Browser Fingerprinting as a Tracking Technology

Your browser carries a "fingerprint" that is unlike any other in the world. Screen resolution, installed fonts, the GPU model - each of these details looks harmless on its own, but combine them and they identify you with remarkable accuracy. That is what browser fingerprinting does.

Unlike cookies, it stores no data at all on your device, which is why it is also called a "stateless tracking technology." Resetting your browser settings or deleting your cookies does not stop tracking by fingerprint. In the early findings of the Panopticlick project that the EFF launched in 2010 (now Cover Your Tracks), 83.6% of the browsers that visited the project carried a fingerprint that was unique at that time, and among browsers whose Flash or Java plugin details could be read, 94.2% were reported as unique. The technologies being measured have changed between then and now - Flash and Java plugin details have disappeared, and Canvas, WebGL and audio processing traits have taken their place - but it is worth keeping in mind that identifiability itself has not declined.

What Information Is Collected?

What underpins the accuracy of a fingerprint is the sheer volume of information a browser exposes to the outside world. Each individual setting value, harmless as it looks, becomes a clue for identification.

Basic Browser Information

  • User-Agent string (browser type, version, and OS information)
  • Language settings and language priority order
  • Time zone
  • Whether Do Not Track is enabled
  • Whether cookies are enabled or disabled
  • Client Hints (UA-CH), which convey detailed browser and OS information

Screen and Display Information

  • Screen resolution and color depth
  • Device pixel ratio (used to detect Retina displays and the like)
  • Available screen size (the effective area excluding taskbars and so on)
  • Screen orientation (landscape or portrait) and aspect ratio

Hardware Information

  • Number of logical CPU cores
  • Device memory capacity
  • GPU type (obtained via WebGL)
  • Presence of a touchscreen and the number of touch points
  • Battery status (via the Battery Status API, restricted in some browsers)

Advanced Fingerprinting Techniques

Techniques do not stop at collecting simple attribute values. Advanced methods that exploit minute differences in a browser's rendering engine or audio processing are also in wide use. Like the metadata embedded in images and audio, they erode privacy through information users never notice.

  • Canvas fingerprinting: generates a unique hash from the pixel data of content drawn on an HTML5 Canvas element. Subtle differences in GPU, drivers, and rendering engines produce device-specific output
  • AudioContext fingerprinting: uses the Web Audio API to detect minute differences in audio processing. Variations in how the audio stack is implemented create values that differ from device to device
  • WebGL fingerprinting: identifies GPU-specific characteristics from the results of 3D graphics rendering. Differences in shader precision and in the rendering pipeline serve as identifiers

Entropy and Uniqueness

To assess the discriminating power of a fingerprint quantitatively, an information theory metric called "entropy" is used. Entropy is expressed in bits, and the larger the value, the greater the identifying power of that attribute.

Think about it with concrete numbers. An attribute with 1 bit of entropy can split users into two groups; the presence or absence of a touchscreen, for example, is about 1 bit. Attributes where many users cluster on a particular value, such as screen resolution, have less discriminating power. If 30% of all users fell into "1920×1080," the entropy of that attribute alone would come to only about 1.7 bits. GPU renderer strings, on the other hand, run to thousands of variants, so they can carry more than 10 bits of entropy. Ten bits corresponds to roughly 1,024 distinguishable groups, narrowing a user down to less than 0.1% of the whole on its own.

Real-world fingerprints combine 20 to 30 of these attributes. Add up the entropy of each attribute and the total not uncommonly exceeds 33 bits (roughly 8.6 billion combinations), reaching a level at which an individual can be picked out from among all internet users worldwide.

The fingerprint uniqueness score on IP Check-san displays the entropy contribution of each attribute visually, so you can see in numbers how unique your own browser is.

How Fingerprinting Is Used

Fingerprinting is not only a means of tracking that threatens privacy; it is also put to work improving security. Understanding both sides of its use correctly is the first step toward appropriate countermeasures.

Ad Tracking

Advertising networks use it as an alternative to cookies for tracking user behavior across sites. Because tracking by fingerprint continues even after cookies are deleted, it amounts to a more tenacious form of surveillance. This technology is one reason behind the phenomenon of the same ads appearing everywhere. Do read how ad tracking works and how to counter it alongside this article.

Fraud Detection

Financial institutions and e-commerce sites use it to detect unauthorized access and account takeovers. When access from a fingerprint that differs from the usual one is detected, the site requires additional authentication.

Bot Detection

It is also used to tell automated access (bots) apart from human visitors. Bots generally exhibit distinctive fingerprint patterns, such as attribute values specific to headless browsers or unnatural API responses.

How to Protect Yourself from Fingerprinting

Complete protection is difficult, but combining several measures can greatly reduce the risk of being tracked. What matters is building layered defenses instead of relying on any single measure.

Choose a Privacy-Focused Browser

The Tor Browser is designed so that every user carries an identical fingerprint, a thoroughgoing approach in that it erases individual differences altogether. The Brave browser also ships with fingerprint countermeasures as standard. Combining either with a privacy-focused search engine prevents tracking based on your search activity as well.

Use Browser Extensions

  • CanvasBlocker: randomizes or blocks Canvas fingerprinting
  • User-Agent Switcher: spoofs the User-Agent string to a common value
  • Privacy Badger: learns and blocks trackers automatically
  • uBlock Origin: blocks ads and trackers comprehensively, and is also effective against fingerprinting scripts

Review Your Browser Settings

  • In Firefox, enabling privacy.resistFingerprinting normalizes many fingerprint attributes to standard values
  • Disable WebGL (this may affect how some sites are displayed)
  • Restrict JavaScript execution (many fingerprinting techniques depend on JS)
  • Block third-party cookies

Combine with a VPN

A VPN can conceal your IP address and time zone information, but it cannot prevent fingerprinting itself. Combining concealment of your connection route with fingerprint countermeasures delivers more robust privacy protection. If the characteristics of your traffic reveal that you are using a VPN at all, one option is to choose a service that supports obfuscation. Note that a WebRTC leak can expose your IP address even while a VPN is in use, so additional measures are needed.

Do Not Track and Cookie Management

Enabling your browser's Do Not Track (DNT) setting communicates your wish to opt out of tracking to websites. However, since DNT carries no legal force, it is important to use it together with cookie management and tracker blockers such as ad tracking protection tools.

Developments in 2024 and 2025

The landscape around fingerprinting moved substantially between 2024 and 2025. The mechanisms meant to replace cookies were scaled back, while browsers strengthened their countermeasures, so forces pulling in different directions are at work at the same time.

The Policy on Restricting Fingerprinting That Chrome Set Out

In 2019 Google noted that, unlike a cookie, a fingerprint cannot be cleared by the user and leaves people unable to control how information about them is gathered, describing it as something that "subverts user choice and is wrong," and set out a policy of tightening restrictions in Chrome. The direction it presented was to reduce the information that can be obtained passively and to make active fingerprinting attempts detectable so that the browser can step in. Unlike approaches that perturb the values returned or make every user look the same, this is a countermeasure aimed at limiting how much information is available in the first place.

The Major Scaling Back of Privacy Sandbox

Google substantially scaled back the Privacy Sandbox effort it had promoted as a replacement for cookies. The announcement of October 17, 2025 declared the retirement of Topics, Protected Audience, the Attribution Reporting API, Private Aggregation (including Shared Storage) and Related Website Sets, among others. CHIPS, FedCM and Private State Tokens are retained, and the current policy of leaving the handling of third-party cookies in Chrome to the user's choice continues. The originally planned phase-out of third-party cookies has effectively been withdrawn.

The premise that cookies would disappear is gone, yet the advertising industry's demand to identify users remains. As a result, attention has returned to established identification methods such as fingerprinting and probabilistic matching. From a user's point of view, the situation where deleting cookies alone does not stop tracking has, if anything, become more pronounced.

Fingerprint Countermeasures in Major Browsers

Browser vendors are moving in the opposite direction, strengthening their anti-fingerprinting measures.

Mozilla introduced a new stage of fingerprinting protection in Firefox 145, released on November 11, 2025. Mozilla states that these defenses "cut the percentage of users seen as unique almost in half," and the protection takes effect in Private Browsing and when Enhanced Tracking Protection (ETP) is set to Strict.

Brave adopts a technique it calls "farbling," which adds slight per-site, per-session noise to the values returned by APIs such as Canvas, WebGL and AudioContext. By varying the values every time, it aims to make re-identifying the same browser difficult. Safari is also reducing the information usable for fingerprinting as part of Intelligent Tracking Prevention (ITP). Making every user look identical, as Tor Browser does, and perturbing the values, as Brave does, share the same goal but rest on different design philosophies.

Standardization and Regulatory Developments

The W3C, which develops web standards, publishes "Mitigating Browser Fingerprinting in Web Specifications" (September 2025 edition), asking designers of new web APIs to avoid designs that increase the information usable for fingerprinting (the fingerprinting surface). The practice of conducting privacy reviews while new APIs are being specified has become established.

In the EU, the European Data Protection Board (EDPB) adopted the final version of its "Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive" in October 2024, setting out the scope of actions that access information stored on a user's device. Identification methods that do not use cookies can also fall under that provision, which points toward a reading in which fingerprinting too requires user consent in principle. In Japan, the external transmission rules of the Telecommunications Business Act oblige covered operators to notify users or publicly disclose when they send information from a user's device to an external party. Under GDPR and other national regulations as well, demands for transparency around device identification are growing stronger.

Practical Checklist You Can Start Today

To reduce the risk of being tracked through fingerprinting, work through the following items in order. Carrying out privacy measures for mobile devices as well gives you more comprehensive protection.

  1. Check your fingerprint uniqueness score on IP Check-san to see how easily your browser can be identified
  2. Review your browser's privacy settings and enable third-party cookie blocking
  3. Install extensions such as CanvasBlocker or Privacy Badger
  4. Check whether you have a WebRTC leak and take countermeasures if necessary
  5. Check how security headers are configured on the sites you connect to
  6. Verify that HTTPS/TLS connections are properly established
  7. Review your digital footprint as a whole and keep your online exposure to a minimum

Summary

Browser fingerprinting is a powerful tracking technology that stands in for cookies. Knowing how unique your own browser is makes the first step toward protecting your privacy. Check it right now with the fingerprint uniqueness score on IP Check-san.

Related Glossary Terms

Browser Fingerprint A technique that identifies and tracks users based on unique combinations of bro… WebRTC A browser technology that enables real-time peer-to-peer audio, video, and data … Browser Isolation A security technology that separates web content rendering from the user's endpo… Canvas Fingerprint A browser fingerprinting technique that draws invisible graphics (text, shapes, … CSP (Content Security Policy) An HTTP response header that provides a powerful mechanism for restricting the s…

Frequently Asked Questions

How is browser fingerprinting different from cookies?

Cookies are data stored in your browser that you can delete. A browser fingerprint, by contrast, is an identifier generated from the combination of your browser settings and hardware information, so tracking continues even after you delete your cookies.

Does private browsing (incognito mode) prevent fingerprinting?

No. Private browsing only stops your browser from saving history and cookies. Browser attributes such as screen resolution, fonts, and plugins are exposed exactly the same way as in normal mode.