Jump to content

Browser Fingerprinting

From GAMAYUN+ Wiki

Cookies aren't the only way sites track you. Your browser leaks a surprising amount of identifying detail just by existing — which GPU you have (via WebGL), tiny timing differences in your CPU (via performance.now()), even the exact order your OS signs network packets. None of it requires a cookie, none of it requires you to be logged in, and clearing your cookies or using a VPN doesn't touch most of it. "I'm not logged in and I cleared my cookies" is not the same thing as "I'm not being tracked" — fingerprinting techniques were specifically built to survive the privacy measures people actually use.

How much any one signal actually reveals

No single data point identifies you — your screen resolution alone is shared by millions of people. The technique works by combining dozens of individually unremarkable signals until the combination itself becomes rare. The Electronic Frontier Foundation's original Panopticlick research (the project now continues as Cover Your Tracks) measured the average browser as carrying about 18 bits of identifying entropy from a fingerprint — enough, in information-theory terms, to narrow a given browser down to roughly 1 in 262,000.[1] Later measurements that include newer techniques put the achievable entropy well above 30 bits for a browser with no countermeasures — enough to be close to unique among billions of devices, from signals that individually look completely mundane. That's the same entropy math The Odds a UUID Ever Repeats uses to prove a UUID basically never collides — here it's run in the opposite direction, to show how few random-looking bits it actually takes to make one browser stand out from everyone else's.

The techniques that do the most work

  • Canvas fingerprinting. A hidden instruction tells your browser to silently render text or shapes to an invisible <canvas> element, then reads back the resulting pixel data. Tiny differences in GPU, graphics driver, and font-rendering engine mean two different machines drawing the exact same instructions produce measurably different output — a side effect nobody designed for tracking, repurposed for it anyway.[2]
  • WebGL / audio fingerprinting. Same idea, different subsystem — how your GPU renders a 3D scene, or how your audio stack processes a synthesized waveform, both vary just enough between hardware/driver/OS combinations to be a usable signal.
  • Font and plugin enumeration. Which fonts are actually installed (checked indirectly, by measuring how text renders) says something real about your OS, region, and installed software.
  • Everything else, stacked. Timezone, installed language packs, screen resolution and color depth, hardware concurrency (CPU core count), battery API quirks, and dozens of smaller signals each contribute a little.

What actually helps, and what doesn't

Incognito/private browsing mode blocks cookies, not fingerprinting — your canvas and WebGL output look identical in and out of a private window. A VPN changes your IP address and rough location, which is a real and separate privacy improvement, but does nothing to the dozens of other signals a fingerprinting script reads directly from your browser. The approach that actually works is uniformity: the Tor Browser is deliberately engineered so that as many installations as possible report identical values for every fingerprintable signal, on the theory that a fingerprint that's shared by millions of other Tor users isn't a useful fingerprint at all.[3] Browser extensions that randomize individual signals (a slightly different canvas hash every visit) can sometimes make things worse rather than better, since "this fingerprint changes in a suspicious, non-human way every reload" is itself a distinguishing signal.

See also