Skip to main content

A coherent browser identity, controlled locally.

404 coordinates supported fingerprint signals across TLS, HTTP, JavaScript, and—on supported systems—TCP/IP. One selected profile follows the session instead of exposing an unrelated collection of native device characteristics.

  • Local-firstBrowsing traffic stays on the path you choose
  • Profile-drivenSupported layers share one identity definition
  • Open sourceInspect and build the underlying components
404 Desktoprunning locally
Active profileResearch workstation
protected session
Presented identityChrome · Windows 11desktop · en-US · UTC−06
A product-interface illustration showing one active identity applied across supported layers.

A VPN can change the route. The browser still introduces the machine.

Switch the view to see the difference between changing only the network path and coordinating the identity that appears across multiple layers.

DenverVPNMadrid
TLSChromium-shaped handshakesoftware-family evidence
HTTPChrome headers · en-USrequest and language evidence
JavaScriptGPU · fonts · screen · timezonenative device evidence
TCP/IPhost network defaultsoperating-system evidence

Route changedThe browser and device profile can remain recognizable.

Conceptual illustration. Coverage depends on the browser, operating system, feature, and current release.

Fingerprinting does not happen in one place.

A page script, the destination server, and the network stack observe different pieces of the same session. 404 uses one active profile to coordinate supported changes instead of treating each surface as an unrelated toggle.

Explore the architecture
Active profileChrome · Windowsshared identity definition
  1. 01
    TLSClientHello · cipher and extension order
    Handshake presentationaligned
  2. 02
    HTTPHeaders · Client Hints · negotiation
    Request presentationaligned
  3. 03
    JavaScriptCanvas · WebGL · audio · Navigator
    Page-visible surfacesaligned
  4. 04
    TCP/IPTTL · window · MSS · option behavior
    Supported kernel signalsaligned
One selected profile coordinates supported signals across the stack.

Your browsing traffic never leaves your machine.

The desktop controller, profile state, local certificate authority, proxy path, and supported kernel handling operate on your machine. Websites still receive traffic through the network path you configure.

Separate concern: 404 does not mask an IP address by itself. Pair it with a VPN when changing network location is part of the threat model.

your device
Browsing traffic is processed locally before continuing to the destination through the route you selected.

Use ordinary browsers without treating their exposed identity as fixed.

404 is intended for work where repeat recognition can reveal interests, relationships, clients, sources, staff, or investigative patterns.

  1. 01

    Sensitive research

    Reduce the chance that repeat browsing sessions are connected by the same exposed browser and device profile.

  2. 02

    Client and source work

    Keep ordinary work in familiar browsers while controlling more of the identity those browsers present.

  3. 03

    Technical investigation

    Select, hold, and inspect a coordinated profile instead of changing isolated values by hand.

  4. 04

    Privacy engineering

    Study the interaction between browser, request, TLS, and supported packet-level fingerprint surfaces.

404 complements network privacy tools. It does not replace them.

VPN

Changes the visible route

Replaces the public exit IP and changes the network path. It normally leaves browser and device surfaces intact.

Location and route privacy
404

Changes the presented profile

Coordinates supported browser, request, TLS, and network-stack signals around one selected identity.

Fingerprint and linkability control
Tor Browser

Creates a shared anonymity model

Standardizes browsers and routes traffic through Tor. 404 does not claim to reproduce that anonymity set.

Purpose-built anonymity system

Desktop convenience or direct control.

The product and open-source paths use the same underlying project, but differ in who manages configuration, updates, and day-to-day operation.

01
Managed experience

404 Desktop

Choose a profile, launch a supported browser, manage the local service, and receive product updates through a graphical desktop application.

  • Windows
  • macOS
  • Linux
  • Chrome
  • Firefox
See plans
02
Operate it yourself

Self-hosted components

Build the open-source components, manage certificates and configuration, and control the deployment and update process yourself.

  • Rust
  • Open source
  • AGPLv3
  • Manual setup
Read the docs

Use the desktop app—or inspect every layer yourself.

404 Desktop manages profiles and updates through a graphical interface. The underlying components remain available for people who prefer to build and operate the stack themselves.