Insights
The numbers on the front page say how much was seen. These say what shape it was in — and where the obvious reading of a number is the wrong one.
A real audience is never even
Client populations are power laws. On any domain with real traffic the busiest stack carries far more than its 1/N share — a browser version everyone is on, an SDK every app embeds. So multiply the top stack's share by the number of stacks and organic endpoints land in double digits.
A value near 1 means every stack carried the same load. No audience does that. A roster of profiles being rotated does exactly that.
| domain | stacks | observations | busiest stack | flatness |
|---|
Only domains with at least ten distinct stacks are ranked. Below that the statistic is arithmetic rather than evidence: with five stacks even a thoroughly dominated endpoint scores low, because there is nothing for the load to be uneven across.
One stack, a lot of traffic
The other end of the same axis. Volume behind a single client stack is one operator, not an audience — the corpus cannot say who, but it can say there was only ever one of them.
| domain | observations | stacks |
|---|
What the traffic is made of
Grouped by cipher list, which is a property of the TLS library build and passes through unchanged to everything using it — so one row here covers a whole family of clients. Named from the same catalogue the fingerprint pages use.
| cipher list | known as | observations | share | JA4 rows |
|---|
A high JA4-row count against one cipher list is the collapse above, seen from the other side: many destinations, one client family. An unnamed row is a cipher list the catalogue has not been taught yet, not an unknown client.