Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Browser fingerprinting is the attempt to recognise a browser from a combination of characteristics it exposes to websites. A VPN can change the apparent network address of a connection, but it does not automatically change the browser’s rendering, language or hardware-related signals.[1] Treat network privacy and browser privacy as separate decisions.
Key Takeaways
- A fingerprint is an inferred pattern, rather than a file you can simply delete.
- Several ordinary attributes can become distinctive when combined.
- A test describes its observations and comparison population; it cannot certify anonymity.
- Prefer maintained browser protections to a collection of unexplained spoofing extensions.
Imagine two visitors using the same browser family. One uses a common language and display configuration; the other combines several languages, unusual font availability and a different graphics environment. None of those observations necessarily identifies a person alone. The combination gives an observer a better way to distinguish the visits. MDN describes this collection-and-combination mechanism as fingerprinting.[1]
The observer does not need to learn your name to create a useful identifier. It may first label a cluster of visits as belonging to the same browser, then associate that cluster with an account login or a transaction. Recognition and real-world identification are different stages. A claim that a test “knows who you are” therefore needs more evidence than a distinctive result.
Nor is a fingerprint an immutable serial number. Updates, different displays and browser protections can alter the observed pattern. A tracker might still match similar patterns rather than requiring every value to remain identical. W3C’s guidance distinguishes the availability and persistence of signals, helping explain why a short-lived observation and a cross-site, persistent characteristic deserve different concern.[2]
Consider a shared family laptop. Similar browser observations may describe the same device used by several people. Conversely, one person can use several devices with different fingerprints. Neither “same fingerprint means same human” nor “different fingerprint means unrelated humans” is a safe conclusion. Use this distinction when reading claims about tracking accuracy.
A page can receive some information with a request and obtain other information through browser features. MDN lists browser version, language, timezone, available codecs, fonts and display characteristics among possible inputs.[1] Availability varies with the browser, platform, permissions and protections; a list of possible inputs is not proof that every site collects all of them.
| Signal group | What the observation can describe | Why the interpretation needs care |
|---|---|---|
| Request information | Browser and content preferences sent to a server | Values may be reduced, generalised or shared by many visitors |
| Language and timezone | A configured environment | Settings are not reliable proof of nationality or current location |
| Display and input | Screen dimensions and input capabilities | An external display or window change can alter the observation |
| Rendering | The output of canvas or graphics operations | Browser defences may limit or modify what is exposed |
| Feature availability | Supported functionality and environment differences | Ordinary compatibility checks can resemble tracking inputs |
Canvas deserves particular explanation. It is a legitimate browser drawing facility. A fingerprinting script can ask it to render content and examine the output; differences in the environment may create differences in that result. EFF’s test includes canvas and WebGL observations, but a page using graphics is not automatically a malicious tracker.[3] Purpose, collection and correlation matter.
An extension list is also easy to overstate. A site does not universally receive a complete inventory of every modern browser extension. An extension may instead affect page behaviour in an observable way. Do not assume that a successful browser update exposes all installed software, or that a test label describes the implementation used by every advertising company.
The practical question is what a particular observer can actually obtain and link. Our guide to online trackers explains the broader collection ecosystem; this article focuses on the browser characteristics within it. Keeping that boundary makes it easier to choose the relevant defence.
A cookie can store an identifier for later requests. Clearing cookies rather than the cache removes that stored value from the browser, subject to the scope of what you clear. Fingerprinting tries to infer a pattern from observations, so deleting stored site data does not necessarily change the underlying pattern. EFF explicitly separates these mechanisms.[3] Cookies remain useful for legitimate sessions as well as tracking.
An IP address describes a connection’s apparent network origin. It can be shared by many users or change for one user. A fingerprint concerns browser observations; the two can be combined without becoming the same thing. Signing into an account introduces an even more direct identifier. That is why a clean browser session can still become associated with an existing profile after a login.
AethoVPN belongs to the network side of this distinction: changing the connection’s apparent IP is not a browser-fingerprint reset. For a fuller account of identities that survive a network change, read can you be tracked with a VPN?. Keep the browser’s protections enabled independently of the connection you choose.
TLS fingerprinting examines characteristics of a network handshake. It answers a different question from examining a page’s graphics or language environment. A successful browser test does not establish what a network observer can infer, just as a successful tunnel connection does not establish what a website can infer.
EFF’s Cover Your Tracks compares observed characteristics with those of other visitors to its research tool and tests selected tracking protections.[3] A uniqueness result is relative to that comparison set. It is not a census of all internet users, a probability that an advertiser has identified you or a measurement of every tracker’s success.
Before testing, decide what you want to learn. “Which attributes does this browser expose?” is a useful question. “Am I impossible to identify?” is not a result any single page can establish. Read the test’s methodology and privacy information before volunteering browser observations, especially if your circumstances make even a small additional disclosure unwelcome.
For an interpretable comparison, keep a short local record of the browser version, profile, privacy setting and extension configuration. Compare the same setup after one intentional change. Running one test on a phone and another on a laptop changes too many factors to attribute the difference to a single setting. There is no need to publish the resulting report or share the full fingerprint.
A result labelled distinctive is a reason to inspect the setup, rather than an instruction to keep changing settings until a green badge appears. A blocked test script may leave the tool with incomplete observations. A different comparison population may change a score even when your configuration is unchanged. Record functional breakage alongside the apparent privacy improvement.
Avoid interpreting the test as incident evidence. It cannot establish that your employer, former partner or a named advertising company has followed you. If your concern is a specific actor, use a personal threat model to connect that actor’s access with the information you want to protect. This prevents a generic score from becoming your entire privacy plan.
Browser vendors use different combinations of restricting exposed information and blocking recognised collection. Mozilla documents separate protection against known and suspected fingerprinters, with behaviour depending on Firefox’s protection mode.[4] Check the documentation for your actual browser and platform; a feature on one version or operating system does not establish equivalent protection elsewhere.
Start with a maintained browser and its documented privacy controls. Remove extensions you do not need, especially those with broad access to pages. This is a management choice as well as a fingerprinting choice: fewer unexplained components make it easier to understand an unexpected result and identify which change broke a site.
Blocking known trackers reduces some collection opportunities, but it cannot promise to block every new or first-party implementation. Reducing exposed values addresses a different part of the problem. W3C describes limiting available characteristics and increasing the number of users who share them as distinct mitigation approaches.[2] Look for an explanation of the mechanism, rather than a promise of being “undetectable.”
Be cautious with manually spoofing one attribute. If the rest of the browser still behaves differently, a changed label does not produce a coherent alternative environment. EFF warns that unusual combinations of protective settings can themselves be distinguishable.[5] Installing several overlapping “anti-detect” tools without understanding their interactions creates a difficult configuration to maintain.
Private browsing is useful for separating some local session state. It does not guarantee an unrecognisable rendering environment, prevent a website from keeping its own records or undo an account login. Browser-specific protections can still apply in that mode. Read the actual feature description instead of treating the word “private” as a universal anonymity claim.[5]
If a protection breaks a necessary service, consider a narrow exception and record why it is needed. A payment form failing after a browser setting changes is not a reason to disable every protection everywhere. Mozilla’s documentation describes site-specific exceptions; their scope matters when balancing privacy with access.[4] Review exceptions when the original problem no longer exists.
Use a small decision record rather than a contest for the lowest score. Write the intended outcome, the change, the observations and the cost. For example: “Reduce third-party collection during ordinary browsing; enable the documented stricter setting; compare the same profile; note any broken checkout or video call.” This is an illustrative record, not a report of tests we performed.
Keep changes that have a clear purpose and a tolerable maintenance cost. Revisit them after a major browser update, a change in your work requirements or a meaningful change in your threat model. Do not postpone security updates solely to preserve a familiar fingerprint. A privacy configuration is useful only if you can continue using and maintaining it.
Fingerprint protection is one part of a wider digital privacy plan. Account identity, permissions and device access can remain more direct paths to your information. The realistic goal is to reduce unnecessary recognition while preserving a usable, understood browser environment.
Yes. A website can combine browser observations without relying on a stored cookie identifier. Clearing cookies may still help with stored tracking state, but it does not necessarily change the characteristics used for fingerprinting.[3]
It does not guarantee that result. Private modes separate some session data, while fingerprint-related behaviour depends on the browser’s actual protections and the observations available to the site. Logging into an account also supplies an identity.[5]
No. Distinguishing a browser in a test population does not establish a real-world identity. An observer would need an additional link, such as account information, to connect that pattern with a named person.
There is no single fingerprint file to delete. You can clear stored site data and change what the browser exposes, but those are different actions and neither guarantees that past observations disappear.[1][3]
Not simply to improve a score. Overlapping tools can introduce unusual behaviour and break services. Prefer a maintained configuration whose controls and exceptions you understand, and evaluate a change against a specific purpose.[5]
No. Canvas is a normal drawing feature. Its output can be used as one fingerprinting input, but graphics use alone does not prove a page is collecting and correlating identifiers.[3]
It does not automatically change browser characteristics. An observer may see a different network origin alongside similar rendering or language signals, and account logins can associate those visits independently.[1]
Sources:
Sources checked 5 October 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.




