facebook-pixel

Browser Fingerprinting: How Websites Track You Without Cookies

L
Lunyb Security Team
··9 min read

Every time you visit a website, your browser quietly broadcasts dozens of technical details about your device — your screen size, installed fonts, graphics card, time zone, language settings, and much more. Combined, these details form a nearly unique signature called a browser fingerprint. Unlike cookies, you can't delete it, and most people have no idea it exists.

In this guide, we'll break down exactly how browser fingerprinting works, why it has become the tracking method of choice for advertisers and data brokers, and what you can realistically do to reduce your exposure.

What Is Browser Fingerprinting?

Browser fingerprinting is a tracking technique that identifies and re-identifies users by collecting a combination of device, browser, and network attributes that, taken together, form a unique or near-unique profile. Instead of storing an identifier on your device (like a cookie), the website builds the identifier from characteristics your browser already reveals.

According to research from the Electronic Frontier Foundation's Panopticlick project (now called Cover Your Tracks), the average browser leaks enough information to be uniquely identified among millions of other users — often with 90%+ accuracy, even without any cookies at all.

Why Fingerprinting Replaced Cookies

As browsers added stronger cookie controls, Intelligent Tracking Prevention (Safari), and third-party cookie blocking (Firefox and Chrome), advertisers needed a tracking method that users couldn't easily reset. Fingerprinting fit the bill because:

  1. It's stateless. Nothing is stored on your device, so there's nothing to delete.
  2. It's silent. No permission prompt is required to read most fingerprinting signals.
  3. It's persistent. Private browsing windows and cleared caches don't change your underlying hardware or OS.
  4. It works across sites. Trackers embedded on multiple websites can link your activity without any shared cookie.

How Browser Fingerprinting Actually Works

When your browser loads a webpage, it executes JavaScript that can query dozens of APIs. Each API returns a small piece of information. On its own, each piece seems harmless — but combined, they form a highly specific identifier.

Common Fingerprinting Signals

SignalWhat It RevealsUniqueness
User-Agent stringBrowser name, version, OSLow
Screen resolution & color depthMonitor configurationMedium
Installed fontsSoftware ecosystem on deviceHigh
Canvas fingerprintGPU + driver rendering quirksVery high
WebGL fingerprintGraphics card model & driverVery high
AudioContext fingerprintAudio stack processing differencesHigh
Time zone & languageApproximate location, localeLow–Medium
Browser plugins & extensionsInstalled softwareMedium–High
Hardware concurrencyNumber of CPU coresMedium
Battery status (older APIs)Device power profileLow

Canvas Fingerprinting Explained

Canvas fingerprinting is one of the most powerful techniques. A script instructs your browser to draw a hidden image or text to an HTML5 canvas element. Because of subtle differences in your GPU, drivers, operating system, and installed fonts, the rendered pixels will differ slightly between devices — even between two identical phone models. The script then hashes those pixels into a signature.

Two users on the same model of laptop, with the same browser version, will usually produce distinguishable canvas hashes within milliseconds of loading a page.

WebGL and Audio Fingerprinting

WebGL fingerprinting works similarly to canvas, but exploits 3D rendering. The browser renders a complex 3D scene and the slight differences in how different graphics cards and drivers handle shading, anti-aliasing, and precision produce a unique hash.

Audio fingerprinting uses the Web Audio API to generate a sound signal, process it through the browser's audio stack, and measure the output. Different hardware and software combinations produce measurably different waveforms.

Who Uses Browser Fingerprinting?

Fingerprinting isn't just a shady advertising trick. It's used across a surprisingly wide range of industries, some for legitimate security reasons.

Advertising and Analytics Networks

Ad tech companies use fingerprinting to build cross-site behavioral profiles even when users have blocked third-party cookies. This feeds targeted advertising, retargeting campaigns, and audience segmentation.

Fraud Prevention and Banking

Banks, payment processors, and e-commerce platforms use device fingerprinting to detect account takeover attempts. If someone logs into your bank account from a device with a completely different fingerprint than usual, the bank can trigger additional verification. This is one of the few genuinely user-protective uses of the technology.

Bot Detection

Services like Cloudflare, Akamai, and PerimeterX use fingerprinting to distinguish real browsers from automated scripts. Headless browsers often have detectable anomalies in their fingerprints.

Data Brokers

Some data brokers combine fingerprints with other identifiers (email hashes, IP addresses, loyalty program data) to maintain cross-device profiles that get sold to advertisers, insurers, and sometimes even employers.

How Unique Is Your Fingerprint?

You can test your own fingerprint using free tools like:

  • Cover Your Tracks (coveryourtracks.eff.org) — maintained by the EFF, this tool simulates a tracker and tells you how identifiable you are.
  • AmIUnique (amiunique.org) — a research project that compares your fingerprint to a database of millions.
  • BrowserLeaks (browserleaks.com) — shows the raw data your browser exposes across many APIs.

Most users discover they are either "unique" or "nearly unique" within the sample. Ironically, the more customizations you've added (unusual fonts, rare extensions, non-standard screen resolutions), the easier you are to fingerprint.

How to Reduce Browser Fingerprinting

The uncomfortable truth is that you cannot completely eliminate fingerprinting without making your browser nearly unusable. But you can meaningfully reduce your exposure with a layered approach.

1. Use a Browser Designed for Fingerprint Resistance

Some browsers actively fight fingerprinting:

  • Tor Browser — the gold standard. It makes every user look identical by locking down screen size, fonts, and APIs. The trade-off is slower browsing and site compatibility issues.
  • Mullvad Browser — a desktop browser built on the Tor Browser codebase but without the Tor network, suitable for everyday use.
  • Brave — includes "farbling," which randomizes certain fingerprinting signals on each visit to break tracking continuity.
  • Firefox — has built-in fingerprinting protection that can be enabled by setting privacy.resistFingerprinting to true.

2. Block Fingerprinting Scripts

Content blockers like uBlock Origin, Privacy Badger, and NoScript can block known fingerprinting scripts before they load. uBlock Origin's filter lists include a dedicated anti-fingerprinting list that catches most known trackers.

3. Avoid Unnecessary Browser Customization

Counterintuitively, having lots of extensions, custom fonts, or an unusual screen size makes you more identifiable, not less. For maximum anonymity, use a default browser configuration — the same one millions of other users have.

4. Keep Your Browser Updated

Browser vendors are gradually locking down the most abusive fingerprinting APIs. Safari now blocks or truncates many signals, and Firefox's Enhanced Tracking Protection is improving each release. Running an up-to-date browser benefits from these mitigations.

5. Separate Browsing Contexts

Use different browsers or browser profiles for different activities — one for banking and work, another for shopping, another for casual browsing. This limits how much any single tracker can link together.

6. Use Private DNS and Network-Level Protections

Encrypted DNS (DNS over HTTPS or DNS over TLS) through providers like Cloudflare 1.1.1.1, NextDNS, or Quad9 can block connections to known tracking domains at the network level, before scripts even load. Pi-hole on a home network does the same across every device.

Fingerprinting and Shortened Links

Any time you click a link, the destination site can fingerprint you. This matters even for shortened URLs — but the shortening service itself can be either a privacy risk or a privacy asset depending on how it handles data.

Privacy-respecting link shorteners like Lunyb focus on minimal data collection and transparent redirects, rather than injecting their own tracking scripts into the click path. If you're evaluating options, our best URL shorteners comparison for 2026 breaks down which services prioritize user privacy versus which load extensive analytics tags. You can also read our honest review of Lunyb for details on how the service handles tracking.

The Regulatory Landscape

Browser fingerprinting exists in a legal grey zone in many jurisdictions, but regulators are catching up.

GDPR (European Union)

Under the GDPR and the ePrivacy Directive, fingerprinting for tracking purposes requires informed consent, just like cookies. European Data Protection Board guidance from 2019 explicitly states that device fingerprinting falls under the same consent rules as cookie storage. Enforcement has been inconsistent, but fines are rising.

CCPA and CPRA (California)

California's privacy laws treat device identifiers — including those built from fingerprints — as personal information. Businesses must disclose their use and honor opt-out requests.

Browser-Level Responses

Apple's Safari and Mozilla's Firefox treat fingerprinting as a form of tracking that users don't consent to, and they actively work to break it. Google Chrome has been slower to act, partly because its parent company depends on advertising revenue, but even Chrome has begun limiting some fingerprinting surfaces as part of its Privacy Sandbox initiative.

The Future of Fingerprinting

As browsers restrict individual APIs, trackers evolve new techniques. Recent research has demonstrated fingerprinting based on:

  • CSS media queries that reveal rendering engine quirks
  • Scroll behavior and mouse movement patterns unique to individual users
  • Battery charge/discharge cycles on supported devices
  • Network latency patterns that reveal ISP and geographic location
  • GPU performance benchmarks run invisibly in the background

The arms race between trackers and privacy tools will continue. For users, the practical takeaway is simple: no single tool will make you invisible, but combining a fingerprint-resistant browser, a good content blocker, encrypted DNS, and sensible browsing habits dramatically reduces how much any one entity can learn about you.

Key Takeaways

  • Browser fingerprinting identifies you using your device's unique combination of attributes — no cookies required.
  • Canvas, WebGL, and audio fingerprinting are among the most powerful techniques because they exploit hardware-level differences.
  • Fingerprinting is used by advertisers, fraud prevention systems, bot detection services, and data brokers.
  • Tools like Cover Your Tracks and AmIUnique can show you how identifiable your browser is.
  • You can meaningfully reduce fingerprinting with a resistant browser (Tor, Mullvad, Brave, hardened Firefox), content blockers, and encrypted DNS.
  • Regulations like GDPR and CPRA increasingly treat fingerprinting as a form of tracking that requires consent.

Frequently Asked Questions

Can incognito or private browsing mode stop fingerprinting?

No. Incognito mode only prevents your browser from saving history, cookies, and form data locally. Your hardware, operating system, fonts, and graphics card remain the same, so your fingerprint is essentially identical in private mode. Sites can still track you across private sessions.

Does clearing cookies help against fingerprinting?

Only slightly. Clearing cookies removes stored identifiers but does nothing about the fingerprint itself. A tracker that recognizes you by fingerprint can simply assign you a new cookie after you clear the old one, effectively re-identifying you within seconds.

Is browser fingerprinting illegal?

It depends on jurisdiction and purpose. In the EU, using fingerprinting for tracking without explicit user consent likely violates the GDPR and ePrivacy Directive. In the US, California's CPRA treats it as personal data collection requiring disclosure. Fingerprinting for fraud prevention is generally more defensible than for advertising.

Which browser is best for avoiding fingerprinting?

Tor Browser offers the strongest protection because it makes every user look identical, though it's slow and some sites break. For everyday use, Mullvad Browser, Brave with aggressive shields, or Firefox with privacy.resistFingerprinting enabled offer a good balance of protection and usability.

Will fingerprinting ever be completely eliminated?

Unlikely in the near future. As long as websites can run JavaScript and query device information for legitimate purposes (responsive design, accessibility, performance), some fingerprinting surface will exist. The realistic goal is to raise the cost and reduce the accuracy of fingerprinting, not to eliminate it entirely.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles