Priviy
privacy-basicsINFO

Browser Fingerprinting Test: What the Score Means, and Why Fixing It Is a Trap

Fingerprinting tests give you a uniqueness score in seconds. What that number is actually measuring, why a hardened browser can score worse than a plain one, and the trade-off nobody resolves cleanly.

By Eric Gerard · Editor · Priviy3 min readPhoto via Pexels

A fingerprinting test takes about three seconds and gives you a number. The number is real. What it means is narrower than the page implies.

What the score is actually comparing

The test reads what your browser volunteers during ordinary use: screen dimensions, timezone, language, font list, how your graphics stack draws a curve, which extensions alter the page. It combines those into a signature and compares it against the visitors that particular test has seen.

That is the first thing worth knowing. "One in 250,000" means one in that site's pool, and the pool of people who run fingerprinting tests is not a normal sample of the internet. It skews heavily toward people already running unusual configurations. Your score against that crowd is not your score against the crowd you actually browse in.

Why the obvious fix makes it worse

The instinct is to install something that spoofs the values. Here is the documented failure mode.

Inconsistency is distinctive. A browser claiming a user agent that does not match its rendering behaviour, or a screen size that no shipped device has, is not blending in. It is announcing that something is modifying it, and that fact is now part of the signature.

Randomising per session is distinctive too. Almost nobody has a screen resolution that changes every visit. A value that never repeats is a value that says "this is the person who randomises".

This is why the browsers that take fingerprinting seriously do the opposite of disguise. They aim to make all their users identical, with fixed window dimensions and features switched off, so the crowd is large and uniform. It works, and it costs you things you will notice.

Two hands opening a beige card folder tied with string, holding a fingerprint record sheet with a newspaper clipping stapled beside it, on a wooden desk lit warmly from one side.
Two hands opening a beige card folder tied with string, holding a fingerprint record sheet with a newspaper clipping stapled beside it, on a wooden desk lit warmly from one side.

The analogy holds in one direction only. A fingerprint on paper identifies a person; a browser fingerprint identifies a configuration. Change the machine and it changes, which is both the reason it is weaker than it sounds and the reason it is harder to remove than people expect.

The trade-off nobody resolves cleanly

You can be anonymous in a crowd or invisible alone, and the web only offers the first.

Every step toward uniqueness-reduction costs usability: fixed window size, disabled canvas, missing fonts, broken video on some sites. Every step toward comfort adds signal. There is no configuration that is both ordinary and untrackable, and any guide claiming otherwise has not tested its own advice against a second measurement.

We are not going to hand you a settings list that makes your score go green. A green score on one test says nothing about the next one, because each test compares you against its own pool.

What to do instead, ranked by effect

  1. Separate rather than disguise. A distinct browser profile or container for the activity you want kept apart, with no logged-in account inside it. This defeats linking without requiring you to look like nobody, and it is the single most effective item here.
  2. Do not sign in. A login makes the entire fingerprint question academic.
  3. Then, if your threat model needs it, use a browser built to make its users look alike, and accept the cost.
  4. Run the test twice, on two different services, before believing any score.

Where this stops mattering

If you are logged into an account, fingerprinting is irrelevant to that site: it knows exactly who you are. If your concern is your internet provider or the cafe wifi rather than the sites you visit, fingerprinting is the wrong thing to worry about, and encryption is the right one.

Fingerprinting is a linking problem, not an exposure problem. It tells a site that today's visitor is yesterday's visitor. Knowing which of those two problems you have decides everything you should do next, and most advice on this topic never asks.

Frequently asked questions

What does a browser fingerprinting test actually measure?
It reads the values your browser hands over during normal operation, then compares that combination against the other visitors that particular test has seen. Screen size, timezone, language, installed fonts, how your graphics stack renders a shape, which extensions modify the page. The output is a uniqueness score, and it is a score relative to that site's own visitor pool, not to the internet. That distinction matters more than most people realise.
Is a unique fingerprint dangerous?
It means a site can recognise you across visits without cookies, and across sessions you believed were separate. Whether that is dangerous depends entirely on what you are protecting. For most people it is a tracking concern rather than a safety one. For someone whose threat model includes being linked to a specific identity, it is the main problem, and no VPN addresses it.
Does a VPN change my fingerprint?
Barely, and it can make it stranger. The fingerprint is read from the browser, not from the network, so the tunnel does not touch it. What does change is your apparent location, which can now contradict your timezone and language settings. A browser reporting a Berlin timezone over an IP that says Toronto is a rarer combination than either would be on its own.
Should I install anti-fingerprinting extensions?
Cautiously, because the obvious fix has a well-documented failure mode. An extension that spoofs values gives you an inconsistent set of answers, and inconsistency is itself distinctive. Randomising per session can also be distinctive, because almost nobody has a screen size that changes every visit. The approaches that work aim for a large crowd of identical users rather than for uniqueness, which is why they ship with fixed window sizes and disabled features you may miss.
What actually reduces fingerprinting risk?
Separation, more than disguise. Keep the activity you want unlinked in a distinct browser profile or container, and do not sign in to anything that identifies you inside it. That defeats linking without requiring you to look like nobody, which is a fight the browser cannot win outright. Then, if it fits your threat model, use a browser designed to make its users look alike and accept the usability cost that comes with it.
Choix éditorial
4.5 / 5

Store your files privately → pCloud

Swiss privacy · 10 GB free · optional zero-knowledge Crypto

Société suisse depuis 2013Satisfait ou remboursé 10jFree 10 GB
Voir l'offre