Browser fingerprinting
Building an identifier from browser and device characteristics exposed to JavaScript.
Browser fingerprinting assembles a large number of small, individually unremarkable properties into an identifier that is often unique. It runs in JavaScript once the page loads.
#Properties commonly collected
- Screen dimensions, colour depth, device pixel ratio.
- Installed fonts, detected by measuring rendered text.
- Canvas and WebGL output, which vary with GPU and driver.
- Audio stack behaviour.
- Timezone, language, platform, hardware concurrency.
- Available plugins and supported media types.
#Why automation is easy to spot
Headless browsers historically exposed direct tells such as navigator.webdriver. Those are patchable, but internal consistency is much harder to fake: a fingerprint claiming macOS with Linux font metrics, or a GPU renderer string that no consumer machine reports, stands out precisely because real devices are consistent.
#The practical implication
Changing your address does nothing here. A pristine residential exit combined with an implausible fingerprint is still identifiable — and the combination can look worse than either problem alone.
#Why the combination identifies you
No single property is rare. The combination is. A screen size shared by many people, a timezone shared by many people and a font list shared by many people can intersect on a very small group, or on one visitor.
This is why partial disguise often backfires. Changing one property to an unusual value does not blend you in; it moves you to a smaller group. A visitor claiming a common browser while reporting no fonts at all is more distinctive than either fact alone.
#Consistency is the requirement
| Property | Must agree with |
|---|---|
| User agent string | The TLS handshake and the header set |
| Claimed platform | Font list, canvas output and hardware hints |
| Timezone | The address geolocation and the reported locale |
| Language headers | The claimed country |
An exit in one country with a browser reporting another country’s timezone is a contradiction the address alone cannot fix. Set geo-targeting and the browser locale together, or neither.
#What actually reduces exposure
Use a real browser engine rather than emulating one, keep every property internally consistent, and prefer common values over unusual ones. A headless browser that has been made to look ordinary is far quieter than an HTTP client that claims to be a browser.