Skip to main content

A public website can become a quiet surveillance point.

Human rights teams must revisit government, military, police, detention, corporate, and armed-group infrastructure. A hostile operator does not need to breach the organization to notice that the same browser keeps returning.

Login required
No
Malware required
No
Identity proven
No
Illustrative site logReturning visitor
Profile H4 observed again3 visits · 9 days
  1. Detention facility registryprofile H4 · network A
  2. Unit procurement noticeprofile H4 · network B
  3. Command appointment pageprofile H4 · network B
Possible inferenceSomeone is mapping this unit’s detention operations.The profile is a continuity clue—not a verified person or organization.
Synthetic example. A site sees activity on its own infrastructure. Cross-site association requires a shared observer, identifier, account, or dataset.

A fingerprint is not a name. It is a handle that can accumulate context.

The risk is not that one browser measurement instantly identifies a human-rights worker. It is that a recurring technical profile can make separate observations look related, allowing other evidence to gather around them.

01

The investigation becomes visible

Repeated visits to one ministry, military unit, detention facility, contractor, or company can disclose sustained attention before a report or intervention is public.

02

Separate sessions become comparable

A recurring browser profile can connect monitoring over days or months even when local storage is cleared, a private window is used, or the public IP changes.

03

Other people can become adjacent

Shared devices, accounts, networks, documents, and timing can add context around a field partner, defender, witness, survivor, or person seeking support. Fingerprinting alone does not create that link.

visitrecurring profileoperational contextpossible attribution

The person browsing is not always the only person exposed.

Human-rights work is relational. Investigators, field partners, defenders, witnesses, survivors, clients, and support organizations can become connected through shared technical or operational context.

01

Investigator

Revisits official statements, registries, procurement data, maps, social accounts, and archived pages.

Why it matters

A target may recognize sustained monitoring and infer the investigation’s subject or cadence.

02

Field partner or defender

Checks local reporting, government portals, case updates, travel information, or emergency resources.

Why it matters

Network origin, locale, time zone, device traits, and timing may narrow the operating environment when combined.

03

Witness, survivor, or client

Uses an intake form, support portal, shared device, referral link, or organization account.

Why it matters

Poor separation can place a vulnerable person beside the organization’s existing account or browser context.

04

The organization

Operates a recognizable office fleet, extension set, SSO environment, network range, or research routine.

Why it matters

Repeated technical patterns can make activity look organizational even when a staff member is not named.

Remote observationWhat a page can measure
Connection

Public IP, route-derived context, TLS and transport behavior

Request

Headers, client hints, language preferences and referrer context

Browser

Screen, platform, time zone, locale, capabilities and API results

Rendering

Canvas, WebGL, fonts, audio and graphics behavior

Activity

Timing, recurrence, navigation, account state and on-site behavior

Combined resultComparable browser profile

The page measures the session. Context can turn that measurement into meaning.

Technical signals can help distinguish one browser from nearby browsers. Cookies, accounts, IP history, timing, on-site behavior, and outside datasets can make the profile more useful.

Not automatically visible to the page
  • Your legal name or employer
  • Files stored on the device
  • Encrypted Signal messages
  • Every other website you visit
  • The identity or intent behind the activity

Those facts can still be exposed through accounts, malware, shared infrastructure, third-party code, referrals, downloads, operational mistakes, or separate data sources. They are not outputs of browser fingerprinting by themselves.

The same browser signal has different consequences in different work.

Start with the activity and the plausible adversary. A public education campaign and a covert investigation do not need the same environment.

01Monitoring

Tracking an abusive actor

Repeated checks of official sites, propaganda channels, unit pages, corporate assets, or public records may reveal that the actor is under sustained observation.

02Documentation

Building an evidence record

A recurring profile around maps, media, registries, satellite providers, archives, and verification tools can expose the shape and pace of an investigation.

03Support

Assisting a person at risk

Account reuse, shared devices, browser state, referrals, and local network context can create association paths around intake and emergency support.

04Advocacy

Preparing a campaign or filing

Research bursts around a government, company, venue, or policy can make timing visible before publication, litigation, sanctions work, or public action.

There is no universal “safe browser” switch.

Privacy, compartmentalization, communications security, and anonymity are different goals. Use the tool that changes the layer your threat model depends on.

High-risk anonymity

Tor Browser or Tails

Changes
Network path and many identifying browser characteristics through a standardized environment.
Does not solve
Logins, endpoint compromise, operational mistakes, downloaded files, and human behavior can still create exposure.
Role and case separation

Dedicated profile or device

Changes
Accounts, cookies, extensions, local state, and some configuration context.
Does not solve
Shared hardware, network, behavior, files, or sign-ins may reconnect contexts.
Network-origin change

VPN

Changes
The public IP address and route visible to the destination.
Does not solve
The destination, browser profile, account state, and many device signals remain available.
Third-party reduction

Tracker blocking

Changes
Known advertising, analytics, and tracking requests that the blocker recognizes.
Does not solve
First-party measurement and any unblocked or necessary scripts can remain.
Message and source protection

Secure communications

Changes
The confidentiality and integrity of supported conversations and shared material.
Does not solve
Signal, SecureDrop, and similar tools do not change an unrelated research browser’s fingerprint.
Conventional browser linkability

404 Desktop

Changes
Supported browser, HTTP, TLS, and network-stack surfaces presented during ordinary desktop research.
Does not solve
It is not an anonymity network, secure messenger, malware defense, or substitute for disciplined compartmentalization.

For high-risk anonymity, use Tor Browser or Tails as designed. Adding extensions, changing defaults, or combining untested spoofing layers can make a standardized environment more distinctive.

Protect the investigation before, during, and after the browser session.

The goal is a workflow a team can repeat under pressure. Browser controls belong beside account separation, device security, communications security, and incident response.

  1. 01Before

    Model the observer

    • Name who may care about the work
    • Decide whether privacy, separation, or anonymity is required
    • Choose the browser, device, account, and network workflow first
  2. 02During

    Keep contexts apart

    • Avoid personal or organization SSO when it is not required
    • Do not move links, files, or identities between risk tiers casually
    • Treat new downloads and unexpected prompts as a separate threat
  3. 03After

    Review what changed

    • Record exceptions and accidental sign-ins
    • Reassess when a partner, witness, location, or adversary changes
    • Escalate suspected targeting to qualified digital-security support
Active targeting or compromiseDo not troubleshoot a high-risk incident alone.

Preserve context, avoid contaminating evidence, and contact a qualified digital-security response organization. Access Now’s Digital Security Helpline provides support to civil society around the world.

Open the Digital Security Helpline

A coordinated browser profile for ordinary research workflows.

404 is designed to reduce linkability across supported browser, HTTP, TLS, and network-stack surfaces while preserving a conventional desktop workflow. It can sit inside a research tier where Tor Browser is not required and organization accounts are kept separate.

Research browserselected workflow
404 profilecoordinated surfaces
Remote sitepresented identity