What Is a Device Fingerprint Made Of?
The short answer to how does device fingerprinting work is that a script on the page reads several dozen attributes your browser exposes by design — screen geometry, fonts, canvas pixels, WebGL renderer strings, audio output, timezone — and hashes them into one short identifier. Nothing is written to your disk. The identifier lives on the server, where it is matched against everything that machine has shown before, and it survives cookie clearing, IP changes and even a switch to a different browser on the same computer.
📌 TL;DR Executive Summary
- Core Takeaway: A device fingerprint is a composite of browser and hardware attributes that survives cookie clearing, IP changes and switching browsers on the same machine.
- Key Risk/Challenge: Fingerprints follow the device, not the account — so every profile you run on one computer looks like the same visitor unless each profile’s signals are genuinely different and internally coherent.
- Recommended Solution: Spoof at the engine level, not with script patches. Send.win ships canvas, WebGL, audio, font and hardware spoofing per profile, plus built-in residential proxies on every plan.
A device fingerprint is information about the software and hardware of a remote device, usually compressed by a fingerprinting algorithm into a brief identifier. It needs no stored file and no permission prompt, and it identifies a device even when cookies cannot be read or stored, the IP is hidden, or the user opens a second browser on the same machine.
Primitive attributes combine into a near-unique composite
Almost every single signal is weak on its own. A default user agent string matches millions of machines; a common screen resolution matches millions more. Each attribute you add narrows the matching population, and the intersection of twenty of them lands on one device.
EFF’s Panopticlick project collected 470,161 fingerprints and found 83.6% were unique — 94.2% once Flash or Java was present. Later measurements moved the other way: 89.4% unique in the 2016 AmIUnique study, then 33.6% in a 2018 study, with mobile devices at just 18.5%. Uniqueness depends heavily on how much noise the browser injects, and browsers have injected a lot since 2010.
The signal groups inside a modern fingerprint
- Rendering: canvas pixel hashes via the Canvas API, WebGL vendor and renderer strings, shader output.
- Audio: the Web Audio API — an oscillator routed through a compressor produces measurably different output per audio stack.
- Fonts: enumeration by measuring text width for thousands of candidate font names. 34% of users can be identified from the 43 characters of their installed fonts, and 56.86% have unique browser extension sets.
- Hardware: CPU core count, device memory, screen geometry, device pixel ratio, number of cameras and microphones.
- Locale and time: timezone, language preferences, date and number formatting output.
- Transport layer: TLS ClientHello shape, HTTP header order, HTTP/2 settings frames — all measured server-side.
If you want to see how much entropy each of these carries, the breakdown in what a browser fingerprint is is worth reading alongside this one.
How Does Device Fingerprinting Work Under the Hood?
Collection, hashing and matching happen at three different layers, and each layer answers part of the same question: how does device fingerprinting work at collection, at the socket, and inside the matching engine. Knowing which layer produces which signal tells you where a fix actually has to live.
Step 1 — Collection in JavaScript
Canvas fingerprinting is the clearest example. The script draws a text string with a chosen font and background colour, calls the Canvas API’s ToDataURL() to get back Base64 PNG data, then hashes those encoded pixels. Anti-aliasing and rasterisation differ by GPU and graphics driver, so the hash differs by machine too. The technique was described by Acar and colleagues in 2014; by that year 5.5% of the Alexa top 10,000 sites were running canvas fingerprinting scripts across 20 domains, with the widget company AddThis serving 95% of them.
Its standalone power is modest. In a 294-participant study, canvas fingerprinting carried about 5.7 bits of entropy — nowhere near unique on its own, but additive on top of everything else. Tor Project documentation from 2018 called the HTML5 canvas the single largest fingerprinting threat browsers face after plugins; Tor Browser now notifies you about canvas read attempts and can return blank image data instead. The full script-level mechanics are covered in this canvas fingerprinting pipeline guide.
The concept has since moved deeper into hardware. DrawnApart, published in 2022, fingerprinted graphics hardware performance characteristics — including tiny differences between nominally identical GPUs of the same model — and boosted tracking duration of individual fingerprints by 67% when layered onto other methods.
Step 2 — Server-side and transport signals
Some of what identifies you never executes in JavaScript. JA4 TLS fingerprints derive from the order and contents of your TLS ClientHello; HTTP header ordering and HTTP/2 frame settings are observed at the socket. A page-level script override cannot change any of it, which is why sloppy spoofing shows up as a JavaScript environment that disagrees with the network traffic underneath it.
Step 3 — Fuzzy matching and confidence scores
Real systems do not store one hash and compare it for equality. They collect signals, compute a signature, compare it against recently seen signatures, resolve it to a visitor ID, and return that ID with a confidence score. Fuzzy matching absorbs fingerprint drift: install a font, apply a browser update, plug in a monitor, and you still match your previous signature — just with a lower score.
Step 4 — First-party serving
How the agent is delivered matters as much as what it collects. Serving a fingerprinting script from the site’s own first-party domain reduces blocking and stripping by ad blockers and privacy extensions, because third-party blocklists no longer apply. This is one reason blocking extensions lose ground against commercial detection.
Device Fingerprints vs Cookies vs IP Addresses
These identifiers behave differently under the same cleanup routine, which is the whole reason fingerprinting exists as a discipline.
| Identifier | Where it lives | Survives clearing cookies | Survives a new browser on the same device | Survives a VPN change |
|---|---|---|---|---|
| HTTP cookie | Browser storage, per domain | No | No | Yes |
| Local storage / IndexedDB | Browser storage | Only if site data is cleared | No | Yes |
| IP address | Network layer | Yes | Yes | No |
| Device fingerprint | Server-side only | Yes | Usually yes | Yes |
Fingerprint IDs persist longer than cookies or IP addresses precisely because the hardware and software attributes they measure change infrequently. A cookie can be deleted in two clicks; a graphics driver cannot be argued with.
Transport-level identifiers follow the same logic. TLS handshake shape sits between the fingerprint and the network layer, which is why JA3 fingerprinting still catches tools that spoofed everything visible in the page.
Who Fingerprinting Affects, and Under What Rules
Fraud defense and bot detection
Banks, marketplaces, ad networks and ticketing platforms lean on device intelligence because the alternatives have weakened. Google has reported that advanced bots now beat many visual CAPTCHAs at rates above 99%, so signal-based detection carries more weight than puzzle-solving ever did. Automated environments also betray themselves through inconsistency: headless and containerised bots frequently produce mismatched screen resolutions, implausible font combinations and hardware values no shipping device would emit.
Multi-account work
If you run several seller accounts, ad accounts or social profiles from one computer, the device layer is where they get linked. The question sharpens at that scale: how does device fingerprinting work when one machine runs a dozen accounts? The canvas hash, WebGL renderer, font stack and audio output are the same for every one of them, no matter how many logins and proxies you layer on top. Cloned profiles make this worse, because a duplicated environment produces an identical fingerprint under a different account name.
The legal layer: GDPR, ePrivacy and CCPA
Under GDPR, a device fingerprint that can single out a user counts as personal data even without a name attached. Fraud prevention can generally rely on legitimate interest; marketing generally requires consent. The ePrivacy Directive goes further, governing any storing of or access to information on a user’s device regardless of whether it is personal data, with consent as the default and only narrow exemptions. Regulators key these rules to purpose rather than technology, so cookie consent rules generally apply to fingerprinting too.
In California, Civil Code §1798.140(v)(1)(A) defines personal information to include unique personal identifiers, and §1798.140(aj) names probabilistic identifiers as an example — which is what a browser fingerprint is by construction. Civil penalties are capped at $2,500 per violation and $7,500 per intentional violation or one involving a minor’s data. The Attorney General’s August 2022 settlement with Sephora ($1.2M) confirmed that the Global Privacy Control browser signal is a legally recognised opt-out of sale that must be processed server-side. CPRA, effective 1 January 2023, added the California Privacy Protection Agency and new rights to correct and to limit use of sensitive personal information.
How to Check and Reduce Your Own Fingerprint
Work through these in order. Each step tells you something the next one depends on.
- Measure before you change anything. Open a fingerprint test page in two fresh sessions and compare. Signals that stay identical across both are the ones carrying your identity.
- Enable browser-level protection. Firefox fingerprinting protection blocks known fingerprinters, limits suspected ones, introduces randomised data in HTML5 canvas readback, and restricts font visibility in stricter modes. Tor Browser warns you about canvas reads and can return blank image data.
- Stop trusting incognito. Private mode drops cookies and local storage. It does not touch canvas, WebGL, audio, fonts, core count, memory or screen geometry — the attributes that actually identify you.
- Audit the hardware layer. Compare CPU core count, device memory, screen width and height, pixel ratio, and camera and microphone counts against what a real device of your claimed model would report.
- Check timezone and language against your exit IP. A browser set to UTC while the connection exits in Frankfurt is a mismatch, and mismatches are easier to detect than spoofed values.
- Separate identities by environment, not by tab. Tabs share one fingerprint. Any setup that keeps two accounts on one browser engine keeps them linked.
- Re-test after every browser or OS update. Driver and font updates shift rendering output, so a configuration that matched yesterday can drift today.
Common Mistakes That Make Fingerprints Inconsistent
- Randomising everything. Injecting noise into every readable value creates an unusual, high-entropy profile. Random values also change between page loads, and a fingerprint that changes on every request looks less like a real user, not more.
- Patching one layer in JavaScript. Overriding navigator.userAgent while canvas, WebGL and audio still return native output leaves an environment that contradicts itself. Detection engines compare layers.
- Incoherent composites. A Windows user agent paired with a Mac font stack, a mobile user agent with desktop screen geometry, or a residential proxy in one country with a browser locale from another — each is a single-flag detection.
- Cloning a profile. Duplicating a configured profile duplicates its fingerprint. Two accounts, one device signature.
- Rotating proxies against a fixed fingerprint. Stable device, changing IP, many accounts — that pattern reads as automation regardless of how clean each individual signal looks.
- Counting on extensions. Third-party canvas blockers are defeated by first-party script delivery, can be detected themselves, and often break page rendering. The reasons are laid out in anti-fingerprinting extensions that quietly fail.
- Leaving headless defaults in place. Default viewport sizes, missing font families and automation flags are the easiest inconsistencies to spot from the outside.
How Send.win Helps With How Does Device Fingerprinting Work
Send.win is an antidetect browser built for exactly this kind of work — every profile is a clean, isolated identity:
- Isolated profiles – unique fingerprint, separate cookies and storage per profile
- Stealth engine – canvas, WebGL, fonts, and audio spoofed at the engine level
- Desktop app + cloud sessions – native app for Windows, macOS, and Linux, or run profiles in the cloud with no install
- Built-in residential proxies – with automatic timezone, locale, and WebRTC matching
- Team features – share logged-in profiles with teammates without sharing passwords
Try the instant cloud browser demo — no install, no signup — or download the desktop app. The 30-day free trial needs no credit card, and paid plans start at $6.99/month billed annually (see pricing).
Why Coherent Spoofing Beats Patching One Signal
If fingerprints are composites compared layer by layer, then the fix has to be a composite too. Spoofing one signal and leaving five native is worse than changing nothing, because the mismatch itself becomes a detectable attribute. The workable approach is a per-profile environment where canvas, WebGL, audio, fonts and hardware values are generated together and stay consistent with the proxy the profile exits through.
That is the design behind Sendwin Browser, a patched-Chromium desktop app for Windows 10/11, macOS 12+ and Linux with the Sendwin Stealth engine built in. Spoofing happens at the engine level rather than through script injection, so the values survive a page that re-reads them and no two profiles share a fingerprint. Timezone, locale, WebRTC and geolocation follow the proxy’s exit IP automatically, and every plan includes built-in residential proxies plus bring-your-own HTTP/SOCKS5 — which removes the geography mismatch class entirely. The same profiles can also run in the cloud browser on Send.win’s EU and US nodes when you need a session from a device that has nothing installed.
If you drive profiles from code, the local Automation API on the Team plan works with Selenium, Puppeteer and Playwright. Connect to a running profile and read back exactly what the environment reports:
from playwright.sync_api import sync_playwright
# Copy this URL from the profile's automation settings panel.
CDP_URL = "http://127.0.0.1:PORT"
with sync_playwright() as p:
browser = p.chromium.connect_over_cdp(CDP_URL)
context = browser.contexts[0]
page = context.new_page()
page.goto("https://example.com")
signals = page.evaluate("""() => ({
ua: navigator.userAgent,
cores: navigator.hardwareConcurrency,
memory: navigator.deviceMemory,
tz: Intl.DateTimeFormat().resolvedOptions().timeZone,
screen: [screen.width, screen.height, window.devicePixelRatio]
})""")
print(signals)
browser.close()
Run that against two profiles and compare the dictionaries. Matching values between profiles mean the two identities are linked; values that contradict the profile’s proxy location mean the environment needs to be rerolled before you log in anywhere.
🏆 Send.win Verdict
Fingerprinting works by combining many weak signals into one strong, server-side identifier that cookies and proxies cannot erase. That makes patching a single value pointless and coherent per-profile spoofing the only approach that holds. Send.win is built for that job — engine-level spoofing instead of brittle script injection, residential proxies included on every plan, and a setup that still works when you add teammates or automation.
Try Send.win free today — 30 days of the full desktop browser at $0, cancel anytime, your profiles stay on your machine.
Frequently Asked Questions
How does device fingerprinting work without cookies?
It never needs storage on your device. The script reads attributes the browser exposes for rendering and media purposes, hashes them, and sends the result to the server, which keeps the record. Clearing cookies removes the site’s stored file but leaves your graphics driver, font stack and screen geometry exactly as they were, so the next visit recomputes the same identifier.
What information is included in a device fingerprint?
Typically canvas and WebGL rendering output, Web Audio processing differences, enumerated fonts, screen geometry and pixel ratio, timezone and language, CPU core count and device memory, camera and microphone counts, plus server-side signals like TLS handshake shape and header ordering. Individually they are weak; combined they narrow to a single device.
Can you delete or clear a device fingerprint?
You cannot delete the identifier, because it is not stored on your machine. You can only change the inputs that produce it — the rendering, audio, font and hardware signals behind it. Ordinary browser settings do not do that, and extensions typically affect only part of the picture.
How does device fingerprinting work in incognito mode?
Exactly the same way it works in a normal window, which is why private mode does not help. Private browsing drops cookies and local storage when you close the window, but canvas readback, WebGL output, audio behaviour, fonts and hardware values are untouched. Sites routinely use fingerprints as a fallback precisely because private mode removes the easier identifiers.
How do you prevent device fingerprinting?
You reduce or control it rather than stop it. Firefox blocks known fingerprinters and randomises canvas readback, and Tor Browser can return blank canvas data. For multi-account work the practical answer is isolation — a separate browser environment per identity, with signals that are internally coherent and different from every other profile on the same machine.
Is device fingerprinting legal under GDPR?
A fingerprint that can single out a user is personal data even without a name, so GDPR applies. Fraud prevention can usually rely on legitimate interest; marketing and analytics generally require consent. The ePrivacy Directive adds a separate layer, covering any access to information on a user’s device regardless of whether it is personal data.
Do I need consent for fingerprinting used only for fraud prevention?
Often not under GDPR, where fraud prevention is a recognised legitimate interest, but ePrivacy’s device-access rule can still require consent because it governs the act of reading the device rather than the purpose behind it. National implementations differ, so the answer depends on where your users are.
How does canvas fingerprinting work?
The script draws text with a chosen font and background colour onto an invisible canvas, then calls ToDataURL() and hashes the resulting Base64 pixel data. Anti-aliasing and rasterisation vary by GPU and driver, so the hash varies by machine. Alone it carries only a few bits of entropy, but it slots neatly into a larger composite.