Deep Seek New Harness Vs Reasonix whats smarter in coding tasks?

cache rate is same for both , 99% approx!
but if we talk about harness smartness which one is better?

reddit.com
u/NinjaAlaska — 1 day ago
▲ 7 r/ollama

After Price hike DeepSeek-V4-Flash:0731 is dumb in opencode & Else where. How it is in Ollama cloud?

seems like others are now using lower precision models. On open code sub i see a lot of people saying model has gone dumber since price hike started.

How it is behaving in Ollama cloud PRO? Same?

reddit.com
u/NinjaAlaska — 2 days ago
▲ 134 r/opencode+1 crossposts

Command Code when you expose their misleading schemes.

So speaking truth is bad. Only those who try both , know that its highly misleading even after new pricing. Ban me all you want, others speak of truth often too.

P.S: dont assume request in deepseek is more there, its token based and misleading. stop being dumb. they literally have a token slider some where in docs, me smart.

REASON:
just speaking truth!
https://www.reddit.com/r/DeepSeek/comments/1viwwpx/beware_of_command_codes_misleading_marketing/
https://www.reddit.com/r/CommandCode/comments/1v61r8h/command_code_1_plan_claims_50_mimo_v25_pro/ (read owner's comment full of down votes as proof)

EDIT; i gain nothing from dissing them, its just that as a consumer its my duty to let other know with proofs. you will find plenty of complains on their sub too but they keep deleting those. good news in in other sub the proof stays.

u/NinjaAlaska — 4 days ago
▲ 96 r/opencode+2 crossposts

Beware of Command Code's misleading marketing

TL;DR: the $1 Go plan gets you $10 of DeepSeek V4 Pro credit, not the "$40" the headline claims. The $10 GOAT plan gets you a $20 DeepSeek V4 Pro allowance, not "$80". The "4x deal" is DeepSeek's own price cut, relabeled. The value itself is fine. The misleading marketing around it isn't.

This is their pricing page, right now. Go costs $1/month and comes with "$10 in credits included" and "up to $40 usage with deals". GOAT costs $10/month with "$70 in credits included" and "$80 on DeepSeek V4 Pro with deals".

Source: https://commandcode.ai/pricing (captured 2026-08-08)

Here's what "with deals" means. Their own GOAT model table shows DeepSeek V4 Pro with a -75% badge, $1.74 / $3.48 / $0.0145 struck through, next to $0.435 / $0.87 / $0.003625.

Source: https://commandcode.ai/docs/plans/goat (captured 2026-08-08)

Now check DeepSeek's own price list. The current official rates for deepseek-v4-pro are exactly those numbers: $0.435 per million input tokens, $0.87 output, $0.003625 on cache hits. Anyone with an API key gets them.

Source: https://api-docs.deepseek.com/quick_start/pricing (captured 2026-08-08)

It gets better. Archived copies of DeepSeek's page show DeepSeek itself running that "75% off" promo, with the same strikethroughs, back in May. And by June 1 the cut was permanent.

Source: https://web.archive.org/web/20260501050639/https://api-docs.deepseek.com/quick_start/pricing

Source: https://web.archive.org/web/20260601081343/https://api-docs.deepseek.com/quick_start/pricing/

Any reseller billing at today's rates gets that "deal" for free. Command even spells the trick out in its docs: "$10 credits effectively has up to $40 of DeepSeek V4 Pro usage", and the deal is labeled "permanent".

Source: https://commandcode.ai/docs/resources/pricing-limits (captured 2026-08-08)

So your $10 of credits is $10 of usage at current prices. The "$40" headline only works if you pretend the old price, which nobody has paid since May 31, is still real.

The GOAT plan launched in August 2026, two months after the DeepSeek cut was permanent. Command Code bills DeepSeek tokens, so it knew the rates. I don't think a company builds a "permanent 4x deal" out of a price that stopped existing two months earlier by accident. I asked them about it and got blocked on the platforms where I asked. That's my experience, take it for what it's worth. I believe the misleading framing is deliberate. I can't prove intent, but the dates do the talking.

To be fair, the plans are not bad value. $1 for $10 of DeepSeek V4 Pro usage at official rates is a decent deal. My problem isn't the pricing, it's the misleading marketing wrapped around it, and how the company and its CEO treats people who ask questions about it. I'd think twice before trusting this company with anything. If you read the fine print and check the numbers yourself, at least you'll know exactly what you're paying for.

This post was drafted with AI. I do dislike Command Code's marketing, just not enough to write all of this by hand.

reddit.com
u/NinjaAlaska — 13 days ago

command code 1$ plan claims 50$ Mimo V2.5 Pro Credits but is it true? because rate limit math makes no sense otherwise

https://preview.redd.it/qsre5bzlxbfh1.png?width=1186&format=png&auto=webp&s=4417ed9ad92dc0a54c22f1a165aed157cfe90e10

can some one help me understand. they have limit of 6$ per week. that 6*4 = makes 24$ a month cap. Why they are saying Mimo V2.5 pro is worth 50$ and mimo v2.5 is worth 100$ in credits in 1$ plan?
source: https://commandcode.ai/docs/resources/pricing-limits#mimo-v2.5-pro-99-off

trying to understand how it works in case of Mimo v2.5 pro. Not complaining or something. its already still good deal.

reddit.com
u/NinjaAlaska — 27 days ago
▲ 226 r/Bard+1 crossposts

AI community: Give us Gemini 3.5 Pro. Google DeepMind:

u/NinjaAlaska — 1 month ago
▲ 2 r/pop_os

does new version of popOS of supports binderfs? if no how i can enable?

any idea how i can enable binderfs some how in Pop!_OS ? as of my knowledge its a kernel thing right? can some one help me has some one achieved this?

reddit.com
u/NinjaAlaska — 1 month ago

This Simple SOUL.md Tweak helped me gain +13% Score in Terminal Bench With Hermes

I benchmarked lot of harness (PI, Hermes CLI, Codex CLI and claude code, etc) against terminal benchmark v2.0. (ON each benchmark i used a fresh VM or sandbox offcourse to test hermes)

AI models used were: Mimo V2.5 & Deep Seek v4 flash (both from opencode as provider in this test)

NOTE: I have tried making my own SOUL.md and looped it many time. this is latest version of it written/modified by CLAUDE FABLE which has scored max (+15%) in 1 models listed above. (mimo). Hermes did scored highest on both models with base SOUL file hence i picked to improve Hermes only.

Hermes + Below SOUL.md scored 63% In Terminal Bench 2:

You are a fast, pragmatic terminal engineer. A hidden automated test inspects the machine's FINAL
state after you finish, and passes ONLY if EVERY requirement is met -- satisfying most but missing
one detail or edge case still FAILS. Your first solution is a hypothesis; only the real output of a
command you actually ran proves anything ("looks right" is not proof) -- so when a step depends on a
result, run the command and read what it ACTUALLY printed before deciding; never assume or invent
output you haven't seen.

Work every task in this order, and never skip step 5:

1. TARGET -- write a short checklist (1-5 items) of exactly what must be true when you're done: the
   precise output file path(s)/format and every stated or implied requirement. Turn it into a
   command that objectively passes/fails (exit code, grep the artifact, diff the output). To fix a
   bug, grep the exact error/symbol to find the responsible file+line and grep its callers so you
   fix the root once -- then run the check and watch it FAIL first. Never assume a path, format, or
   requirement.

2. SOLVE FAST -- build a complete, working solution that PRODUCES the exact required output as early
   as possible; a simple correct solution beats an elaborate unfinished one. Reason in a sentence or
   two, then run something -- long plans with no command waste budget and prove nothing. Prefer
   tools/libraries
   that are ALREADY INSTALLED (stdlib first). If you must install something, do it early -- downloads
   are slow and flaky -- and keep a no-install fallback in mind.

3. RUN & CHECK -- actually run your solution (and any test/check command the task or workspace
   provides -- that is ground truth) and READ the real output. Exercise edge/boundary cases too, not
   just the happy path.

4. FIX & LOOP -- diagnose from the real output, fix anything missing or wrong, then re-check. If the
   same approach fails twice, switch approaches.

5. FINAL GATE (mandatory) -- before finishing, prove by commands you ran that: (a) the required
   artifact EXISTS at the exact path, (b) EVERY checklist item from step 1 is satisfied (its pass/fail
   check passes on a clean re-run), and (c) you left ONLY the required outputs -- no stray/temp files,
   and no unrelated files changed. If you are low on time, still leave a COMPLETE best-effort solution
   in place -- never end with nothing.

Terminal discipline: use only non-interactive commands (never open editors/pagers; use flags like
-y or --no-pager, or pipe through cat); inspect large files with head/tail/grep instead of dumping
them whole; start any long build/download early. Don't invent flags, APIs, or filenames -- verify
one exists (--help / quick import / ls) before relying on it; on "unknown option"/"not found", read
what IS available instead of guessing the same shape again.

Task-type reminders (apply only if relevant):
- Removing/sanitizing data: it must be gone from EVERYWHERE it persists (git history, branches,
  reflog) -- without altering unrelated files.
- Filtering/transforming: enumerate every variant/instance, handle all, then re-scan to prove none
  remain.
- A computed answer: derive it a second, independent way before writing it.
- A speed/time requirement: measure your solution's actual runtime yourself.
- Match the exact required filename, path, and output format precisely.

Prefer minimal sufficient changes over broad rewrites; change only what the task requires.

If you are using DeekSeek V4 Flash and not Mimo v2.5 do give it a try. A lot of people has agreed with me on diff discussion. Both are good but Mimo scored more in test 15%. Both have similar benchmarks too, i moved to Mimo V2.5 from DS v4 my coding task suits it more. Both are similar so no biggie.

How good is this prompt?
Claude Code (Opus 4.8 xhigh) and Codex (GPt 5.5 high) they were unable to fix bugs in my opensource project and a personal AI trading project. This setup did fixed it. I am not claiming this is better but its also not bad. 62% Score on this model is good. Base was 50% without my SOUL.md for Mimo. This might be base SOUL but little modified.

Just wanted to share something to make some one's life little better, nothing special.

I am sure there are even more SOUL.md tested by you guys which have made Hermes Better Engineer in Vibe Coding. Please do share below would love to test them too.

u/NinjaAlaska — 1 month ago

any one else finds Mimo v2.5 better than deepseek v4 flash!?

I noticed while using both, mimo was often better,
after benchmarking mimo v2.5 via open code endpoint in diff harness like codex, oh my pi, hermes. i found that mimo is indeed better in coding tasks.
and over all, hermes scored 55% with mimo v2.5 via terminal bench v2.0
others did under 50% too with any harness from my list or deepseek v4 flash

Not that i dont like deep seek v4 flash its GOAT, i have used it more. but as per benchmark both models are same at most places but when u run real life complex problems solving mimo v2.5 seemed to me helping me more

i tested hy3 preview too. idk to me it felt like benchmark trained. needs to try more , but scores were pretty low for me in terminal bench

EDIT: also while comparing oh my pi vs hermes vs codex cli. found hermes better for some reason. (offc for low lvl models only in my casestudy)

reddit.com
u/NinjaAlaska — 1 month ago
▲ 118 r/huggingface+1 crossposts

I fine tuned Gemma 4-31B for Copywriting & Creative Work

Hey everyone,

Wanted to share a project I've been working on: copywriter-gemma4-31b, a fine-tune of Gemma aimed specifically at copywriting tasks — headlines, product descriptions, ad copy, CTAs, and short marketing emails. Link: https://huggingface.co/akwin123/copywriter-gemma4-31b
GGUF:
https://huggingface.co/models?other=base_model:quantized:akwin123/copywriter-gemma4-31b

Why I built this

Most general-purpose LLMs are decent at copywriting but tend to default to generic, safe phrasing ("Elevate your experience," "Unlock the potential of..."). I wanted something smaller and cheaper to run that leans into punchier, more direct commercial writing without needing a huge model or heavy prompting gymnastics every time.

Training approach

  • Base model: Gemma 4 - 31B
  • Method: QLoRA
  • Data size: 93k (high quality)
  • Scored +290 points more than base model as per https://eqbench.com/

What worked

  • Style transfer was strong for short-form copy (headlines, CTAs) — noticeably punchier than base Gemma
  • Held up reasonably well on product categories it wasn't explicitly trained on
  • Inference is fast/cheap enough to run on [hardware], which was the whole point

Example output

Prompt: "Write a headline for a noise-cancelling headphone brand targeting remote workers"

Base Gemma: "Experience premium sound quality with our advanced noise-cancelling technology."

Fine-tuned: "Silence the chaos. Work like you're the only one in the room."

(Your mileage may vary obviously — cherry-picked example, not a guarantee.)

Open questions for the community

  • Anyone else fine-tuned small models for narrow commercial writing tasks? Curious how you handled the "generic tone" problem.
  • Is LoRA generally sufficient for style transfer like this, or does full fine-tuning meaningfully help for domain-specific voice?
  • Any recommended eval methods for copywriting quality beyond just vibes/manual review?

Happy to share more details on the dataset curation process or answer questions about the setup if it's useful to anyone attempting something similar.

u/NinjaAlaska — 2 months ago

My ISP is secretly intercepting my HTTPS!? But only on TLS 1.2. Took me 6 hours to figure out and I almost lost my mind

TL:DR: In short my ISP can see my encrypted information like Passwords, OTPs, card numbers, Cookies etc. easily which they are not supposed to -.-

Just burned 6 hours on this and need to dump it somewhere before I forget half of it.

Started off dumb. Claude Code AI and a couple of my Node.js apps suddenly started throwing SSL/cert errors out of nowhere. But Chrome? Totally fine, every site green padlock, no warnings. So naturally I assumed my PC was cooked. Reinstalled stuff, even ripped out Bitdefender AV thinking it was the culprit. Nothing changed.
Turns out my PC was never the problem. It's my ISP.

Here's the part that made me feel insane: (tech stuff)
Chrome works fine because it uses QUIC and TLS 1.3. My Node apps were breaking because they default to TLS 1.2. The second I forced TLS 1.2, the certs came back signed by some Fortinet CA instead of the real one (issuer literally says CN=redacted, O=Fortinet). Same site, same second — TLS 1.3 gives you the real cert, TLS 1.2 gives you a fake one. That's the whole bug.

So my ISP is running a FortiGate firewall doing SSL deep inspection — it decrypts your HTTPS and re-signs it with its own cert on the fly. But it only seems to bother with TLS 1.2 traffic. TLS 1.3 it just waves through, probably because it can't crack it. That's exactly why browsers look totally clean and only "older" apps blow up.Made sure it wasn't my own gear before going off about it:So basically anything I sent over TLS 1.2 on this line — logins, whatever — XYZ could've read in plaintext. I never installed their cert, never agreed to anything, no heads up, nothing.Couple questions for anyone who's been through this:If you want to check your own line: force a TLS 1.2 connection (openssl or PowerShell works) to any site and look at the cert issuer. If it says Fortinet or your ISP's name instead of the real CA, congrats, you're being inspected.

Note: ran a full deep scan on my Win 11 PC, it's clean. Android devices on the same wifi showed the exact same issue, and none of these devices show any problem on a different ISP or hotspot. So it's 100% on their end, not mine. I also asked AI to deep scan things and confirm.
Worst part , I can't connect to most VPNs right now, paid or free. Never had this issue before either. Privacy is now a bigger joke !?

Should i do a TRAI (GOV) complaint or for your ISP's support ticket? Idk how I will even explain this issue to Non Tech Support of ISP.

My ISP is #1 or #2 ISP in my State. Dont want to name it.

Question To Techy People: is there any thing else that can cause similar behaviour by chance?! I can confirm there is no virus or malware, I am a techy person & a computer engineer.

NOTE: Post formatted & edited by AI help.

reddit.com
u/NinjaAlaska — 2 months ago
▲ 602 r/india

My ISP is secretly intercepting my HTTPS!? But only on TLS 1.2. Took me 6 hours to figure out and I almost lost my mind

FINAL UPDATE:

1. No way to know if it was intentional MITM or an ISP misconfig — either way, on TLS 1.2 their FortiGate could read my traffic due to certain conditions explained below.

2. Some of my data leaked, partly my fault — an old Node.js setup forcing TLS 1.2 with SSL checks off (NODE_TLS_REJECT_UNAUTHORIZED=0) I set last year and forgot.

3. Browser users hit too — if you saw "Not private" and clicked "Proceed anyway," that site's data leaked (banks/Google use HSTS, so those were safe). I was safe from this but if other users would have clicked that, their data was assumed to be leaked I guess.

4. Chrome's SSL error came and went randomly = the interception was flipping on/off a lot, not constant intitally. Then it was always consistant on TLS 1.2 Only.

5. Lasted ~6 PM to till morning, then fixed itself — no complaint from me yet — so probably a config screwup they caught and reverted. (MTIM possiblity seems low, but like i said we will never know). Behaviour was itself like MITIM if a user ignores SSL request even my mistake.

How to stay safe:

  1. Never click "Proceed anyway" on a cert warning — that's the moment you leak. If a site says "Not private," stop right there please.
  2. Don't disable SSL checks and forget, a rookie mistake as a dev lol — audit for NODE_TLS_REJECT_UNAUTHORIZED=0, curl -k, --ignore-certificate-errors. That's what got me.
  3. Keep apps modern — TLS 1.3 (all current browsers/Node) slips past this kind of interception automatically.
  4. Sensitive stuff → mobile data or a VPN. (Standard VPNs may be DPI-blocked on such ISPs; a TLS-camouflaged proxy on 443 gets through.)
  5. Test your own line: force a TLS 1.2 connection and check the cert issuer — if it's not the real CA, you're being inspected or there is a misconfigure thats troublesome. (this is hard and techy part ignore if you are ordinary person, read point 1 only)
  6. If you were exposed (clicked through, or had SSL checks off): rotate those passwords/API keys and turn on app-based 2FA (TOTP, not SMS).

TL;DR: keep TLS 1.3, never bypass cert warnings, VPN/mobile for anything sensitive.

I have enough headache i am taking break now, this ans all of most questions now and what happened too. thansk guys for tips.

OLD STUFF and INCIDENT:

TL:DR: In short my ISP can see my encrypted information like Passwords, OTPs, card numbers, Cookies etc. easily which they are not supposed to -.-

Just burned 6 hours on this and need to dump it somewhere before I forget half of it.

Started off dumb. Claude Code AI and a couple of my Node.js apps suddenly started throwing SSL/cert errors out of nowhere. But Chrome? Totally fine, every site green padlock, no warnings. So naturally I assumed my PC was cooked. Reinstalled stuff, even ripped out Bitdefender AV thinking it was the culprit. Nothing changed.
Turns out my PC was never the problem. It's my ISP.

Here's the part that made me feel insane: (tech stuff)
Chrome works fine because it uses QUIC and TLS 1.3. My Node apps were breaking because they default to TLS 1.2. The second I forced TLS 1.2, the certs came back signed by some Fortinet CA instead of the real one (issuer literally says CN=redacted, O=Fortinet). Same site, same second — TLS 1.3 gives you the real cert, TLS 1.2 gives you a fake one. That's the whole bug.

So my ISP is running a FortiGate firewall doing SSL deep inspection — it decrypts your HTTPS and re-signs it with its own cert on the fly. But it only seems to bother with TLS 1.2 traffic. TLS 1.3 it just waves through, probably because it can't crack it. That's exactly why browsers look totally clean and only "older" apps blow up.Made sure it wasn't my own gear before going off about it:So basically anything I sent over TLS 1.2 on this line — logins, whatever — XYZ could've read in plaintext. I never installed their cert, never agreed to anything, no heads up, nothing.Couple questions for anyone who's been through this:If you want to check your own line: force a TLS 1.2 connection (openssl or PowerShell works) to any site and look at the cert issuer. If it says Fortinet or your ISP's name instead of the real CA, congrats, you're being inspected.

Note: ran a full deep scan on my Win 11 PC, it's clean. Android devices on the same wifi showed the exact same issue, and none of these devices show any problem on a different ISP or hotspot. So it's 100% on their end, not mine. I also asked AI to deep scan things and confirm.
Worst part , I can't connect to most VPNs right now, paid or free. Never had this issue before either. Privacy is now a bigger joke !?

Should i do a TRAI complaint or for your ISP's support ticket? Idk how I will even explain this issue to Non Tech Support of ISP.

My ISP is #1 or #2 ISP in my State. Dont want to name it.

Question To Techy People: is there any thing else that can cause similar behaviour by chance?! I can confirm there is no virus or malware, I am a techy person & a computer engineer.

NOTE: Post formatted & edited by AI help.

reddit.com
u/NinjaAlaska — 2 months ago

I am tired of BitDefender false positives - Better Alternative Please?

i am developer. I use lot of open source AI tools, and other safe tools.
Stupid bitdefender is flagging everything. at this point it thinks all nodejs tools are now unsafe. My system is clean i can tell myself i am not stupid.

please suggest me something better. or should i just use windows defender?! or some other free antivirus that is better?

EDIT: using bitdefender total plan. Paid one. I tried white listing as exceptions too, this is just absurdly stupid now

reddit.com
u/NinjaAlaska — 2 months ago

Use Stealth Playwright on real Android OS, Stop Using Desktop — free & open-source Playwright automation (Redroid + CDP)

Hey r/playwright 👋

I built the Playwright + Android + CDP framework everyone keeps recommending but nobody had free & open-source.

If you've ever run Playwright with a stealth plugin and still got flagged, you know the core problem: it's desktop Chromium faking mobile with viewport tricks and JS patches, and detection suites see through that fast.

What it is: Damru is a free, open-source browser-automation framework that runs Playwright on real Android (via Redroid — Android in Docker), instead of desktop Chromium pretending to be a phone. You drive it with the Playwright API you already know, but it executes on a genuine Android stack.

The key difference — zero JS injection: most stealth tools patch the browser from inside with Object.defineProperty-style JavaScript, which is brittle and detectable. Damru does its spoofing at the OS, binary, and CDP levels — so there's no injected JS fingerprint to catch.

Vs the usual stack (Playwright, puppeteer-stealth, undetected-chromedriver, Camoufox, fingerprint-chromium): those all harden a desktop browser. Damru takes the other road — a real Android environment — for a genuinely mobile fingerprint surface and far less reliance on brittle browser-side patches.

What's in it:

  • Android-in-Docker via Redroid + Playwright support
  • Zero-JS spoofing at the OS / binary / CDP level
  • 100+ built-in Android device profiles; CPU / RAM / touch-point hardware overrides
  • Proxy-aware timezone / locale / language matching
  • Mobile network emulation; WebRTC + IPv6 leak blocking; native iptables network protection
  • TLS spoofing
  • Multi-container pooling for scale + pre-baked images to cut setup time
  • Real HAL Sensors , etc.

Holds up against the suites that flag normal Playwright for mobile device — CreepJS, BrowserScan, Sannysoft, Cloudflare Turnstile, and the major CDN anti-bots — thanks to the real-Android approach. Ideal for stress-testing your own anti-bot stack and for fingerprinting research.

Pros: far harder to detect than desktop stealth setups for Mobile.
Cons: real Android = a bit slower since its a real android OS running in Docker.

Why I built it: I kept seeing posts recommending "just use Playwright + Android + CDP" — but no actual framework existed around it. So I made one.

Quick start:

pip install damru

Strictly for educational and research use — please don't use it for anything abusive or illegal. 100% Free to Use, no backed SaaS.

Repo: https://github.com/akwin1234/damru
Site / docs: https://damru.dev

Would love feedback from anyone doing browser automation, testing, or anti-bot research — what would make this genuinely useful to you?

u/NinjaAlaska — 2 months ago
▲ 40 r/privacy

If i remove Edge Not only Micorsoft Brings it back But also deletes Cookies of my chrome - How this is even fair? isnt this unethical? why would they touch my chrome?

At first I thought it was a system bug. But now I see it happen every time I remove Edge, not only does Microsoft bring it back, they also somehow reset my Chrome (i must not loose my chrome cookies). Another sign is they try to set Edge as the default browser, and the same action deletes my Chrome cookies. I don’t get why they would touch my Chrome. How bad do they have to be?

I switched to Linux, but I still need Windows for development. This is really annoying and I don’t know what to do. All my websites are logged out again, not a huge issue, but it’s painful to deal with. I’m pissed off. They don’t reset my Chrome often, but this is definitely the third time. -.-

I am not seeking tech support. I will deal with it, no biggie.
But this behaviour of edge deleting my chrome cookies while it reinstall itself and then it trying to set it as default, has any one else faced it? or only me?

I feel targetted because it resets only chrome + its main profile lol. Good thing it doesnt touches other chrome profiles

reddit.com
u/NinjaAlaska — 2 months ago
▲ 46 r/freesoftware+5 crossposts

New Free open-source Android automation for web scraping - Damru

Damru is a browser automation framework built around real Android environments in Docker for scraping and automation tasks where mobile behavior matters.

What sets it apart is that it’s not just another desktop browser with stealth patches. The project is built around zero JS injection, with spoofing handled at the OS, binary, and CDP levels instead of the usual JavaScript-heavy tricks used by many stealth tools.

Compared with tools like Playwrightpuppeteer-stealthundetected-chromedriverCamoufox, and Fingerprinting Chromium, Damru is trying to solve the problem differently: by running inside a real Android stack rather than faking mobile behavior on desktop Chrome. The idea is to get a more realistic mobile environment, stronger fingerprint control, and less reliance on brittle browser-side patches.

What makes it different:

  • Zero JS injection: Damru does spoofing at the OS, binary, and CDP levels instead of relying on Object.defineProperty-style JavaScript patches.
  • Real Android OS: It runs inside Redroid, so it’s not just desktop Chrome pretending to be mobile through viewport tricks.
  • Native mobile fingerprinting controls: device profiles, hardware overrides, locale/timezone matching, mobile network emulation, and WebRTC/IPv6 blocking.
  • Multi-instance pooling: built for scaling across multiple containers.
  • Pre-baked image support: reduces setup overhead.

Some of the features include:

  • Android-in-Docker via Redroid.
  • Playwright support.
  • A built-in database of 32+ Android device profiles.
  • Proxy-aware timezone, locale, and language matching.
  • Hardware overrides for CPU, RAM, and touch points.
  • Mobile network emulation.
  • WebRTC and IPv6 leak blocking.
  • Native Android iptables-based network protections.
  • Multi-container pooling for scale.
  • Pre-baked image support to reduce setup time.
  • TLS spoofing and soo many things

Also stronger against systems like CreepJS, BrowserScan, Sannysoft, Cloudflare Turnstile,etc ALL CDN anti-bots dont waana name them than standard Playwright or typical stealth plugins, mainly because of the deeper Android-based approach.

Pros: Highly UnDetectable
Cons: Real Android OS hence little slower. Hard to Use (thats why custom docker image included)

Repo: https://github.com/akwin1234/damru

Would love feedback from anyone who works on scraping, browser automation, or anti-bot research. I made this because i see many reddit post recommending Android Player

u/NinjaAlaska — 3 months ago
▲ 109 r/webscraping+1 crossposts

New Free open-source Android automation for web scraping - Damru

Hey r/webscraping, I’m sharing a free open-source project I’ve been building called Damru: https://github.com/akwin1234/damru

Damru is a browser automation framework built around real Android environments in Docker for scraping and automation tasks where mobile behavior matters.

What sets it apart is that it’s not just another desktop browser with stealth patches. The project is built around zero JS injection, with spoofing handled at the OS, binary, and CDP levels instead of the usual JavaScript-heavy tricks used by many stealth tools.

Compared with tools like Playwrightpuppeteer-stealthundetected-chromedriverCamoufox, and Fingerprinting Chromium, Damru is trying to solve the problem differently: by running inside a real Android stack rather than faking mobile behavior on desktop Chrome. The idea is to get a more realistic mobile environment, stronger fingerprint control, and less reliance on brittle browser-side patches.

What makes it different:

  • Zero JS injection: Damru does spoofing at the OS, binary, and CDP levels instead of relying on Object.defineProperty-style JavaScript patches.
  • Real Android OS: It runs inside Redroid, so it’s not just desktop Chrome pretending to be mobile through viewport tricks.
  • Native mobile fingerprinting controls: device profiles, hardware overrides, locale/timezone matching, mobile network emulation, and WebRTC/IPv6 blocking.
  • Multi-instance pooling: built for scaling across multiple containers.
  • Pre-baked image support: reduces setup overhead.

Some of the features include:

  • Android-in-Docker via Redroid.
  • Playwright support.
  • A built-in database of 32+ Android device profiles.
  • Proxy-aware timezone, locale, and language matching.
  • Hardware overrides for CPU, RAM, and touch points.
  • Mobile network emulation.
  • WebRTC and IPv6 leak blocking.
  • Native Android iptables-based network protections.
  • Multi-container pooling for scale.
  • Pre-baked image support to reduce setup time.
  • TLS spoofing and soo many things

Also stronger against systems like CreepJS, BrowserScan, Sannysoft, Cloudflare Turnstile,etc ALL CDN anti-bots dont waana name them than standard Playwright or typical stealth plugins, mainly because of the deeper Android-based approach.

Pros: Highly UnDetectable
Cons: Real Android OS hence little slower. Hard to Use (thats why custom docker image included)

Repo: https://github.com/akwin1234/damru

Would love feedback from anyone who works on scraping, browser automation, or anti-bot research. I made this because i see many reddit post recommending Android Playwright CDP but there was no framework around it. This is strictly for educational purpose only. Do not do legal abuse.

u/NinjaAlaska — 3 months ago