In HTTP/2 and HTTP/3, the server may ask the browser to send highly identifying details about its properties, aka high-entropy client hints. This may be used as a stealthy way to fingerprint and track browsers since this traffic is not displayed in the DevTools Network interface. The goal of this research will be to collect and analyze HTTP/2 and HTTP/3 client hint collection attempts while crawling a large number of popular websites.
If you are interested in this topic, please send an email to Gunes Acar via g.acar@cs.ru.nl .