facebook-pixel

Browser Fingerprinting: How Websites Track You Without Cookies

L
Lunyb Security Team
··9 min read

Every time you visit a website, your browser quietly broadcasts dozens of technical details about your device — your screen size, installed fonts, graphics card, time zone, language settings, and much more. Combined, these details form a unique signature known as a browser fingerprint. Unlike cookies, which you can delete, this fingerprint follows you across sessions, incognito windows, and sometimes even different browsers on the same machine.

In this guide, we break down exactly how browser fingerprinting works, which data points matter most, who is using this technology, and what you can realistically do to limit your exposure in 2026.

What Is Browser Fingerprinting?

Browser fingerprinting is a tracking technique that identifies and follows users by collecting a combination of hardware, software, and configuration data points exposed by a web browser. Instead of storing an identifier on your device (like a cookie), the website calculates a fingerprint based on characteristics your browser reveals, then uses that fingerprint to recognize you on future visits.

The term was popularized in 2010 by a study from the Electronic Frontier Foundation, which showed that most browsers were uniquely identifiable even without cookies. Since then, the technique has grown dramatically more sophisticated and is now a core tool in the online advertising, fraud detection, and analytics industries.

Fingerprinting vs. Cookies: The Key Difference

Cookies are small files stored on your device that websites use to remember you. You can see them, block them, and delete them. Fingerprinting is fundamentally different:

  • Stateless: Nothing is stored on your device.
  • Passive: It happens silently, often without any visible notice.
  • Persistent: Clearing cache, cookies, or history does not reset your fingerprint.
  • Cross-session: It works in private/incognito mode too.

How Browser Fingerprinting Actually Works

When your browser loads a page, it exchanges data with the web server through HTTP headers and JavaScript APIs. Tracking scripts collect dozens of these data points, hash them together, and generate a probabilistic identifier. Here is the process in simplified steps:

  1. Data collection: A script runs in the background and queries the browser for information such as screen resolution, user agent, installed plugins, and language.
  2. Active probing: The script performs tests like rendering hidden graphics, generating audio signals, or measuring font metrics to extract hardware-specific quirks.
  3. Hashing: All collected attributes are combined into a single string and run through a hashing algorithm to create a compact identifier.
  4. Matching: The hash is compared against a database. If it matches a previous visitor, you are re-identified. If not, a new profile is created.
  5. Enrichment: Over time, your fingerprint is linked with behavioral data — pages viewed, purchases made, locations visited — building a detailed profile.

The Main Data Points Used in Fingerprinting

Modern fingerprinting libraries collect anywhere from 20 to over 100 attributes. Here are the most important categories and what each one reveals.

1. Device and Hardware Attributes

  • Screen resolution and color depth
  • CPU core count and device memory
  • Touch support and pointer type
  • Battery status (where still exposed)

2. Browser and OS Configuration

  • User agent string (browser name, version, operating system)
  • Installed browser extensions (inferred indirectly)
  • Preferred languages and time zone
  • Do Not Track and other privacy headers

3. Canvas Fingerprinting

The browser is asked to draw a hidden image or text using the HTML5 Canvas API. Tiny differences in your GPU, drivers, and font rendering produce a unique pixel-level output. This is one of the most powerful and widely deployed techniques.

4. WebGL Fingerprinting

Similar to canvas fingerprinting, but using 3D graphics rendering. Your graphics card and driver combination produces reproducible, highly unique results.

5. Audio Fingerprinting

The AudioContext API processes a silent audio signal. The way your system processes that signal depends on your hardware and OS, generating another identifiable value.

6. Font and Plugin Enumeration

Scripts detect which fonts are installed on your system by measuring the dimensions of rendered text. The exact list of fonts is often highly unique.

7. Network and TLS Fingerprinting

Beyond the browser, your network stack also leaks information. TLS handshakes, HTTP/2 settings, and TCP window sizes can all be used to identify a device at the connection level.

Comparison: Common Tracking Methods

MethodStored on Device?User Can Delete?Works in Private Mode?Accuracy
CookiesYesYesLimitedVery high
LocalStorageYesYesLimitedVery high
Browser FingerprintingNoNoYesHigh (80-95%)
IP Address TrackingNoChanges with networkYesModerate
Account LoginServer-sideN/AYesPerfect

Who Uses Browser Fingerprinting?

Fingerprinting is not inherently malicious. It has both legitimate and controversial uses, and the same script can serve multiple purposes simultaneously.

Legitimate Use Cases

  • Fraud prevention: Banks and payment processors use fingerprints to detect account takeovers and suspicious transactions.
  • Bot detection: Fingerprints help distinguish real users from automated scripts and scrapers.
  • Account security: Services flag logins from unfamiliar devices.
  • Rate limiting: Fingerprints prevent abuse of free trials and sign-up forms.

Controversial Use Cases

  • Cross-site advertising: Ad networks build persistent profiles that follow you across unrelated websites.
  • Price discrimination: Some retailers display different prices based on inferred device value and purchase history.
  • Re-identification after cookie deletion: Trackers restore identifiers even after you clear cookies, defeating user choice.
  • Shadow profiling: Profiles are built on people who never consented and have no account with the collecting company.

How Unique Is Your Fingerprint?

Research consistently shows that the majority of browsers are either unique or part of a very small group. The EFF's Panopticlick (now Cover Your Tracks) study found that around 80-90% of desktop browsers tested had a globally unique fingerprint. Even on mobile, where devices are more standardized, fingerprints remain highly distinctive when combined with behavioral signals.

You can test your own browser using free tools like Cover Your Tracks (EFF), AmIUnique.org, or CreepJS. The results are usually eye-opening.

Can You Prevent Browser Fingerprinting?

Completely eliminating fingerprinting is extremely difficult because the same features that make the web interactive also expose device information. However, you can meaningfully reduce your fingerprint uniqueness with a layered approach.

1. Use a Privacy-Focused Browser

Some browsers actively fight fingerprinting by standardizing or randomizing exposed values:

  • Tor Browser: The gold standard. All Tor users are designed to look identical to each other.
  • Brave: Includes built-in fingerprinting randomization and script blocking.
  • Firefox: Offers Resist Fingerprinting mode and Enhanced Tracking Protection.
  • LibreWolf: A hardened Firefox fork with aggressive anti-tracking defaults.

2. Install Script-Blocking Extensions

Extensions like uBlock Origin, NoScript, and Privacy Badger block many known fingerprinting scripts before they can execute. Blocking third-party JavaScript is one of the most effective single defenses.

3. Disable Unnecessary APIs

Advanced users can disable or restrict high-entropy APIs like WebGL, WebRTC, and the AudioContext through browser settings or extensions. Be aware that this may break certain websites.

4. Keep Your Browser and OS Updated — But Standard

Counterintuitively, running a heavily customized browser with rare extensions and settings can make you more unique, not less. A stock, up-to-date mainstream browser blends in better with the crowd.

5. Use Encrypted DNS and Private Browsing Modes

Encrypted DNS (DoH or DoT) prevents your network provider from logging the domains you visit. Combined with private browsing modes, this reduces the amount of behavioral data that can be correlated with your fingerprint.

6. Be Mindful of What You Share

Fingerprinting is only one piece of the tracking puzzle. The links you click, the shortened URLs you share, and the services you sign up for all feed data into profiling systems. Using a privacy-respecting URL shortener like Lunyb helps limit how much metadata trackers can collect from the links you distribute. For a broader look at shortener options, see our 2026 shortener buyer's guide.

Pros and Cons of Anti-Fingerprinting Measures

Pros

  • Significantly reduces cross-site tracking
  • Limits ad targeting and price discrimination
  • Improves overall browsing privacy
  • Reduces data available in case of breaches

Cons

  • Can break website functionality (CAPTCHAs, video players, logins)
  • Some sites flag anti-fingerprinting users as bots
  • Requires ongoing maintenance as techniques evolve
  • Over-customization can backfire and increase uniqueness

The Future of Browser Fingerprinting

As major browsers phase out third-party cookies, the advertising industry is leaning harder on fingerprinting and server-side tracking. At the same time, browser vendors are introducing countermeasures:

  • Client Hints: Replacing the verbose user-agent string with structured, limited data.
  • Privacy Budget proposals: Capping how much identifying information a site can request.
  • Partitioned storage: Isolating data per top-level site to prevent cross-site linking.
  • Fingerprint randomization: Returning slightly different values on each visit.

Regulations like the GDPR, CCPA, and newer frameworks in Brazil, India, and the UK increasingly treat fingerprints as personal data, requiring consent for non-essential tracking. Enforcement, however, remains inconsistent.

Practical Checklist: Reduce Your Fingerprint Today

  1. Switch to a privacy-focused browser (Brave, Firefox, or Tor Browser for sensitive sessions).
  2. Install uBlock Origin and keep its filter lists updated.
  3. Enable Resist Fingerprinting or equivalent anti-tracking mode.
  4. Use encrypted DNS at the system or browser level.
  5. Avoid installing rare browser extensions that make you more unique.
  6. Test your fingerprint quarterly using Cover Your Tracks or AmIUnique.
  7. Compartmentalize activities across different browsers or profiles.
  8. Prefer privacy-respecting tools and services for sharing links and files.

Frequently Asked Questions

Does incognito or private browsing mode stop fingerprinting?

No. Private browsing modes prevent your browser from storing history, cookies, and cache locally, but they do not change the data your browser exposes to websites. Fingerprinting works just as effectively in private mode as in regular mode.

Can clearing my cookies reset my browser fingerprint?

No. Your fingerprint is calculated from hardware and software characteristics that do not change when you clear cookies, cache, or history. Resetting your fingerprint would require changing your device, operating system, browser, or multiple configuration settings.

Is browser fingerprinting legal?

It depends on jurisdiction and purpose. In regions covered by the GDPR, UK GDPR, or similar laws, fingerprinting for non-essential purposes typically requires informed consent. Fingerprinting for legitimate fraud prevention is usually permitted under other legal bases. Enforcement varies widely, and many websites deploy fingerprinting without clear disclosure.

Will using a privacy browser break websites?Occasionally, yes. Aggressive anti-fingerprinting settings can interfere with video streaming, online banking, CAPTCHAs, and interactive web apps. Most privacy browsers let you create per-site exceptions, so you can relax protections only where strictly necessary.

Is there any way to be completely anonymous online?

True anonymity is extremely difficult to achieve and maintain. The closest practical approach is using Tor Browser on a dedicated device, over a network you do not control, with no logins to personal accounts. For most users, the realistic goal is minimizing tracking and compartmentalizing identities rather than achieving perfect anonymity.

Final Thoughts

Browser fingerprinting is one of the most persistent and least understood forms of online tracking. Because it operates silently and cannot be deleted like a cookie, it has become the backbone of modern cross-site profiling. The good news is that you are not powerless: a combination of a well-chosen browser, script blockers, careful configuration, and privacy-aware tools can dramatically shrink the data that follows you around the web.

Privacy is a layered discipline. Pay attention not just to how you browse, but to what you share and the services you rely on. Small, consistent choices — from your browser settings to the links you shorten — add up to a much smaller digital shadow.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles