Human rights organizations
A public website can become a quiet surveillance point.
Human rights teams must revisit government, military, police, detention, corporate, and armed-group infrastructure. A hostile operator does not need to breach the organization to notice that the same browser keeps returning.
- Login required
- No
- Malware required
- No
- Identity proven
- No
- Detention facility registryprofile H4 · network A
- Unit procurement noticeprofile H4 · network B
- Command appointment pageprofile H4 · network B
Why continuity matters
A fingerprint is not a name. It is a handle that can accumulate context.
The risk is not that one browser measurement instantly identifies a human-rights worker. It is that a recurring technical profile can make separate observations look related, allowing other evidence to gather around them.
The investigation becomes visible
Repeated visits to one ministry, military unit, detention facility, contractor, or company can disclose sustained attention before a report or intervention is public.
Separate sessions become comparable
A recurring browser profile can connect monitoring over days or months even when local storage is cleared, a private window is used, or the public IP changes.
Other people can become adjacent
Shared devices, accounts, networks, documents, and timing can add context around a field partner, defender, witness, survivor, or person seeking support. Fingerprinting alone does not create that link.
Who carries the risk
The person browsing is not always the only person exposed.
Human-rights work is relational. Investigators, field partners, defenders, witnesses, survivors, clients, and support organizations can become connected through shared technical or operational context.
Investigator
Revisits official statements, registries, procurement data, maps, social accounts, and archived pages.
A target may recognize sustained monitoring and infer the investigation’s subject or cadence.
Field partner or defender
Checks local reporting, government portals, case updates, travel information, or emergency resources.
Network origin, locale, time zone, device traits, and timing may narrow the operating environment when combined.
Witness, survivor, or client
Uses an intake form, support portal, shared device, referral link, or organization account.
Poor separation can place a vulnerable person beside the organization’s existing account or browser context.
The organization
Operates a recognizable office fleet, extension set, SSO environment, network range, or research routine.
Repeated technical patterns can make activity look organizational even when a staff member is not named.
Public IP, route-derived context, TLS and transport behavior
Headers, client hints, language preferences and referrer context
Screen, platform, time zone, locale, capabilities and API results
Canvas, WebGL, fonts, audio and graphics behavior
Timing, recurrence, navigation, account state and on-site behavior
What is actually exposed
The page measures the session. Context can turn that measurement into meaning.
Technical signals can help distinguish one browser from nearby browsers. Cookies, accounts, IP history, timing, on-site behavior, and outside datasets can make the profile more useful.
- Your legal name or employer
- Files stored on the device
- Encrypted Signal messages
- Every other website you visit
- The identity or intent behind the activity
Those facts can still be exposed through accounts, malware, shared infrastructure, third-party code, referrals, downloads, operational mistakes, or separate data sources. They are not outputs of browser fingerprinting by themselves.
Where exposure appears
The same browser signal has different consequences in different work.
Start with the activity and the plausible adversary. A public education campaign and a covert investigation do not need the same environment.
Tracking an abusive actor
Repeated checks of official sites, propaganda channels, unit pages, corporate assets, or public records may reveal that the actor is under sustained observation.
Building an evidence record
A recurring profile around maps, media, registries, satellite providers, archives, and verification tools can expose the shape and pace of an investigation.
Assisting a person at risk
Account reuse, shared devices, browser state, referrals, and local network context can create association paths around intake and emergency support.
Preparing a campaign or filing
Research bursts around a government, company, venue, or policy can make timing visible before publication, litigation, sanctions work, or public action.
Choose by job
There is no universal “safe browser” switch.
Privacy, compartmentalization, communications security, and anonymity are different goals. Use the tool that changes the layer your threat model depends on.
Tor Browser or Tails
- Changes
- Network path and many identifying browser characteristics through a standardized environment.
- Does not solve
- Logins, endpoint compromise, operational mistakes, downloaded files, and human behavior can still create exposure.
Dedicated profile or device
- Changes
- Accounts, cookies, extensions, local state, and some configuration context.
- Does not solve
- Shared hardware, network, behavior, files, or sign-ins may reconnect contexts.
VPN
- Changes
- The public IP address and route visible to the destination.
- Does not solve
- The destination, browser profile, account state, and many device signals remain available.
Tracker blocking
- Changes
- Known advertising, analytics, and tracking requests that the blocker recognizes.
- Does not solve
- First-party measurement and any unblocked or necessary scripts can remain.
Secure communications
- Changes
- The confidentiality and integrity of supported conversations and shared material.
- Does not solve
- Signal, SecureDrop, and similar tools do not change an unrelated research browser’s fingerprint.
404 Desktop
- Changes
- Supported browser, HTTP, TLS, and network-stack surfaces presented during ordinary desktop research.
- Does not solve
- It is not an anonymity network, secure messenger, malware defense, or substitute for disciplined compartmentalization.
For high-risk anonymity, use Tor Browser or Tails as designed. Adding extensions, changing defaults, or combining untested spoofing layers can make a standardized environment more distinctive.
Operational protocol
Protect the investigation before, during, and after the browser session.
The goal is a workflow a team can repeat under pressure. Browser controls belong beside account separation, device security, communications security, and incident response.
- 01Before
Model the observer
- Name who may care about the work
- Decide whether privacy, separation, or anonymity is required
- Choose the browser, device, account, and network workflow first
- 02During
Keep contexts apart
- Avoid personal or organization SSO when it is not required
- Do not move links, files, or identities between risk tiers casually
- Treat new downloads and unexpected prompts as a separate threat
- 03After
Review what changed
- Record exceptions and accidental sign-ins
- Reassess when a partner, witness, location, or adversary changes
- Escalate suspected targeting to qualified digital-security support
Preserve context, avoid contaminating evidence, and contact a qualified digital-security response organization. Access Now’s Digital Security Helpline provides support to civil society around the world.
Open the Digital Security HelplineWhere 404 fits
A coordinated browser profile for ordinary research workflows.
404 is designed to reduce linkability across supported browser, HTTP, TLS, and network-stack surfaces while preserving a conventional desktop workflow. It can sit inside a research tier where Tor Browser is not required and organization accounts are kept separate.