Browser Fingerprinting: How Sites Recognize You Without Cookies
Cookies are the tip of the tracking iceberg. How fingerprinting works, what signals your browser broadcasts, and realistic defences that don't break the web.
Published · Updated · 7 min read
Delete your cookies and websites can still recognize you. That's not paranoia, it's browser fingerprinting, and it works because every browser's combination of fonts, screen size, graphics stack, settings and quirks forms a description rare enough to act as an identifier. Studies repeatedly find most desktop browsers uniquely identifiable out of the box. No storage is touched, no permission asked, and clearing data changes nothing.
Here's how the technique actually works, what you're broadcasting right now, and which countermeasures help without turning the web unusable.
What goes into a fingerprint
Individually these attributes are mundane. Combined, they behave like a hash: stable across days, distinctive across users, and computable by any page within milliseconds. Our Hash & Encoding Lab demonstrates the hashing half of that equation if you want to see how easily arbitrary data collapses into a compact identifier.
- User agent and platform strings, browser family, version, operating system.
- Screen resolution, color depth, pixel ratio and window dimensions.
- Installed fonts (probed via measurement tricks), a surprisingly strong differentiator.
- Canvas and WebGL rendering quirks, identical drawing instructions produce per-GPU pixel noise.
- Audio stack timing signatures, timezone, language list, CPU core count and memory hints.
- Enabled extensions, ad-blockers and privacy settings themselves.
Why blocking cookies didn't kill tracking
Third-party cookie phase-outs pushed the advertising industry toward alternatives, and fingerprinting tops the list because it requires no cooperation from the user's browser. Privacy regulations complicate things, device signals usually count as personal data requiring consent, but enforcement lags technique, and consent banners rarely mention fingerprints explicitly.
Defences ranked by realism
- Use a browser with anti-fingerprinting built in. Firefox and Brave actively randomize or homogenize canvas, audio and font APIs; Tor Browser forces everyone into identical configurations, making the crowd uniform.
- Keep your browser updated and moderately hardened: block third-party scripts by default where tolerable (uBlock Origin's medium mode is a sane middle ground).
- Resist exotic uniqueness. Obscure browser builds and rare extension combinations make you more identifiable, not less, blend into the herd.
- Separate contexts: different browser profiles (or containers) for work, personal and shopping reduces cross-context joining.
- On mobile, prefer per-app browsers, which sandbox storage and limit script access between apps.
What doesn't work
- Clearing cookies religiously, fingerprints ignore storage entirely.
- Incognito mode as anonymity, it limits local traces, not network-side identification.
- Free VPNs as privacy tools, they relocate your IP but centralize trust in an unaccountable party, and do nothing about fingerprinting.
- Disabling JavaScript sitewide, effective but breaks most of the modern web, so people revert within days.
A proportionate mindset
Perfect anonymity online is impractical; reducing linkability is achievable. The goal isn't vanishing, it's ensuring advertisers can't stitch your Tuesday browsing to your Friday purchases, and that data brokers accumulate less raw material about you. Uniform browser, aggressive script-blocking, context separation and periodic self-audits get you most of the benefit at a fraction of the inconvenience.
Curious what your own setup broadcasts? Fingerprint-testing sites visualize your browser's uniqueness in real time, and our OSINT beginner's guide extends the audit to your broader public footprint. Small configuration changes compound into a much smaller shadow.