Font fingerprinting
Your fonts reveal the software behind your browser.
A website does not need a list of files from your computer. It can ask the browser to render the same characters again and again, then use changes in width and shape to infer which fonts are available. Those measurements become more useful when assembled with the rest of a browser fingerprint.
- Permission
- Not requested
- Stored ID
- Not required
- Primary clue
- Text metrics
- Stronger with
- Other signals
Wm1lI0 @ 72px318.42 px302.17 px346.80 pxFont Fingerprinting Demo
See which candidate fonts change the measurement.
This local demonstration compares a test string against three generic fallback families. A changed width suggests that a candidate font rendered. Results stay in this page.
Probe this browser
The test uses a short candidate list for illustration, not exhaustive enumeration.
not generatedA production system would combine a much larger set of values.- Run the test to compare candidate fonts with local fallbacks.
Computation happens in your browser. The page does not transmit or retain the result.
From a word to an inventory
The browser can reveal a font without naming it directly.
- 01
Establish a fallback
The page measures a test string in a generic family such as monospace, serif, or sans-serif.
- 02
Request a candidate font
The same string is measured again with a named local font placed before the fallback.
- 03
Compare the metrics
If the width or glyph bounds change, the named font likely rendered. Repeating the test produces a font inventory.
- 04
Combine the evidence
Presence results and exact measurements can be joined with locale, platform, canvas, and other browser signals.
The essential comparison
One API call can return precise text dimensions.
Canvas measureText() returns a TextMetrics object. A script can repeat the measurement across candidate names, sizes, weights, scripts, and fallback families.
const baseline = width('monospace');
const candidate = width('"Font Name", monospace');
if (candidate !== baseline) {
profile.fonts.push('Font Name');
}What the pattern can imply
A font list can become a map of the machine.
A typeface is not proof that a particular application, language, or operating system is present. It is a clue. Multiple related fonts make the inference stronger.
Default fonts can narrow the likely platform family.
Installed software may add recognizable typefaces.
Language packs and fallback coverage can expose regional context.
A rare combination can separate one machine from otherwise similar devices.
Good analysis separates observation from inference: “Calibri measured differently” is an observation; “Microsoft Office is installed” is a plausible but unproven explanation.
Two kinds of evidence
Installed fonts and rendered glyphs answer different questions.
Font inventory
Which named families appear to be available?
- Operating-system defaults
- Language packs
- Fonts added by applications
- User-installed typefaces
Rendering behavior
How does this environment shape and measure text?
- Glyph width and bounds
- Font version differences
- Hinting and rasterization
- Canvas pixel output
What changes the result?
Network resets do not rewrite the local font environment.
Stored identifiers are removed; local software is not.
The session is separate, but font exposure may remain similar or be restricted.
The route and IP change; local typography does not.
The browser may expose a different set of measurable families.
Fallbacks, rasterization, hinting, and available families may differ.
A browser can limit local fonts or standardize what pages can use.
Meaningful defenses
The goal is to make your font profile less unusual.
Removing one rare font may change a fingerprint, but manual customization can create a new rare configuration. Stronger defenses reduce the number of answers a browser can give and place users into larger groups.
Firefox can restrict locally installed fonts when fingerprinting protection is active. Tor Browser limits font enumeration and character fallback as part of a broader standardization strategy.
- 01
Limit local font exposure
Allow pages to use a smaller, common set instead of every font installed on the machine.
- 02
Standardize the visible set
A shared bundle helps many users return the same answers instead of inventing a unique answer for each person.
- 03
Protect related surfaces
Font inventory is only one path. Canvas text, glyph metrics, locale, and platform data can reinforce the same inference.