Consistency & human evidence

Server-side cross-checks between the page and the request, and the signs a person is really there.

Two more families of beacon evidence: cross-checks the server runs between what the page reported and what the request said, and the signs that a person is actually there.

01 · Consistency cross-checks, evaluated on the server
CodeWeightWhat it means
platform_mismatch35The reported platform contradicts the operating system in the User-Agent
touch_missing_mobile30A phone or tablet User-Agent on a device with no touch support
screen_outer_impossible25The window is larger than the screen it sits on
dpr_odd10The device pixel ratio is absent, zero or not a finite number
tz_mismatch—The browser timezone disagrees with the one derived from the address
tz_unknown5The browser gave no timezone at all

The beacon reports the raw measurements and the server does the comparing. Three reasons, and byte count is the least of them: the server holds the authoritative User-Agent read off the connection, and half these checks compare something against the User-Agent, which is precisely the thing we do not trust; a client cannot suppress a comparison it never performs; and thresholds can be tuned server-side without asking every site to redeploy a script tag.

Two conservatism rules apply here. The reverse of the touch check is deliberately not performed, because a desktop User-Agent with touch would flag every touchscreen laptop. And the display checks only run when the payload actually reported a screen size — a truncated write or an older client sends zeroes, and “no data” must never be read as “a window with no size”.

02 · Human-presence evidence
human_mouse_natural

Sampled pointer positions vary in a way a straight line cannot explain

Weight
−25
mouse_linear

Nine in ten sampled triples are exactly collinear — what an interpolating driver produces and a hand never does

Weight
40
mouse_static

The pointer fired move events but never changed pixel

Weight
25
no_interaction

Zero interactions across the whole session, added server-side because only the server knows the session ended

Weight
20
no_scroll_tall_page

A page half again as tall as the viewport that was never scrolled

Weight
10
beacon_forged

The payload claimed time that provably did not exist

Weight
90

Mouse positions are sampled at most once per second, up to sixteen points, and the classifier stays silent below six samples: somebody who nudged the mouse twice is not evidence of anything. The coordinates never leave the browser — only the verdict does.

Every “unknown” is recorded as unknown

Throughout the beacon, a probe whose interface is missing, blocked or throwing records nothing at all. A false “this human is a bot” is far worse than a missed bot, and every ambiguous case in this codebase is resolved in that direction.

Detection

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation