Skip to main content

A website can recognize your browser without a login.

Websites can combine ordinary details about your browser, device, and connection into a profile that may recognize the same browser later—without relying on one cookie or learning your name first.

Observed browser reconstructed now
viewportChecking…browserChecking…operating systemChecking…timezoneChecking…localeChecking…WebGL / GPUChecking…
local fingerprint sampleCalculating…
This combination of signals (along with hundreds more) can be hashed into a unique and recognizable fingerprint.

See what your browser makes visible.

Each button reads one ordinary browser API. A real fingerprinting system can collect many more values, test rendering behavior, and compare the result on a server.

Nothing in this demonstration is transmitted or stored.

$
Choose a signal to inspect.

These values describe a configuration. They do not prove who is using it.

A fingerprint is assembled from many signals

The page observes characteristics. Software normalizes them into a profile. A service then compares that profile with previous visits and decides whether the evidence is close enough.

01

Observe

Read values and run small tests.

02

Combine

[2d:7c, gpu:07, tz:−6,
font:12, tls:C, hdr:4A]

Create a comparable feature vector.

03

Compare

previousXYZ≈currentXYZ′

Allow for normal changes and uncertainty.

04

Assign

Browser · XYZ

Append this visit to a recurring profile.

The assigned ID belongs to the observer’s system. Another observer can collect different signals and reach a different result.

A fingerprint can be reconstructed many times

Cookie

The website writes an ID.

  1. Visit 1save ABC
  2. Visit 2send ABC
  3. Clear storageremove ABC
  4. Visit 3no stored ID
Fingerprint

The observer measures again.

  1. Visit 1compute XYZ
  2. Visit 2compare XYZ′
  3. Clear storagestored state removed
  4. Visit 3recompute XYZ″

Real systems may tolerate changed values, combine server-side history, and return a confidence score rather than require an exact match.

Recognition turns separate moments into a history.

A fingerprint does not need to contain a name to be commercially useful. If the same browser can be recognized, new events can be attached to an existing pseudonymous profile. 404 Privacy’s original research on fingerprinting and advertisingfollows this shift from cookie rejection to reconstructed identifiers.

profile · XYZillustrative activity history
  1. Product viewedrunning shoes
  2. Article readmarathon training
  3. Cart startedsame browser profile
  4. Email submittedpseudonymous history can meet a known account
possible downstream usesaudience · attribution · frequency · personalization
An example of association—not a claim that every site or vendor performs every step.

Recognition can protect a session—or profile a customer.

Intent changes. The underlying capability remains the ability to recognize a browser across moments.

01

Fraud and abuse controls

Estimate whether a login, checkout, or account action resembles a known device or an unusual environment.

02

Analytics and attribution

Estimate repeat visits, conversion paths, and campaign performance when ordinary identifiers are unavailable.

03

Advertising and marketing

Place a returning browser into an audience, limit ad frequency, personalize an offer, or measure whether an ad preceded a sale.

04

Account security

Add a device signal to risk scoring, session protection, or prompts for additional authentication.

Different controls operate at different layers.

A useful defense claim should say which signal it changes, who can still observe the rest, and whether many users receive the same protection.

ActionWhat it changesWhat remains
Clear cookiesRemoves stored identifiersThe browser can expose the same characteristics again.
Open a private windowSeparates local history and storageMany browser, device, and network signals remain observable.
Change VPN serverChanges the IP address and routeIt does not change the local graphics, fonts, screen, or browser APIs.
Use anti-fingerprinting protectionsCan reduce, standardize, or partition signalsEffectiveness depends on the browser, defaults, and observer.
01

Minimize

Expose fewer unnecessary characteristics.

02

Standardize

Make more browsers look alike.

03

Partition

Prevent one observer’s identifier from becoming universal.

04

Separate the network

Reduce linkability at the IP and transport layers too.

A browser fingerprint is a repeatable profile built from observable characteristics.

It can recognize without naming. A pseudonymous browser history can still reveal patterns and support decisions.

It becomes more consequential when associated. Accounts, purchases, and submitted details can connect that history to a person.

Defense is a system property. The strongest approaches reduce linkability across browser, device, and network layers.

Sources and technical references
W3C Privacy Working Group · Mitigating Browser FingerprintingMDN · FingerprintingEFF · Cover Your TracksTor Project · Browser design and fingerprinting defenses

This page describes capabilities and illustrative data flows. It does not claim that every website, advertiser, or security service collects the same signals or performs every association shown.

Published 2025-01-15 · Reviewed 2026-09-19