facebook-pixel

Browser Fingerprinting: How Websites Track You Without Cookies

L
Lunyb Security Team
··9 min read

You clear your cookies, switch to private browsing, and maybe even change networks — yet advertisers and analytics platforms still seem to know exactly who you are. The reason is browser fingerprinting, a stealthy tracking technique that identifies you based on the unique characteristics of your device and browser rather than data stored on your machine.

Unlike cookies, fingerprints can't be deleted from a settings menu. They're reconstructed every time you load a page. In this guide, we'll break down exactly how browser fingerprinting works, why it's so effective, what data it collects, and the realistic steps you can take to reduce your exposure.

What Is Browser Fingerprinting?

Browser fingerprinting is a tracking technique that collects dozens or hundreds of attributes about your browser, operating system, and hardware to build a unique identifier — a "fingerprint" — that can distinguish you from other users without storing anything on your device.

The Electronic Frontier Foundation's Panopticlick project (now Cover Your Tracks) demonstrated that most browsers reveal enough information to be uniquely identified among millions of users. When properly combined, attributes like screen resolution, installed fonts, time zone, and GPU rendering behavior create a signature that's often as identifiable as a name.

Fingerprinting vs. Cookies: The Key Difference

Cookies are small files that a website places on your device. You can view them, delete them, or block them entirely. Fingerprinting flips this model: instead of putting something on your device, the website reads what's already there. There's nothing to delete, and blocking the collection often breaks the site.

How Browser Fingerprinting Works

When you visit a website, your browser silently transmits or exposes a huge amount of technical information. Fingerprinting scripts collect these attributes using standard web APIs, hash them together, and store the resulting identifier on the server side.

  1. Data collection: JavaScript running on the page queries dozens of browser APIs to read device properties.
  2. Attribute combination: The values are concatenated or normalized into a single string.
  3. Hashing: A hash function (often SHA-256) turns that string into a compact fingerprint ID.
  4. Server storage: The fingerprint is stored alongside behavioral data — pages visited, purchases, ad clicks.
  5. Cross-site matching: When the same fingerprint appears on another site using the same tracking network, your activity is linked across domains.

What Data Is Collected in a Browser Fingerprint?

The list of signals is longer than most users realize. Below are the main categories that modern fingerprinting libraries collect.

Basic Browser and System Attributes

  • User-Agent string (browser name, version, OS)
  • Screen resolution and color depth
  • Time zone and system language
  • Preferred languages sent via HTTP headers
  • Do Not Track setting
  • Cookie and local storage support flags

Hardware Signals

  • CPU core count (via navigator.hardwareConcurrency)
  • Device memory (via navigator.deviceMemory)
  • Touchscreen support and maximum touch points
  • Battery level and charging state (in some browsers)
  • Connected media devices (microphones, cameras — count only)

Advanced Fingerprinting Techniques

The most powerful signals come from indirect measurements that reveal how your hardware and software render content.

  • Canvas fingerprinting: A hidden HTML5 canvas draws text and shapes. Tiny differences in font rendering, anti-aliasing, and GPU acceleration produce a unique image hash.
  • WebGL fingerprinting: Reads your graphics card vendor, renderer, and how it draws 3D shapes.
  • AudioContext fingerprinting: Generates an audio signal and measures how your device's audio stack processes it.
  • Font enumeration: Detects which fonts are installed by measuring the width of rendered text.
  • Media queries: Detects dark mode preference, reduced motion settings, and monitor refresh rate.

Types of Browser Fingerprinting

Not every fingerprint is created equal. Understanding the categories helps clarify which defenses actually work.

Type How It Works Uniqueness Difficulty to Block
Passive fingerprinting Reads HTTP headers sent automatically Low to medium Easy (change headers)
Active fingerprinting Runs JavaScript to probe APIs High Medium (block scripts)
Canvas fingerprinting Renders images and hashes pixels Very high Hard (breaks legit features)
Behavioral fingerprinting Tracks mouse, typing, scroll patterns Extremely high Very hard
Cross-browser fingerprinting Uses hardware signals that persist across browsers High Very hard

Why Websites Use Browser Fingerprinting

Fingerprinting isn't only used for advertising. It has both legitimate and invasive applications, which is part of why it's so hard to eliminate entirely.

Legitimate Uses

  • Fraud detection: Banks and payment processors use fingerprints to flag suspicious logins from unfamiliar devices.
  • Bot mitigation: Distinguishing real users from automated scrapers and credential-stuffing bots.
  • Account security: Alerting users when a new device signs into their account.
  • License enforcement: Preventing shared accounts on paid services.

Invasive Uses

  • Cross-site advertising: Building long-term profiles that follow you across the web without consent.
  • Price discrimination: Showing different prices based on your device or perceived income bracket.
  • Circumventing consent choices: Continuing to track users who rejected cookies.
  • Data broker enrichment: Merging browsing behavior with offline data for resale.

How Unique Is Your Browser Fingerprint?

Research from the EFF found that roughly 1 in 3 browsers has a fingerprint that is completely unique across a sample of millions. A 2020 study by INRIA showed that even mobile browsers — which were once considered more homogeneous — now carry enough distinguishing signals to be tracked reliably.

You can test your own browser at coveryourtracks.eff.org or amiunique.org. The results are often eye-opening: even a plain Chrome install with no extensions typically produces a fingerprint shared by fewer than 0.01% of visitors.

How to Reduce Your Browser Fingerprint

There is no perfect defense, but you can dramatically shrink your exposure by choosing tools designed with fingerprint resistance in mind and by changing a few habits.

1. Use a Fingerprint-Resistant Browser

Some browsers actively fight fingerprinting by standardizing what scripts can see or by randomizing outputs on every visit.

  • Tor Browser: The gold standard. Every Tor user reports identical values for most attributes, so blending into the crowd is automatic.
  • Brave: Randomizes canvas, WebGL, and audio outputs slightly on each session, defeating hash-based tracking.
  • Firefox with resistFingerprinting: Set privacy.resistFingerprinting to true in about:config for Tor-like protections.
  • LibreWolf: A Firefox fork with hardening enabled by default.

2. Block Fingerprinting Scripts

Extensions like uBlock Origin (with the "Fanboy's Anti-Facebook" and privacy filter lists enabled), Privacy Badger, and NoScript can prevent known fingerprinting libraries from running. Blocking scripts entirely on untrusted sites is the single most effective step.

3. Disable or Limit JavaScript Where Possible

Most advanced fingerprinting requires JavaScript. Browsers like Tor let you set a global security level that disables JS on non-HTTPS sites or across the board. This breaks many sites but eliminates a huge attack surface.

4. Use Encrypted DNS and Reputable Networks

Encrypted DNS (DNS over HTTPS or DNS over TLS) prevents your resolver from logging every domain you visit. Combined with a trustworthy network, this reduces the amount of metadata third parties can correlate with your fingerprint.

5. Avoid Rare Extensions and Fonts

Ironically, installing many privacy extensions can make you more unique. Stick to widely used tools. Similarly, avoid installing exotic system fonts that few other users have.

6. Compartmentalize Your Browsing

Use different browsers for different activities: one for logged-in accounts, one for research, one for shopping. Container extensions like Firefox Multi-Account Containers isolate cookies and storage per tab, limiting cross-site correlation.

7. Be Careful With Shortened and Redirect Links

Some tracking networks use redirect chains to inject fingerprinting scripts before you arrive at your destination. When you need to share a link that respects privacy, use a shortener that doesn't inject third-party trackers. Services like Lunyb focus on clean, privacy-conscious redirects — see our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners.

What Browser Fingerprinting Looks Like in Practice

Here's a simplified example of the kind of object a fingerprinting script might produce for a typical desktop user:

{
  "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...",
  "screen": "1920x1080x24",
  "timezone": "America/Chicago",
  "languages": ["en-US", "en"],
  "cores": 8,
  "memory": 16,
  "canvasHash": "a3f9c1e2...",
  "webglVendor": "NVIDIA Corporation",
  "webglRenderer": "GeForce RTX 3060/PCIe/SSE2",
  "fonts": ["Arial", "Calibri", "Consolas", ...],
  "audioHash": "124.04347527516074"
}

Hashed together, that object produces a stable ID that persists across cookie deletions, private-mode sessions, and often even network changes.

The Future of Browser Fingerprinting

As third-party cookies are phased out by Chrome, Safari, and Firefox, fingerprinting is filling the vacuum. The advertising industry has strong economic incentives to keep tracking working, and browser vendors are responding with new APIs and privacy budgets.

Emerging Defenses

  • Privacy budgets: Proposed by Google, these would limit how many fingerprinting-relevant APIs a site can query per session.
  • State partitioning: Firefox and Safari now partition storage and caches per top-level site, breaking cross-site correlation.
  • Client Hints: A replacement for the User-Agent header that gives sites less default information.
  • API deprecation: Battery Status API and some sensor APIs have been restricted or removed due to fingerprinting abuse.

Emerging Threats

  • Machine-learning fingerprints: ML models can identify users from noisy or partial signals, defeating simple randomization.
  • Behavioral biometrics: Typing rhythm and mouse dynamics create fingerprints that don't rely on device attributes at all.
  • Server-side fingerprinting: TLS handshake analysis (JA3/JA4) fingerprints your browser at the network level, before any JavaScript runs.

Frequently Asked Questions

Can browser fingerprinting identify me personally?

By itself, a fingerprint is just a random-looking hash. It becomes personally identifying the moment you log into any site while carrying that fingerprint — the tracker can then link the hash to your account and, by extension, to everything else you do with the same browser.

Does private or incognito mode stop fingerprinting?

No. Private browsing prevents cookies, history, and local storage from persisting, but it doesn't change any of the attributes fingerprinting relies on. Your screen resolution, fonts, GPU, and canvas hash are the same in incognito as in a normal window.

Is browser fingerprinting legal?

It depends on jurisdiction. Under the EU's GDPR and ePrivacy Directive, fingerprinting for tracking purposes generally requires the same informed consent as cookies. Many sites are non-compliant. In the US, California's CCPA/CPRA gives consumers the right to opt out of the sale or sharing of such data, but enforcement is uneven.

Will disabling JavaScript fully protect me?

It blocks most active fingerprinting techniques, including canvas, WebGL, and audio methods. However, passive fingerprinting based on HTTP headers and TLS handshakes still works. Disabling JS also breaks a large portion of the modern web, so it's a trade-off.

What's the single most effective step I can take today?

Switch to a browser that actively resists fingerprinting — Tor Browser for maximum protection, or Brave and hardened Firefox for a balance between privacy and usability. Combined with uBlock Origin and a habit of avoiding sketchy redirect chains, you'll cut your exposure dramatically without sacrificing daily browsing.

Final Thoughts

Browser fingerprinting is one of the most quietly powerful tracking techniques on the modern web. It bypasses the consent tools most users rely on and grows more sophisticated as regulators crack down on cookies. The good news is that awareness is the first defense: once you know which signals leak and which tools can suppress them, you can make deliberate choices about which sites to trust and which browser to open when privacy matters.

You don't need to disappear entirely. You just need to look enough like everyone else that trackers can't tell you apart — and to route your traffic and links through services that respect that goal.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles