Glowing cyan, magenta and violet contour lines curling into an abstract fingerprint whorl on the right of a dark background, with soft particles of light drifting around it.

Browser Fingerprinting:What Is a Browser Fingerprint and How Does It Work?

2026-10-10•root

Introduction

What is a browser fingerprint? It is a profile a website builds from the details your browser reveals about itself and your device, and it lets the site recognize you on a later visit without storing anything on your computer. Clearing cookies does not remove it, because nothing was stored in the first place. The site measures your browser again and gets the same answer.

Browser fingerprinting has three common users. Fraud-prevention systems notice a correct password typed on an unfamiliar device, bot detection catches software that pretends to be a browser, and advertising and analytics scripts follow people across sites when cookies are blocked. All three read the same signals, so a browser that hides them has to do it without breaking the first two.


What Is a Browser Fingerprint?

A browser fingerprint is a set of values that a website reads from your browser (its version, language, time zone, screen size, graphics hardware, the exact pixels it produces when it draws an image) and combines into one identifier. Each value is shared by a great many people. The combination is much rarer and stays the same from visit to visit, so it works like an ID the browser hands out whenever a page asks. The W3C Privacy Working Group defines browser fingerprinting as "the capability of a site to identify or re-identify a visiting user, user agent, or device".

Browser fingerprint or device fingerprint?

Device fingerprinting is the wider term. The EU's Article 29 Working Party used it in 2014 for any information that can "single out, link or infer a user, user agent or device over time", including data from apps, smart TVs and network protocols. A browser fingerprint is the part a website collects through the browser, and in practice the two terms are often used interchangeably.


How Does Browser Fingerprinting Work?

Passive and active fingerprinting

The W3C guidance separates two kinds. Passive fingerprinting uses what the browser sends anyway: the IP address and request headers such as the User-Agent and preferred languages. Active fingerprinting runs a script that asks for more, such as the window size or the available fonts. Because it runs as code on your machine, it is "potentially detectable on the client", and browsers can change what the script gets back.

What goes into a browser fingerprint

SignalHow a site reads itWhat it reveals
User-Agent and Client HintsRequest headers and JavaScriptBrowser, version and OS. Chromium browsers also give the full build, CPU architecture and device model on request.
ScreenJavaScriptResolution, space left by the taskbar or dock, color depth, pixel density.
Time zone and languagesJavaScript and request headersRegion and language setup, and any mismatch with the IP address.
FontsMeasuring how text rendersInstalled fonts, which reflect the system and its software.
CanvasA hidden drawing, read back and hashedThe rendering stack: operating system, browser, font engine and graphics driver.
WebGLThe 3D graphics interfaceA renderer string that often names the graphics card.
AudioThe Web Audio API, with nothing played aloudSmall differences in how the audio stack processes a signal.
Speech voicesThe Speech Synthesis APIInstalled voices, which depend on the OS and language packs.
HardwareJavaScriptCPU core count, approximate memory (Chromium only) and the number of touch points.

None of these values is secret. A site needs the screen size to lay out the page and the language to pick a translation, and fingerprinting reuses them. The User-Agent is the only one that is easy to edit, so sites compare it with Client Hints, the platform and touch support, which is how a switcher gets caught (User-Agent spoofing).

Below the browser: TLS and TCP fingerprints

Two more fingerprints come from the connection. The first TLS message of an encrypted connection lists the cipher suites and extensions the client supports, and JA4 turns that list into a short string (TLS fingerprinting with JA3 and JA4). One layer lower, the first TCP packet carries values set by the operating system's network stack, which point to the OS family whatever the browser claims (passive OS fingerprinting). Neither belongs to the browser fingerprint in the strict sense, and no browser setting changes them, but sites compare them with it: Safari on an iPhone should not have the TLS handshake of a scripting library.


Canvas Fingerprinting and Other Rendering Techniques

The strongest browser signals come from making the browser produce something and measuring the result. In canvas fingerprinting, the best known of these techniques, a script draws text, emoji and shapes on a hidden canvas, reads the pixels back and hashes them. The pixels depend on the operating system, font engine, graphics driver and GPU, so one computer produces the same hash on every visit and a different setup usually does not. Canvas fingerprinting test covers the details and each browser's defenses.

WebGL does the same for 3D graphics and also reports a renderer string that often names the graphics card. Audio fingerprinting runs a short signal through the Web Audio API, with nothing played aloud, and measures the output. The list of speech-synthesis voices depends on the operating system and language packs (audio and voice fingerprinting covers both). Clearing cookies or switching on a VPN changes none of this. Ordinary sites need the same interfaces, so a browser cannot simply switch them off and changes the output instead.


Uniqueness Versus Stability

A fingerprint is useful to a tracker only if it is both distinctive and stable.

Distinctive means few other browsers share it. English as the browser language narrows the crowd a little, an unusual screen size or a long list of extra fonts narrows it a lot, and a browser that is ordinary in every respect can still be the only one with that exact combination.

Stable means it stays the same between visits. Some values change on their own, such as the browser version after an update or the time zone when you travel, but a tracker does not need a perfect match. In EFF's original Panopticlick study, Peter Eckersley found that even a simple heuristic could usually tell when a changed fingerprint was an "upgraded" version of one seen before.

A single visit to a test page cannot tell you how unique you are, because that takes data about everyone else, and test sites estimate it from their own self-selected visitors. A value that changes on every visit is useless for tracking however rare it is, and randomization is built on that.


What Is Browser Fingerprinting Used For?

Fraud prevention and account security

Banks, shops and login systems compare the device in front of them with the one they saw last time, so a correct password from an unfamiliar fingerprint can trigger a second check.

Bot detection

Automated browsers and anti-detect tools have to imitate a real browser's fingerprint, and the imitation tends to be inconsistent: an operating system that the TCP packets contradict, a graphics card that does not fit the device, replaced browser functions. Here a site only needs to see whether the parts agree (fake browser detection).

Advertising and tracking without cookies

A script embedded on many sites computes the same fingerprint on each of them, so it can link visits when third-party cookies are blocked or deleted. The Article 29 Working Party described this in 2014 as a way "to follow users across websites and over time", "even if the user declines cookies". In December 2024 Google said that from 16 February 2025 it would no longer prohibit organizations using its advertising products from fingerprinting.


Browser Fingerprint Test: How to Check Your Browser

A browser fingerprint test runs the same scripts a tracker would and shows what they found. EFF's Cover Your Tracks, AmIUnique and BrowserLeaks are the best known, and the first two also estimate how rare your fingerprint is among their own visitors.

To check your browser fingerprint as a tracker sees it and as a fraud system judges it, the Privacy & Trust Index on packet.guru gives two scores, Privacy (how hidden you are) and Trust (how genuine you look), built from cards that explain their result:

  • The Browser Uniqueness group (Canvas Fingerprint, Audio Fingerprint, Speech Voices) shows whether your browser hands out a stable value, a changing one, or none.
  • The Integrity & Anti-Spoof group checks whether the parts agree. Device Integrity compares the User-Agent with Client Hints, platform and touch support and looks for automation, Regional Integrity compares your time zone and languages with your IP location, Tamper Detection looks for replaced browser functions, and TLS / JA4 Fingerprint and TCP/OS Fingerprint compare your connection with what the browser claims.
  • The Network Identity group covers what your connection exposes: WebRTC Status, DNS Privacy, IP Reputation and ECH Status.

Below the cards, panels list what your browser declares (operating system, language, screen, CPU cores, device memory, touch points), the WebGL renderer, the canvas and audio hashes, your speech voices and your connection's JA4, JA3, HTTP/2 and TCP values, all of it exportable as raw JSON.

The scan prints no uniqueness percentage, for the reason given above. To see whether your protection works, run it, restart the browser or open a private window, and run it again: values that change between sessions are randomized, and values that stay the same can be used to recognize you.


How to Prevent Browser Fingerprinting

Fingerprinting cannot be avoided entirely, since pages need many of the same values to work, but a browser can make them less useful.

Standardization or randomization

Standardization makes many browsers report the same values, so a fingerprint points to a large group instead of one person. The W3C guidance prefers it, because it "provides the benefit of an increased anonymity set". Tor Browser is the clearest example. Randomization adds small, deliberate variation to values such as canvas pixels, so the fingerprint differs from site to site and session to session. Brave is built around it. A third approach, blocking scripts from known fingerprinting companies by list, is used by Firefox, Safari and Chrome's Incognito mode.

Why more extensions can make you easier to track

Every extension that changes what a page sees is a trait of its own, and so is a spoofed User-Agent. Eckersley called this the paradox of privacy tools: measures meant to make a device harder to fingerprint "are themselves distinctive unless a lot of other people also take them". EFF's current advice agrees that "an add-on intended to protect you can even lead to your full identification". Changing one value and not the rest also creates contradictions, such as a Windows User-Agent over a Mac's graphics stack, which bot detection reads as forgery.

In practice: use a browser with built-in protection and keep its defaults, add as few fingerprint-changing extensions as possible, use private windows in Firefox and Safari where the stronger protection is on, and when a site breaks, turn the protection off for that site only.


Anti-Fingerprinting Browsers: Firefox, Brave, Safari and Tor Browser

Each of these browsers has some anti-fingerprinting protection, with different methods and defaults.

Firefox

Firefox has blocked third-party requests to companies known to fingerprint since Firefox 72 (January 2020), using Disconnect's lists. Its Fingerprinting Protection is aimed at scripts that are on no list: Firefox 145 (November 2025) extended it to values such as CPU core count, touch points, taskbar or dock size and installed fonts in private windows and Strict mode, and Firefox 151 (May 2026) brought part of it to the default Standard mode. Mozilla does not go further because more aggressive blocking "is guaranteed to break legitimate website features".

The older privacy.resistFingerprinting preference came from Mozilla's Tor Uplift project and aims at Tor Browser's level of resistance: it reports UTC as the time zone, rounds the window size, limits WebGL and blocks canvas extraction. It hides more, and since few Firefox users turn it on, the setting can itself make a browser stand out. A UTC clock behind an IP address in another region can also look like a time-zone mismatch.

Brave

Brave calls its method farbling: "slightly randomizing the output of semi-identifying browser features", including canvas, WebGL and Web Audio readback. The seed changes per session, per site and per storage area, and embedded scripts get the seed of the site they run on, so one tracker sees a different browser on each site. Fingerprinting scripts usually "hash together a large number of semi-identifiers into a single identifier", so randomizing one value changes the whole hash.

Safari

Safari 17 added Advanced Fingerprinting Protection to Private Browsing, and it can be switched on for all browsing. It adds small amounts of noise to 2D canvas, WebGL and Web Audio readback and reports the window size in place of the screen size. Safari 26 added a second layer: known fingerprinting scripts can no longer reliably read screen dimensions, hardware concurrency, the speech voice list, Apple Pay capabilities, web audio readback or 2D canvas, and cannot set long-lived cookies or local storage.

Tor Browser

Tor Browser goes furthest with standardization. Its documentation admits that it is "practically impossible to make all Tor Browser users identical", so the goal is fewer distinguishable groups for each trait, and it does not let users pick which operating system to appear as, because "any option to choose would only make users more unique".

Chrome

Chrome neither randomizes nor standardizes these values. Incognito blocks scripts from domains on Google's Masked Domain List in third-party contexts, and any script that does run reads the real values.


FAQ

The technique itself is not banned. In the EU and the UK regulators treat it much like cookies, so tracking people this way for advertising generally needs their consent.

Browser fingerprinting vs cookies: what is the difference?

A cookie is a value a site stores in your browser, and you can see, block and delete it. A fingerprint is computed from what your browser reveals on each visit, so there is nothing to delete, and the W3C guidance notes that it can get around attempts to limit or clear cookies.

Does a VPN hide your browser fingerprint?

No. A VPN changes the IP address sites see, while your screen, fonts, canvas pixels, time zone and languages stay the same, and the W3C guidance states that using a VPN does not prevent further correlation. It can even add a contradiction, such as a time zone that does not fit the server's country, and WebRTC can reveal your real address behind it (WebRTC leaks).

Does incognito mode stop browser fingerprinting?

Not on its own, since private browsing was designed to leave fewer traces on your own device. Firefox and Safari switch on stronger fingerprinting protection in private windows. Chrome's Incognito blocks listed fingerprinting scripts in third-party contexts but does not change the values a script reads.

What is a browser fingerprinting attempt?

It is the wording some antivirus suites, anti-tracking extensions and browsers use when they block or flag a script that collects fingerprinting signals, such as a request to a known fingerprinting domain. A count of blocked attempts means the protection acted on that page. It does not mean the site identified you or that your device is infected.


Sources


System Alert

Does your browser look the same to every site it visits?

Run the Privacy & Trust Index check to see which parts of your fingerprint are stable, which change between sessions, and whether they agree with each other.