facebook-pixel

Browser Fingerprinting: How Websites Track You Without Cookies

L
Lunyb Security Team
··10 min read

Every time you visit a website, your browser quietly hands over dozens of technical details about your device. Combined, these details form a nearly unique identifier known as a browser fingerprint—one that can track you across sites even if you block cookies, clear your history, or use private browsing mode.

This guide explains exactly how browser fingerprinting works, what information websites collect, why it's so hard to defeat, and what you can realistically do about it.

What Is Browser Fingerprinting?

Browser fingerprinting is a tracking technique that identifies and follows users by collecting a combination of technical attributes exposed by their browser and device. Unlike cookies, fingerprints are not stored on your device—they are generated on-the-fly by analyzing signals your browser broadcasts to every website you visit.

Research by the Electronic Frontier Foundation (EFF) has shown that the vast majority of browsers produce a fingerprint unique enough to identify a single user out of millions. Even more concerning: fingerprints are stateless, meaning there is no cookie to delete and no simple "opt out" switch.

Fingerprinting vs. Cookies: Key Differences

FeatureCookiesBrowser Fingerprinting
Storage locationSaved on your deviceGenerated from device signals
User can deleteYesNo
Blocked by private modeUsually yesNo
Requires consent (GDPR)YesYes, but rarely enforced
Cross-site trackingLimited by browsersWorks across all sites
User awarenessCookie bannersAlmost invisible

How Browser Fingerprinting Works

Fingerprinting scripts collect small pieces of information—each individually harmless—and combine them into a single hash or ID. Because the combination of hundreds of attributes is statistically unique for most users, that ID reliably identifies you across visits and even across different websites that share tracking networks.

Here is the typical process:

  1. You load a webpage. A tracking script (often from a third-party ad or analytics provider) runs in the background.
  2. The script queries your browser. It uses standard JavaScript APIs to read device attributes.
  3. It performs active tests. These include drawing hidden graphics, playing inaudible audio, and measuring how your device renders them.
  4. Data is hashed. All collected values are combined into a compact fingerprint ID.
  5. The ID is stored server-side. Next time you visit—or visit any partner site—the fingerprint is regenerated and matched.

What Data Is Collected in a Browser Fingerprint?

Modern fingerprinting scripts can gather dozens of attributes. The most common include:

Basic Device and Browser Attributes

  • User agent string: browser name, version, and operating system
  • Screen resolution and color depth
  • Timezone and system language
  • Installed fonts (enumerated via CSS or JavaScript)
  • Browser plugins and extensions (in some browsers)
  • Hardware concurrency (number of CPU cores)
  • Device memory
  • Touch support and pointer type

Advanced Fingerprinting Techniques

Beyond basic attributes, sophisticated trackers use active techniques that produce highly unique signatures:

  • Canvas fingerprinting: The browser is asked to draw an invisible image with specific text and shapes. Tiny differences in GPU, drivers, and rendering libraries produce a unique pixel output.
  • WebGL fingerprinting: Similar to canvas, but uses 3D rendering. Reveals GPU model and rendering behavior.
  • Audio fingerprinting: Generates an inaudible sound and measures how your audio stack processes it.
  • Font enumeration: Detects which fonts are installed, which varies by OS, region, and installed software.
  • Battery status: Historically used to link sessions on the same device (now restricted in most browsers).
  • WebRTC probing: Can expose your local network IP addresses.
  • Media device enumeration: Lists microphones, cameras, and speakers.

Why Fingerprinting Is So Effective

The power of fingerprinting comes from entropy—the amount of uniqueness each attribute contributes. A single attribute like "Windows 11" applies to hundreds of millions of people. But when you combine Windows 11 + Chrome 131 + a 3440x1440 monitor + a specific GPU + a specific font list + a particular timezone, you narrow it down to one person very quickly.

According to studies from the EFF's Panopticlick project (now Cover Your Tracks) and academic research from Mozilla and INRIA, more than 80–90% of desktop browsers have fingerprints that are unique within a large population sample.

Fingerprints Are Also "Stable Enough"

Even when small things change—a browser update, a new font installed—modern trackers use fuzzy matching to link the "new" fingerprint to the old one. This means simply updating your browser rarely breaks tracking.

Who Uses Browser Fingerprinting and Why?

Fingerprinting isn't inherently malicious. It has legitimate uses alongside privacy-invasive ones.

Legitimate Uses

  • Fraud detection: Banks and payment processors use fingerprints to detect account takeover attempts and card fraud.
  • Bot mitigation: Sites like ticket vendors and sneaker drops use fingerprints to block scraping and scalping bots.
  • Account security: Detecting logins from unusual devices.
  • Multi-account abuse prevention: Stopping single users from creating thousands of throwaway accounts.

Privacy-Invasive Uses

  • Cross-site advertising: Building behavioral profiles across every website you visit.
  • Price discrimination: Charging different prices based on device (e.g. Mac users historically shown pricier hotel options).
  • Circumventing cookie consent: Continuing to track users who declined cookies.
  • Data broker enrichment: Selling behavioral data to third parties.

Pros and Cons of Browser Fingerprinting

Pros (from a website operator's perspective)

  • Effective fraud and bot prevention
  • Works without user consent prompts
  • Cannot be cleared like cookies
  • Improves account security

Cons (from a user's perspective)

  • No opt-out mechanism
  • Often invisible and undisclosed
  • Enables tracking despite privacy tools
  • Legally ambiguous under GDPR and CCPA
  • Can enable price discrimination
  • Persists across sessions and profiles

How to Test Your Own Browser Fingerprint

Before you can defend against fingerprinting, it helps to see what your browser leaks. Several free tools show you your fingerprint in detail:

  1. EFF's Cover Your Tracks (coveryourtracks.eff.org) – tests fingerprint uniqueness and tracker blocking.
  2. AmIUnique.org – shows your fingerprint compared to a large database.
  3. BrowserLeaks.com – granular tests for canvas, WebGL, WebRTC, fonts, and more.
  4. CreepJS – advanced fingerprinting demo used by security researchers.

Run these tests on your everyday browser. Most people are shocked to see a message like "Your browser fingerprint appears to be unique among the X million tested in the past 45 days."

How to Reduce Your Browser Fingerprint

You cannot fully eliminate fingerprinting, but you can dramatically reduce the entropy of your fingerprint and make yourself harder to track. Here are the most effective strategies.

1. Use a Privacy-Focused Browser

The single biggest impact comes from choosing a browser that actively fights fingerprinting:

  • Tor Browser: The gold standard. Every Tor user shares an identical fingerprint by design, making individuals indistinguishable.
  • Brave: Uses "farbling"—randomizing small details of canvas and audio output per session and per site, so no stable fingerprint forms.
  • Firefox with resistFingerprinting: Enable privacy.resistFingerprinting in about:config for Tor-like protections.
  • LibreWolf: A hardened Firefox fork with anti-fingerprinting on by default.

2. Block Fingerprinting Scripts

Extensions like uBlock Origin (with the "Fingerprinting" filter list enabled) and Privacy Badger block many known fingerprinting scripts before they run. This is one of the highest-impact, lowest-effort steps you can take.

3. Use Encrypted DNS

While DNS doesn't directly affect fingerprinting, using DNS-over-HTTPS (DoH) or DNS-over-TLS prevents your internet provider from correlating your browsing habits with fingerprint data collected elsewhere. Cloudflare (1.1.1.1), NextDNS, and Quad9 all offer free encrypted DNS.

4. Standardize Your Setup

Fingerprinting relies on uniqueness. The more your setup looks like everyone else's, the better:

  • Avoid installing rare fonts
  • Keep window sizes at common defaults (Tor Browser uses "letterboxing" for this reason)
  • Don't install dozens of exotic browser extensions
  • Keep your browser up to date so you're in the common version pool

5. Disable or Limit JavaScript Where Possible

Most fingerprinting requires JavaScript. Tools like NoScript or the built-in script controls in Brave and Firefox let you disable JavaScript on sites that don't need it, cutting off most fingerprinting at the source.

6. Separate Identities With Browser Profiles or Containers

Firefox Multi-Account Containers and separate browser profiles isolate cookies and site data. While they don't change your fingerprint, they prevent trackers from linking activities across contexts (work, banking, shopping, personal).

Fingerprinting and Link Privacy

Fingerprinting doesn't only happen on the destination website—it can also be triggered by tracking parameters and redirects embedded in links you click. Long tracking URLs with UTM parameters, click IDs, and third-party redirects often load fingerprinting scripts before delivering you to the actual page.

Using a privacy-respecting short link service can help by hiding tracking parameters from casual view, and by not injecting additional third-party trackers into the redirect chain. Tools like Lunyb focus on clean, fast redirects without loading advertising or analytics networks on the interstitial. If you're evaluating link tools, our 2026 buyer's guide to URL shorteners compares the major options on privacy, performance, and features.

The Future of Browser Fingerprinting

The tracking industry and browser vendors are locked in an escalating arms race. Here's what to watch in the next few years:

  • Reduced entropy in APIs: Browsers like Safari, Firefox, and Brave are gradually removing or randomizing high-entropy APIs (device memory, plugin lists, precise timing).
  • User-Agent Client Hints: Chrome is replacing detailed user-agent strings with a more limited hints system that reduces passive fingerprinting.
  • Machine learning fingerprinting: Trackers are increasingly using ML to link fuzzy fingerprints across sessions, even when individual attributes change.
  • Regulatory pressure: European regulators are beginning to treat fingerprinting as consent-required processing under GDPR—expect enforcement actions in coming years.
  • Server-side fingerprinting: Techniques like TLS fingerprinting (JA3/JA4) and HTTP/2 fingerprinting operate below the JavaScript layer, harder to defend against.

Frequently Asked Questions

Can browser fingerprinting identify me personally by name?

Not directly. A fingerprint is a pseudonymous ID—it identifies your device as "the same visitor as before," not your legal identity. However, if you ever log into a site with your real name while carrying that fingerprint, the tracker can link the fingerprint to your identity and then follow you everywhere else.

Does private or incognito mode stop browser fingerprinting?

No. Private browsing modes prevent your browser from saving cookies, history, and cache locally, but they do not change the technical attributes your browser broadcasts. Your fingerprint is essentially identical in normal and private windows unless the browser (like Tor or Brave) specifically randomizes it.

Is browser fingerprinting legal?

It depends on jurisdiction. Under the EU's GDPR and ePrivacy Directive, fingerprinting for tracking purposes generally requires informed user consent, similar to cookies. In practice, enforcement has been inconsistent. In the US, the CCPA and similar state laws treat persistent identifiers—including fingerprints—as personal information subject to disclosure and opt-out rights.

Will using a privacy browser break websites?

Occasionally. Strong anti-fingerprinting measures can break sites that rely on canvas rendering, WebGL, or specific hardware APIs. Most privacy browsers offer per-site toggles so you can loosen protections on sites you trust. For general browsing, banking, and shopping, browsers like Brave and Firefox work smoothly with anti-fingerprinting enabled.

Should I be worried about browser fingerprinting?

It depends on your threat model. For most users, fingerprinting mainly enables targeted advertising and price discrimination—annoying but not dangerous. For journalists, activists, whistleblowers, or anyone in a sensitive situation, fingerprinting can be a serious threat to anonymity and should be actively countered with Tor Browser or a similarly hardened setup.

Conclusion

Browser fingerprinting has quietly become the dominant tracking technology of the modern web. It works despite cookie banners, private modes, and clearing your history—and most users have no idea it's happening. The good news is that awareness plus a few concrete steps (a privacy-focused browser, script blocking, encrypted DNS, and mindful browsing habits) can dramatically reduce how identifiable you are online.

Privacy in 2026 isn't about becoming invisible—that's rarely realistic. It's about raising the cost of tracking you, blending in with the crowd, and choosing tools and services that respect your data by default. If you're building out a broader privacy toolkit, start with your browser, then work outward to your DNS, extensions, and the everyday services—including link shorteners and analytics tools—you rely on.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles