VanishInbox
privacysecurityguide

What Is Browser Fingerprinting? How It Works and How to Stop It

Alex K.Alex K๐Ÿ“… 25 July 2026โฑ๏ธ 8 min read๐Ÿ“ 1,591 words
A device silhouette built from small tracking signals: canvas, fonts, screen resolution, timezone, WebGL, converging into a single fingerprint

Browser fingerprinting doesn't ask you for anything. No cookie banner, no account, no field to fill in. It reads what your browser already hands over on every page load, and turns that into an identifier.

An early study by the Electronic Frontier Foundation found that 83.6% of browsers tested had a fingerprint unique enough to identify them individually, with no cookie required. The EFF's modern successor to that study, Cover Your Tracks, still runs today and scores your own browser against recent visitors the same way. The number moves depending on the sample being measured. The mechanism hasn't changed: your browser configuration is distinctive enough, on its own, to single you out.

This covers how a fingerprint gets built, how unique a typical setup is, and what reduces it.

How a Fingerprint Gets Built

Passive signals like user agent, language, and timezone, and active signals like canvas, WebGL, and audio, both combining into one identifier that's often unique

A fingerprint isn't one signal. It's dozens of small, individually unremarkable details, combined.

Passive signals arrive with every request, no JavaScript needed. Your user agent string, browser language, timezone, and screen resolution get sent as a normal part of loading a page. Plenty of people share your timezone and your screen size.

Active signals come from small scripts that run the moment a page loads. Canvas fingerprinting asks your browser to draw a hidden image and reports back the exact pixels it produced. Small differences in your graphics driver, font rendering, and operating system produce a different result on almost every device. WebGL fingerprinting does the same thing with 3D rendering, exposing details about your specific graphics hardware. AudioContext fingerprinting runs an audio signal through your device's audio stack and measures how it comes out, which varies by hardware and drivers in ways you'd never notice by ear. A script can detect installed fonts by measuring how text renders at different sizes. It can sometimes detect installed extensions too, based on how they modify the page.

Ten million people might share your timezone. A few hundred thousand might match your exact canvas rendering hash. Tens of thousands might match your specific font list. None of these identify you by themselves. A device that matches all of them at once, out of everyone visiting a site, often matches nobody else. Each additional signal narrows the crowd you're hiding in. Modern fingerprinting scripts collect twenty or thirty signals in the time it takes a page to load.

Fingerprinting vs Cookies

A cookie is something a site puts in your browser. Clear it, and the site loses the thread. Most people picture tracking this way, which is why clearing history feels like it should work.

Fingerprinting stores nothing on your device. There's nothing to find in your browser settings and nothing to delete. Your browser recalculates it fresh every time, from your device's actual characteristics, which don't change just because you cleared your cache.

Clear your cookies and browsing history, and the fingerprint stays the same, since it's built from hardware and settings rather than read from storage. Log into a new account, and the fingerprint stays the same, since it doesn't care what you're logged in as. Generate a new temporary email address, and it stays the same again, since your screen resolution, fonts, and graphics driver haven't changed.

If you've read can temporary email be traced, this is the mechanism behind that post's central point. Your email address and your fingerprint are two unrelated identifiers. Resetting one does nothing to the other.

How Unique Is Your Fingerprint?

It depends on your setup, and the numbers you'll see quoted measure you against a specific sample of visitors, not the whole internet.

Cover Your Tracks and similar tools like AmIUnique report your fingerprint's uniqueness against the pool of visitors they've measured, usually as "one in X browsers" or a bits-of-entropy score. A result showing you're unique among the last several thousand visitors tested is a useful signal about how identifiable your specific browser configuration is. Real-world tracking depends on the size and quality of the database doing the matching, so that result doesn't prove any particular company has identified you personally.

Unusual screen resolutions, a long list of installed fonts, uncommon extensions, and browser or OS combinations that aren't the current default all drive uniqueness up. A common, unmodified setup drives it down. Browsers designed for fingerprint resistance build on that second point, covered below.

Test your own browser at Cover Your Tracks or AmIUnique. Both are free and show which of your signals are contributing most to your uniqueness score.

Does a VPN Stop Fingerprinting?

No. A VPN changes your IP address, which affects your apparent location and which server you appear to connect from. It has no effect on canvas rendering, installed fonts, screen resolution, or any other signal fingerprinting reads from your browser and device. You can be behind a VPN in a different country and still present the exact same fingerprint you had before connecting.

VPN and temp email marketing sometimes blur into a general promise of "privacy" without specifying what each tool covers. For the full breakdown of what a VPN protects against, see temp email vs VPN: what's the difference and which do you need.

Does Incognito or Private Browsing Stop Fingerprinting?

No. Private browsing mode stops your browser from saving history, cookies, and site data after you close the window. That's a change to what gets written to disk. It has no bearing on what your browser sends to the website you're visiting during the session.

Your screen resolution, installed fonts, canvas rendering, timezone, and every other fingerprinting signal are identical in a private window and a normal one. Fingerprinting never reads stored data. It reads your device.

What Reduces Fingerprinting Exposure

Three different approaches exist.

Brave randomises. By default it varies signals like canvas output and font metrics slightly on each site visit, so the fingerprint you present today doesn't match the one you presented yesterday. That breaks long-term tracking without breaking the page.

Firefox blends in. Strict tracking protection reduces the precision of several signals, rounding your timezone and standardising some rendering behaviour, so more users share the same values and any individual browser stands out less.

Tor Browser goes furthest. Instead of randomising or reducing signals, it makes every Tor Browser user's fingerprint look identical to every other Tor Browser user's, on the theory that a fingerprint shared by everyone identifies no one. That's a different strategy from the other two, and part of why Tor Browser looks and behaves differently from a standard browser with privacy settings turned up.

None of these eliminate fingerprinting. Running an unusual combination of privacy extensions can make you more unique, since the combination itself is a signal. The goal is reducing how reliably you can be singled out, not hitting zero.

Where Fingerprinting Fits in a Privacy Stack

Fingerprinting, IP address, cookies, and your email address are four separate identifiers, and no single tool covers all four. Can temporary email be traced breaks down the full picture: email address hidden by temp mail, the other three needing their own tools layered on top. A VPN for IP. A fingerprint-resistant browser for this. Cookie hygiene for the rest.

Frequently Asked Questions

Is browser fingerprinting illegal?

Not on its own. In the UK and EU, fingerprinting used for tracking purposes generally falls under the same consent requirements as cookies under GDPR and the ePrivacy Directive, since both identify a device without the user's explicit awareness. Enforcement varies, and many sites use fingerprinting for fraud detection, where the legal basis differs from marketing tracking. This area is unsettled.

Can I opt out of browser fingerprinting?

There's no universal opt-out the way there sometimes is for cookies. Fingerprinting reads what your browser already exposes without needing your consent. The practical opt-out is reducing what your browser exposes, through the browser-level approaches above.

Does clearing cookies reset my fingerprint?

No. Cookies are stored data. A fingerprint is recalculated from your device's characteristics every time. Clearing cookies has no effect on canvas rendering, fonts, screen resolution, or any other fingerprinting signal.

Is fingerprinting worse than cookies?

They're different threats. Cookies are easier to detect and clear but require the site to store something. Fingerprinting requires no storage and survives clearing, private browsing, and new logins, though it links sessions less precisely than a persistent cookie ID under ideal conditions. Sites increasingly use both together, which works better than either alone.

Does a temporary email address affect my fingerprint?

No. A temp email address changes what a site knows about your email identity. It has no effect on your screen resolution, fonts, canvas rendering, or any other fingerprinting signal, since your browser and device generate your fingerprint, not anything you type into a sign-up form.

The Bottom Line

Fingerprinting identifies you by reading what your browser already reveals, not by storing anything on your device. It survives the things people rely on to stay untracked: clearing cookies, going incognito, switching accounts, using a fresh temp email address. None of those change your actual browser and device configuration, so none of those touch it.

A fingerprint-resistant browser changes what your browser exposes. The tools built for other privacy problems don't. If you're building out a fuller privacy stack, can temporary email be traced covers where fingerprinting fits alongside IP address, cookies, and email identity, and what closes each of those gaps.

Generate a free temporary email address โ†’

โšก Try VanishInbox free

Generate a disposable email instantly โ€” no sign-up, auto-deletes in 10 minutes.

Get my free temp email โ†’
โ† Back to all posts