Releases: sunghoojung/reverse-engineering-browser
Release list
Origin Trace v0.2.1
What's Changed
- Origin Trace v0.2.1: cleaner live Traffic by @sunghoojung in #83
Full Changelog: v0.2.0...v0.2.1
Origin Trace v0.2.0
What's Changed
- Add DevTools-style pretty printing to Sources by @sunghoojung in #81
- Harden live session startup and release v0.2.0 by @sunghoojung in #82
Full Changelog: v0.1.10...v0.2.0
Origin Trace v0.1.10
What's Changed
- Fix cancelled live-session navigation and release v0.1.10 by @sunghoojung in #80
Full Changelog: v0.1.9...v0.1.10
Origin Trace v0.1.9
Superseded by v0.1.10, which fixes a launch-time
NSURLErrorDomain error -999alert in this release.
What's Changed
- Start a complete instrumented session on launch by @sunghoojung in #79
Full Changelog: v0.1.8...v0.1.9
Origin Trace v0.1.8
macOS download
- Origin Trace v0.1.8 adds bounded static JavaScript deobfuscation inside Sources. The application is built by GitHub Actions from this release tag and contains no bundled evidence.
- Brave Browser Development preview is unchanged. If you already have it, download only Origin Trace.
Deobfuscation
- Switch between original and derived JavaScript directly in Sources while retaining the captured artifact.
- Map every derived rewrite to its original UTF-8 byte range.
- Fold bounded primitive expressions, constants, literal string tables, proxy calls, closed custom decoders, and loop/switch dispatchers.
- Opt in to a visible standard-intrinsics model for character decoders and JSFuck-style coercion.
- Reject excessive parser nesting before recursive analysis and retain unresolved code when safety or correctness cannot be proven.
Limits and safety
Captured JavaScript is never executed. Unknown effects, arbitrary top-level control-flow graphs, recursion, custom prototype hooks, mutable or escaping tables, and unsupported operations remain visible. The worker enforces source, parser, evaluation, loop, rewrite, and output limits.
The application is ad-hoc signed for development and internal use. It is not Developer ID signed or notarized.
Changes
Reverse Engineering Browser v0.1.7
macOS downloads
- Origin Trace v0.1.7: refreshed research interface, built by GitHub Actions from the release tag. Normal launch uses live mode, without demo evidence.
- Brave Browser Development v0.1.5: the exact unchanged Apple-silicon archive used in v0.1.6. If you already have it, download only Origin Trace.
Unzip the apps and keep them beside each other so Origin Trace can find the custom Brave browser.
UI improvements
- Rosé Pine Moon colors, simpler sidebar navigation, and clearer request/response inspection.
- Fingerprinting emphasizes active surfaces and captured results, with expandable replay and evidence details.
- Backtraces groups identifiers separately from relationship facts.
- Memory places mode selection above search and results.
- Experiments separates setup, request, and response with expandable activity logs.
- Analyst gives the editor more space and groups secondary settings.
- Tools emphasizes input and output with expandable transformation history.
- Improved narrow-window layouts, scrolling, and keyboard focus.
Browser scope and distribution
Brave was not rebuilt. Its archive SHA-256 is f5b3dc4d56fdec11c710295dcd7bc0ab8e93f15b330f61ddc3c3a817c37ff62b. It retains the v0.1.5 browser feature set, including the previously documented absence of newer source-only browser changes.
The apps are ad-hoc signed for development and internal testing, not Developer ID signed or notarized.
Validation
Local lint, check (155 UI tests), E2E, sanitizers, app build, strict signature verification, and diff checks passed. PR and main CI passed on macOS and Linux. The native app was verified in normal mode without demo evidence. Responsive UI flows were checked at 650, 900, and 1440px; live experiment mutations were not exercised during this UI pass.
UI changes: #71
Full changelog: v0.1.6...v0.1.7
Reverse Engineering Browser v0.1.6
macOS downloads
- Origin Trace v0.1.6: updated macOS research interface, built by GitHub Actions from the v0.1.6 tag.
- Brave Browser Development v0.1.5: the exact, unchanged Apple-silicon browser archive from v0.1.5. Brave was not rebuilt for this release. If you already have that browser, download only Origin Trace.
Unzip the apps and keep them beside each other so Origin Trace can find the custom Brave browser.
Origin Trace improvements
- Select exact UTF-16 source columns for runtime hooks on minified code, including inline-script offsets.
- Navigate individual literal search matches with Enter and Shift+Enter, with highlighting and horizontal scrolling.
- Remove stale live scripts and resolved breakpoint locations when execution contexts are destroyed, while preserving URL breakpoint definitions and captured evidence.
- Preserve completed redirect-hop status, headers, and timing in network capture.
- Report renderer crashes and recovery in the Sources view.
- Keep source filenames visible in narrow navigation panes.
- Accept runtime and artifact records in offline evidence validation.
- Report app version 0.1.6 (build 6).
Browser scope
The source tree also includes the multi-client embedder-pause attribution fix, but the reused v0.1.5 Brave binary does not contain that newer browser change.
Validation
- Local lint, native and UI checks (155 Python tests), end-to-end checks, sanitizers, app build, strict signature verification, and whitespace checks passed.
- Packaged native smoke verification loaded bundled UI assets and exercised the decoder successfully.
- Main-branch CI passed on macOS and Linux.
- The tag workflow built and signature-verified the published Origin Trace archive from a clean checkout.
- Reused Brave archive verified against its v0.1.5 SHA-256:
f5b3dc4d56fdec11c710295dcd7bc0ab8e93f15b330f61ddc3c3a817c37ff62b.
Origin Trace archive SHA-256: a02448fc3572988fbc219151199365691fa74f6515f0cd1e31d617cdd454cee0.
Distribution
The apps are ad-hoc signed for development and internal testing, not Developer ID signed or notarized.
Full changelog: v0.1.5...v0.1.6
Reverse Engineering Browser v0.1.5
macOS downloads
- Origin Trace - the macOS research interface.
- Brave Browser Development - the custom Apple-silicon browser containing the native fingerprint probes.
Unzip both downloads and keep the two apps beside each other. Opening Origin Trace will locate the custom Brave app and can launch it for the live capture workflow.
v0.1.5 changes
- Adds a reproducible, pinned-source static Brave distribution build.
- Uses a self-contained non-component browser bundle with the updater disabled.
- Verifies the app after ZIP extraction instead of relying on files outside the bundle.
- Includes the expanded native fingerprint probes and the redesigned per-tab Fingerprinting inspector from v0.1.4.
- Captures Canvas readback images only when explicitly enabled for the session.
Validation
- Main-branch CI passed on macOS and Linux.
- The hosted release job built and verified Origin Trace from tag v0.1.5.
- The custom Brave static build completed 49,150 build steps and passed isolated extraction, strict signature verification, launch, and live Fingerprint Playground QA.
- Live QA observed 483 fingerprint events across all eight surface families, 255 unique operations, five Canvas readbacks, three open tabs, and zero missing event IDs.
Checksums
- Brave Browser Development:
f5b3dc4d56fdec11c710295dcd7bc0ab8e93f15b330f61ddc3c3a817c37ff62b - Origin Trace:
ffcd1ee2b2e719fb153ef9313713e069f1fdb025717ce550734c673d458cfc81
Distribution note
These macOS apps are ad-hoc signed for development and internal testing. They are not Developer ID signed or notarized.
Full changelog: v0.1.4...v0.1.5
Origin Trace v0.1.4
What's Changed
- Refresh README release overview by @sunghoojung in #58
- Document fast Brave development builds by @sunghoojung in #59
- Expand native fingerprint capture and Origin Trace inspector by @sunghoojung in #60
Full Changelog: v0.1.3...v0.1.4
Origin Trace v0.1.3
What's Changed
- Remove demo evidence from production app by @sunghoojung in #57
Full Changelog: v0.1.2...v0.1.3