The September 23 backlog now has an implementation or a bounded experiment for every listed hypothesis. Optional collectors are off by default. The collection guide explains the contract, configuration, primary sources and limits. No new signal has been promoted as a validated detector of a person, assistant brand or attacker.
| Hypothesis | Current implementation | Evidence still needed |
|---|---|---|
| Local/device fonts | Twelve fixed local-only font probes; versioned availability set; optional Jaccard identity weight and Jev context | Multi-device, longitudinal, privacy-browser and collision studies; fonts are not people |
| Downloaded page fonts | Bounded loaded/loading/failed counts; no names or URLs | Separate normal network/policy failures from any useful anomaly |
| Runtime globals | Eight fixed descriptor checks and own-webdriver flag; no getter execution | Modern versions, ordinary extensions, DevTools and assistive software controls |
| CDP timing | Benchmark-only bounded descriptor timing, instrumented browsers and a separately launched no-CDP control | Broader controlled study: sampled markers absent in both controls and timing overlaps; no timing detector is shipped |
| Permission consistency | Bounded read-only Notifications state queries | Browser/private/enterprise policy baselines; no permission requests |
| Cursor steps and alignment | Existing movement aggregates plus opt-in target-relative counters | Human, touch, keyboard, remote desktop and assistive input holdouts |
| Interaction timing | Existing mean/variance, short/repeated-gap summaries and sample support | Broader tasks and human baselines; no raw keys or per-event timing trails |
| Screenshot/focus hypothesis | Opt-in focus aggregates plus capture experiment in Chromium, Firefox and WebKit | Twenty captures per engine plus 193 controlled CDP captures caused no focus/visibility changes locally; no screenshot detector is shipped |
| Repeated workflows | Existing server category/transition summaries; new linked suspicious activity across sessions | Independently confirmed incidents; account/target sharing and retries as controls |
| Hidden decoys | Explicit hidden, inert diagnostic button with no action, plus cleanup | Functional keyboard/accessibility-tree tests pass; broader assistive-technology study remains necessary |
| JA4/TLS | Optional trusted Cloudflare JA4 evidence, private and separate from browser identity | Deployment availability and application-specific validation; no browser/header claims trusted |
The experimental report records the measured controls and limitations. Third-party dataset replay only validates the overlapping features it actually contains. The expanded live validation made 120 provider calls. The new operator prompt scored near chance on its 80 public-data cases; bounded synthetic linked-activity and single-feature checks exposed both useful responses and calibration concerns.
Promotion still requires independently labeled holdouts, measured incremental benefit, false-positive analysis, calibration and a versioned rollback. Predictions never become their own ground-truth labels. DOM scrambling, adversarial image overlays, raw cursor/keystroke recording and bypasses of browser privacy restrictions are not part of this implementation: they do not provide established identity or risk evidence and can damage ordinary use.