so all identities move together).

What this does instead is bind the isolation to the profile: profile A can sit on a residential exit in one country while profile B is on another, in the same session, with no shared storage between them. Timezone and locale follow the exit rather than the host machine, which is the inconsistency that most often gives a research account away.

Relationship to what the toolkit already lists

I went through the 337 tool pages in this repository and did not find a browser or a profile-isolation tool among them - the nearest material is the Stay Safe resources section, which is guidance rather than tooling. So this is not a duplicate of anything listed, but it may be outside the scope you have drawn on purpose.

Limitations, and what it does not do

  • It does not make any site accept an automated session, and it does not defeat account verification. Platforms that want a phone number still want a phone number.
  • The kernel is closed source. For a toolkit aimed at investigators that is a real limitation and I am not going to argue around it: you can read and audit the SDK, not the engine.
  • Fingerprint control reduces cross-profile correlation; it does not make a profile anonymous. Behaviour and request timing remain identifying, and for adversarial situations Tor Browser's approach - everyone looking identical - is a different and often better threat model than everyone looking distinct.
  • Same category of dual-use as several tools already in the toolkit: the same isolation that keeps an investigator's identities apart can be used to run many accounts on a platform that forbids it. We do not sell it for that and our docs do not teach it, but it would be dishonest to pretend the capability is one-directional.

If this is out of scope

If the toolkit deliberately excludes browsers and opsec tooling, or excludes anything with a closed component, just close this - a no is a useful answer and I would rather have it than a maybe.

Lingua principale
JavaScript
Stelle
652
Fork
113
Merge medio
3h 46m
PR unite (30g)
4

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di bellingcat/toolkit

Tutte le issue di bellingcat/toolkit

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.