Privacy

Browser fingerprinting: how sites recognise you without cookies

A browser fingerprint is the set of characteristics of your device and browser that, taken together, are distinctive enough to recognise you on a return visit. Individually they are harmless — language, screen size, time zone, fonts, browser version — but in combination they often point to one specific user, with no cookies, in private mode, and with a VPN switched on.

In short

  • A fingerprint is built from the parameters a browser reports to any site: browser and system version, screen, language, time zone, fonts, quirks of graphics rendering.
  • Each parameter on its own is shared by millions of people; it is the combination that becomes unique.
  • Unlike a cookie, a fingerprint is not stored on your side — it is recalculated on every visit.
  • So changing your IP, clearing cookies and using private mode do not change your fingerprint.
  • Standard settings, an up-to-date browser and built-in anti-fingerprinting protection all make yours less distinctive.

What a browser fingerprint is

To render a page correctly, a browser tells the site something about itself: which version it is, which system it runs on, how large the screen is, which language is selected.

Some data a site gets indirectly, through behaviour. It can draw an invisible image or a brief sound and observe exactly how your graphics and audio stack handled it — the result depends on your hardware and drivers.

None of these parameters is an identifier. But collected together they form a string that turns out to be unique for a great many people.

That string is the fingerprint. A site can store it and recognise the same browser next time round.

What goes into it

Browser and system: name, version, platform, sometimes the number of processor cores and amount of memory.

Screen and window: resolution, pixel density, colour depth, the size of the working area.

Locale: interface language, the list of preferred languages, time zone.

Rendering: the results of graphics processing through Canvas and WebGL, audio parameters, the set of available fonts. Installed extensions can show up too, through the changes they make to a page.

How this differs from cookies

A cookie is a small file a site saves in your browser. You can look through your cookies and delete them, and the site loses the history attached to them.

A fingerprint saves nothing on your side. It is assembled afresh each time from your device's current configuration.

There is no way to "clear" a fingerprint — you can only change the configuration itself: the browser, its settings, the set of fonts and extensions.

So a fingerprint survives clearing cookies, private mode and changing your IP address. These are different mechanisms and they work independently of one another.

Why sites do it

Fraud and bot protection. Services use fingerprints to tell ordinary visits from automated ones and to spot suspicious account sign-ins.

Analytics. A fingerprint helps avoid counting the same visit several times when cookies are unavailable.

Advertising and tracking. When someone limits cookies, a fingerprint becomes the fallback way to link activity across sites.

Fingerprinting is not always aimed against you, but for privacy it matters that this form of recognition works around the settings people usually rely on.

What makes a fingerprint less distinctive

Standard settings. The closer a browser is to a typical configuration, the harder it is to pick out. Rare themes, exotic fonts and unusual parameters make a fingerprint stand out.

Current versions. An updated browser matches a large group of people running the same version.

Browser-level protection. Some browsers can normalise or restrict a number of these parameters — it is worth a look through the privacy settings.

Care with anti-detect add-ons. Attempts to fake parameters often produce a contradictory combination that makes a browser even easier to single out.

Where MaskNet fits in

A fingerprint is formed in the browser and belongs to the device, not the network. A VPN changes your IP address and protects the connection, but it does not control which parameters your browser reports to sites.

MaskNet hides your public IP for traffic that goes through the protected network and encrypts data in transit. A browser fingerprint is a separate layer, and it has to be handled with the browser's own tools.

Understanding that division stops you relying on one tool where you need two: the network covers network data, the browser covers the parameters of its environment.

You can see what your own fingerprint looks like, and how much it stands out, in the fingerprint tool.

What to remember

  • A browser fingerprint is a combination of device and browser parameters that often turns out to be unique.
  • It is not stored on your side and is recalculated on every visit.
  • Clearing cookies, private mode and changing your IP do not change it.
  • Standard settings, current versions and built-in browser protection make it less distinctive.
  • A VPN covers network data but does not control a browser fingerprint.
Check my fingerprint