Browser fingerprinting: how websites recognise you without cookies
Cookies are not the whole story
Most people think of tracking as a cookie problem. Block third party cookies, clear your cookies now and then, maybe run private browsing, and you’re off the hook. That was a reasonable model a decade ago. It isn’t anymore.
Cookies work because your browser stores a small file and hands it back to a site on every visit. Block the cookie, and the site loses the thread. Browser fingerprinting doesn’t rely on anything being stored on your device at all. Instead, a script running on the page asks your browser a long list of questions, things like your screen resolution, your installed fonts, your timezone, how your graphics card renders a specific image, and combines the answers into a value that’s often unique, or close to it, among everyone visiting that site. No file needs to persist. The fingerprint is recomputed fresh every time, and if it comes out the same, the site can reasonably assume it’s the same browser.
This matters because a lot of privacy advice stops at cookies, and fingerprinting quietly picks up where cookies leave off.
What a fingerprint is actually made of
A browser fingerprint is a combination of many individually unremarkable signals. None of them identify you on their own. Stacked together, they narrow things down fast.
HTTP headers and JavaScript-exposed properties. Your user agent string reveals browser version, engine, and operating system. navigator properties expose things like installed language packs, number of logical CPU cores (hardwareConcurrency), device memory tier, and whether you have touch support.
Screen and window characteristics. Resolution, color depth, available screen space versus browser window size, and pixel density all get reported to any script that asks.
Canvas fingerprinting. A page draws hidden text or shapes onto an invisible HTML canvas element and reads back the resulting pixels. Because font rendering, anti-aliasing, and GPU driver behaviour vary slightly between machines, the pixel output varies too, in a way that’s stable for a given device but differs across devices. The script hashes that pixel data into a short fingerprint value.
WebGL and GPU fingerprinting. Similar idea, but the page asks your graphics card to render a 3D scene and reads details about the GPU and driver, which again differ across hardware and driver versions.
AudioContext fingerprinting. The browser is asked to process a generated audio signal through its audio stack. Tiny differences in how the CPU and audio hardware handle floating point math produce a measurably different output waveform, again without you hearing anything.
Fonts. Sites can test which fonts are installed by measuring how text renders at different sizes, which is often a strong signal because font sets vary a lot between operating systems and installed software.
Behavioural and timing signals. Some fingerprinting also looks at things like battery status (largely deprecated now due to abuse), how fast certain operations run, or plugin and MIME type lists in older browsers.
Individually, “screen resolution 1920x1080” tells a site almost nothing, since millions of people share it. But combine resolution, timezone, five installed fonts, GPU renderer string, and canvas hash, and the number of other browsers sharing that exact combination drops sharply. This is the core idea behind fingerprinting: it doesn’t need one unique signal, it needs enough ordinary signals stacked together that the combination becomes rare.
Why this works even in incognito mode
Private or incognito browsing modes stop your browser from saving cookies, history, and local storage after the session ends. They do essentially nothing about fingerprinting, because fingerprinting doesn’t depend on anything being saved locally. Your screen resolution, fonts, GPU, and CPU core count are the same whether you’re in a normal window or a private one. A site can still compute the same fingerprint value and, if it saw that combination before, link the sessions together.
This is a common source of false confidence. Incognito mode protects you from someone else using your computer seeing your history. It was never designed to stop a website from recognising your device across visits.
Server side matching and cross-site tracking
A single fingerprint on one site is only useful to that site. Fingerprinting becomes a broader tracking tool when the same script (often loaded from a shared analytics or ad tech provider) runs on many different sites and reports fingerprints back to a common server. If your fingerprint on siteA.com matches your fingerprint on siteB.com, the tracking company can link your activity across both, similar to what third party cookies used to do before browsers started blocking them by default.
This is part of why fingerprinting has grown in importance industry wide. As Safari, Firefox, and Chrome have restricted third party cookies over the past several years, some ad tech and analytics vendors have leaned more on fingerprinting and similar techniques as a fallback identifier that doesn’t depend on cookies surviving.
The paradox: blocking things can make you more identifiable
Here’s the part that trips people up. If fingerprinting works by finding rare combinations of ordinary signals, then deliberately making your browser unusual can backfire. Installing an obscure combination of privacy extensions, spoofing your user agent to something rare, or disabling JavaScript features in a nonstandard way can all make your fingerprint more distinctive, not less, because almost nobody else’s browser looks like that.
This is why fingerprint resistance, done properly, aims for blending in rather than standing out. The Tor Browser is the clearest example: it deliberately standardises window size, disables or normalises canvas and WebGL output, and tries to make every user’s browser report the same set of values, so that instead of your device being one of a few thousand with that exact fingerprint, it’s one of a very large pool of Tor Browser users who all look alike. Firefox has a similar built in setting (resistFingerprinting, based on Tor Browser’s work) that trades away some convenience for a more uniform fingerprint. It’s not switched on for everyone by default because it can break sites that expect normal timezone or screen data.
Browser extensions that randomise canvas or WebGL output on every page load take a different approach, and it’s worth understanding the tradeoff. If your canvas fingerprint changes every single visit, that itself can become a recognisable pattern, a browser that “spoofs randomly” is its own kind of fingerprint if a site checks for consistency in the wrong places. None of this makes randomising extensions useless. It just means the protection depends on how well the randomisation is implemented, not on the mere fact that an extension is installed.
What actually reduces your exposure
There’s no single setting or product that removes fingerprinting risk, and treating any one tool as a fix is more likely to create false confidence than protect you. What genuinely helps is reducing how distinctive your combination of signals is, and reducing how often the same fingerprint gets linked across different sites.
A few concrete, mechanically grounded points:
- Using a mainstream, widely deployed browser configuration (stock Chrome, stock Firefox, stock Safari, at default settings) puts you in a larger crowd than a heavily customised setup, purely because more people share that exact configuration.
- Browsers with built in tracking protection that specifically targets known fingerprinting scripts (Firefox’s Enhanced Tracking Protection and Safari’s Intelligent Tracking Prevention both include fingerprinting mitigations) block a meaningful share of the scripts before they run, rather than trying to make the fingerprint itself less useful.
- Compartmentalising, using separate browser profiles or containers for different activities, doesn’t stop fingerprinting within a single session but limits how much a fingerprint collected in one context can be tied to activity in another.
- Browser and OS updates matter because fingerprinting entropy shifts as software versions change. An outdated, unusually specific software stack (an old browser version with unusual plugins) tends to be more identifiable than a current, common one.
None of this adds up to being untraceable, and that’s not really the right goal for most people reading this. The realistic aim is reducing how easily your browsing gets linked together across sites and sessions by ordinary commercial tracking, which is a different and more achievable target than trying to disappear entirely.
The takeaway
Browser fingerprinting exists because cookies became easy to block, and tracking companies needed something that didn’t depend on files persisting on your device. It works by combining a lot of mundane technical details, your screen, your fonts, your GPU, into a combination that’s often rare enough to act as an identifier. Nothing about incognito mode stops it, and paradoxically, some attempts to fight it by standing out can make it worse. The tools that help, standardised browsers, targeted tracking protection, compartmentalisation, work by making you blend into a larger crowd or by blocking known tracking scripts outright, not by promising to make you invisible.
If you want to keep going deeper into how tracking actually works under the hood, without the fear-selling, The Privacy Wire covers this kind of thing regularly.