The September 23 backlog now has an implementation or a bounded experiment for every listed hypothesis. Optional collectors are off by default. The collection guide explains the contract, configuration, primary sources and limits. No new signal has been promoted as a validated detector of a person, assistant brand or attacker.
| Hypothesis | Current implementation | Evidence still needed |
|---|---|---|
| Local/device fonts | Twelve fixed local-only font probes; versioned availability set; optional Jaccard identity weight and Jev context | Multi-device, longitudinal, privacy-browser and collision studies; fonts are not people |
| Downloaded page fonts | Bounded loaded/loading/failed counts; no names or URLs | Separate normal network/policy failures from any useful anomaly |
| Runtime globals | Eight fixed descriptor checks and own-webdriver flag; no getter execution | Modern versions, ordinary extensions, DevTools and assistive software controls |
| CDP timing | Benchmark-only bounded descriptor timing, instrumented browsers and a separately launched no-CDP control | Broader controlled study: sampled markers absent in both controls and timing overlaps; no timing detector is shipped |
| Permission consistency | Bounded read-only Notifications state queries | Browser/private/enterprise policy baselines; no permission requests |
| Cursor steps and alignment | Existing movement aggregates plus opt-in target-relative counters | Human, touch, keyboard, remote desktop and assistive input holdouts |
| Interaction timing | Existing mean/variance, short/repeated-gap summaries and sample support | Broader tasks and human baselines; no raw keys or per-event timing trails |
| Screenshot/focus hypothesis | Opt-in focus aggregates plus capture experiment in Chromium, Firefox and WebKit | Five captures per engine caused no focus/visibility changes locally; no screenshot detector is shipped |
| Repeated workflows | Existing server category/transition summaries; new linked suspicious activity across sessions | Independently confirmed incidents; account/target sharing and retries as controls |
| Hidden decoys | Explicit hidden, inert diagnostic button with no action, plus cleanup | Functional keyboard/accessibility-tree tests pass; broader assistive-technology study remains necessary |
| JA4/TLS | Optional trusted Cloudflare JA4 evidence, private and separate from browser identity | Deployment availability and application-specific validation; no browser/header claims trusted |
The experimental report records the measured controls and limitations. Third-party dataset replay only validates the overlapping features it actually contains. The current Jev replay uses cached earlier answers and does not validate the new prompt or probes.
Promotion still requires independently labeled holdouts, measured incremental benefit, false-positive analysis, calibration and a versioned rollback. Predictions never become their own ground-truth labels. DOM scrambling, adversarial image overlays, raw cursor/keystroke recording and bypasses of browser privacy restrictions are not part of this implementation: they do not provide established identity or risk evidence and can damage ordinary use.