In the introductory article I only touched on browser fingerprinting, enough to make it clear that it exists and that neither cookies nor a VPN will hide it. Today I will look at it in depth: who collects it, how rare it makes you, and above all what you can realistically do about it.
Who collects fingerprints and why
Fingerprinting has two entirely different faces, and it is only fair to mention both. The first is the advertising and analytics industry: companies that want to know you are the same visitor as yesterday, even without cookies, so that they can build a profile of you and target you with advertising. The second is banking and payment security. When you sign in to online banking or pay by card online, the bank quietly compares your device fingerprint with the one it knows from before, and if a payment suddenly comes from a completely different device on the other side of the world, the system takes notice. Here fingerprinting is a tool against fraud, not against you. Same technique, opposite purpose. That is precisely why fingerprinting cannot simply be banned outright. You can only protect yourself from the first face, not the second.
How rare you really are
The principle is simple. Each individual characteristic of your device (the type of graphics card, the installed fonts, the screen resolution, the system version) says little on its own, because you share it with thousands of other people. But put 20 of them together, and the combination of “exactly this graphics card, this sound chip, this set of fonts, this resolution” tends to be surprisingly rare, often unique among hundreds of thousands of other devices. It is the same principle as a fingerprint: a single ridge says nothing, but the whole pattern identifies the person.
If you want to see your fingerprint with your own eyes, there are two reputable free tools worth trying: coveryourtracks.eff.org and amiunique.org. Within seconds, both show you how unique your device is compared with those of other people who have taken the same test. I recommend measuring it now, then again once you have tried some of the recommendations below, and comparing what has changed.
Browsers ranked by strength of protection
Not all browsers deal with fingerprinting equally well, and it is worth knowing where standard protection ends and stronger protection begins.
The strongest approach is taken by Tor Browser and by Mullvad Browser, which builds on it. Both rely on a simple but clever idea: rather than making each user’s fingerprint slightly different, they try to make it exactly the same for every user. If you look exactly like millions of other people using the same browser, fingerprinting becomes far less effective. It is a tool for moments when you need the highest possible discretion, not for everyday browsing.
Brave, which I recommend as a sensible everyday standard, takes a different route: it subtly and randomly alters the values a website reads, slightly differently each time. This works well against ordinary tracking, although in fairness, with enough repeated attempts this kind of random defence can be partly seen through. Against a standard advertising tracker, however, it is sufficient protection, it is free, and you do not have to configure anything.
Firefox has a hidden advanced setting, resistFingerprinting, which does something similar to Tor Browser. It is intended more for advanced users, though, because it can break the normal behaviour of some websites, for example by showing the wrong time zone. Firefox is also gradually adding gentler default protection that does not need to be switched on manually and does not break websites in the process. Safari long relied mainly on blocking third-party trackers, but today it also has direct protection against fingerprinting: it adds a small amount of noise to the values that fingerprinting scripts read, so the fingerprint comes out slightly differently each time. In the latest versions this is switched on by default for all browsing; previously it worked only in private windows.
Why incognito mode and a VPN are not enough
This is the most common misconception I come across. Incognito mode or a private window only limits the trail left on your own device: when you close it, it deletes the history, cookies and data from that session. But the fingerprint is read live, at the very moment you open the page, and it is exactly the same whether you are in a normal window or a private one. The same goes for a VPN, which I wrote about last time: it changes only where you appear to be coming from and does not touch the fingerprint of the device itself. Each works on a different layer. Both are useful, but neither solves fingerprinting.
A case that ended up in a US court a few years ago showed that this is not just a theoretical risk. One of the world’s largest technology companies was sued precisely because users of its browser believed they were not being tracked in a private window, while, according to the lawsuit, the company went on collecting signals, including the device fingerprint. The dispute dragged on for years and ended in a settlement: the company had to delete a vast amount of data collected from private windows and promised to change its practices for several years to come. However similar disputes turn out in future, one thing is already clear: “private window” and “invisible” are not synonyms, not even at companies that ought to know best.
What to do about it today
On ordinary days, a good browser with built-in protection is enough: Brave or a properly configured Firefox is a solid choice, just as I wrote in the introductory article. For moments when you need the highest possible discretion (sensitive meetings, research, anything where you do not want to be linked to a previous visit), use Tor Browser or Mullvad Browser. Measure your own fingerprint at coveryourtracks.eff.org or amiunique.org, so that you know your starting point. And remember the principle I mentioned in the introduction, one that applies equally in the digital and the physical world: blending into the crowd is usually the best protection. Fingerprinting only works where you stand out clearly from everyone around you.
“Deleting cookies will not hide your fingerprint. The only way to hide it is to look like everyone else in the room.”— Robert Václavík




