Two more families of beacon evidence: cross-checks the server runs between what the page reported and what the request said, and the signs that a person is actually there.
| Code | Weight | What it means |
|---|---|---|
platform_mismatch | 35 | The reported platform contradicts the operating system in the User-Agent |
touch_missing_mobile | 30 | A phone or tablet User-Agent on a device with no touch support |
screen_outer_impossible | 25 | The window is larger than the screen it sits on |
dpr_odd | 10 | The device pixel ratio is absent, zero or not a finite number |
tz_mismatch | — | The browser timezone disagrees with the one derived from the address |
tz_unknown | 5 | The browser gave no timezone at all |
The beacon reports the raw measurements and the server does the comparing. Three reasons, and byte count is the least of them: the server holds the authoritative User-Agent read off the connection, and half these checks compare something against the User-Agent, which is precisely the thing we do not trust; a client cannot suppress a comparison it never performs; and thresholds can be tuned server-side without asking every site to redeploy a script tag.
Two conservatism rules apply here. The reverse of the touch check is deliberately not performed, because a desktop User-Agent with touch would flag every touchscreen laptop. And the display checks only run when the payload actually reported a screen size — a truncated write or an older client sends zeroes, and “no data” must never be read as “a window with no size”.
human_mouse_naturalSampled pointer positions vary in a way a straight line cannot explain
mouse_linearNine in ten sampled triples are exactly collinear — what an interpolating driver produces and a hand never does
mouse_staticThe pointer fired move events but never changed pixel
no_interactionZero interactions across the whole session, added server-side because only the server knows the session ended
no_scroll_tall_pageA page half again as tall as the viewport that was never scrolled
beacon_forgedThe payload claimed time that provably did not exist
Mouse positions are sampled at most once per second, up to sixteen points, and the classifier stays silent below six samples: somebody who nudged the mouse twice is not evidence of anything. The coordinates never leave the browser — only the verdict does.
Throughout the beacon, a probe whose interface is missing, blocked or throwing records nothing at all. A false “this human is a bot” is far worse than a missed bot, and every ambiguous case in this codebase is resolved in that direction.
Detection
- The fingerprint cluster
- Automation & headless signals
- Browser claim probes
- Consistency & human evidence