Skip to main content
Back to blog

Browser Fingerprinting Explained: How Sites Track You Without Cookies

Privacy

Browser Fingerprinting Explained: How Sites Track You Without Cookies article illustration

Cookies get deleted. Fingerprints don’t.

That’s the uncomfortable truth behind browser fingerprinting: a way for websites to recognise your device based on how it renders, what it reports about itself, and how it talks to the network, without ever setting a cookie or asking permission. Clear your cookies, switch to a private window, even reinstall your browser, and a well-built fingerprint can still land you back in the same bucket as before.

What a fingerprint actually is

A browser fingerprint isn’t one single piece of data. It’s a combination of dozens of small, individually unremarkable details, your screen resolution, your timezone, which fonts you have installed, how your graphics card renders a specific image, that on their own mean almost nothing. Put twenty or thirty of them together, though, and the combination becomes distinctive enough to single out one device among millions, often without needing a single cookie, login, or IP address.

The classic research on this (the EFF’s Panopticlick project, since folded into Cover Your Tracks) found that the large majority of browsers tested had a fingerprint unique enough to identify them individually. That was over a decade ago. Fingerprinting techniques have only gotten more precise since.

The signals that make up a fingerprint

Canvas fingerprinting. A script draws hidden text or shapes to an invisible HTML canvas element, then reads back the resulting image as pixel data. The exact way those pixels render depends on your graphics card, driver version, operating system, and even font rendering engine, small enough differences that two devices rarely produce identical output. The script never shows you anything, it just hashes the result and uses that hash as an identifier.

WebGL fingerprinting. Similar idea, deeper level. WebGL exposes details about your actual graphics hardware, the WEBGL_debug_renderer_info extension can reveal your GPU vendor and model directly (an Intel Arc chip renders identifiably differently from an Nvidia or Apple Silicon GPU), and rendering a 3D scene surfaces further hardware-specific quirks in how shaders and textures get processed.

Font detection. Browsers don’t hand over a list of your installed fonts directly, that would be too easy to fingerprint with. Instead, a script measures how wide a block of text renders in a candidate font compared to a generic fallback. If the measured width differs from the fallback, that font is almost certainly installed. Run this check against a list of a few dozen common fonts (design software, regional language packs, that obscure font your work software installed years ago) and the specific combination of what’s present becomes a real signal, particularly on a machine with an unusual mix of installed software.

TLS and network-level signals. This is the one that doesn’t come from your browser at all, it comes from your device’s network stack. Every time your browser connects to a site over HTTPS, it performs a TLS handshake, and details of that handshake (which protocol version, which cipher suites it offers, in what order, how long the initial hello message is) vary by operating system, browser engine, and even VPN client, independently of anything JavaScript can see or control. This is worth knowing specifically if you use a VPN: switching VPN providers can change your TLS signal even though your browser hasn’t changed at all.

Everything else. Screen resolution and colour depth, timezone, system language, number of CPU cores, device memory, whether cookies and Do Not Track are enabled, installed browser plugins, and the user agent string your browser sends on every request, though what a user agent still reveals is less than most articles claim. None of these alone identifies you, but a fingerprinting script combines all of it, canvas, WebGL, fonts, TLS, and the rest, into one composite signature.

Why fingerprinting is harder to block than cookies

Cookies are opt-in by design, a site has to explicitly set one, your browser has to store it, and you can delete it or block it with a single setting. Fingerprinting doesn’t work like that. Canvas and WebGL are core rendering APIs that legitimate parts of the web genuinely need (image editors, games, video calls). Blocking them outright breaks real functionality, not just tracking.

That’s the real tension: the same APIs that let a site render your video call properly are the ones a tracking script can quietly repurpose to identify you. There’s no clean setting that turns off “fingerprinting” without also turning off features people actually want.

What you can actually do about it

No single setting eliminates fingerprinting, but a few things meaningfully reduce your exposure:

Use a privacy-focused browser or a hardened profile for anything sensitive, browsers like Firefox (with resistFingerprinting enabled) or Brave specifically randomise or normalise some of these signals rather than reporting your device’s real values. Keep your browser and OS on a common, current version rather than an unusual combination, the more your setup matches millions of other people’s, the less distinctive your fingerprint is, oddly enough, being generic is protective here. Limit which sites get canvas, WebGL, and font access where your browser allows granular permissions. Keep timezone, language, and VPN server location consistent with each other, a mismatch (a UK timezone with a US VPN exit node, for instance) is itself a fingerprinting signal.

None of this makes you invisible. It raises the cost of tracking you specifically, which for most people is the realistic goal rather than perfect anonymity.

Checking your own exposure

The best way to understand what your own browser is revealing is to actually look at it. Our Browser Fingerprint Test runs all of the checks described above, canvas, WebGL, fonts, and TLS, directly in your browser and shows you an exposure score along with every individual signal it detected, exactly what a real fingerprinting script would see. It’s worth running before and after changing browser settings to see what actually moves the number.

Worth pairing with a check of your visible IP address and a WebRTC leak test too, fingerprinting and IP exposure are separate tracking vectors, and a full picture of your privacy footprint needs both.