Privacy

Fingerprinting

Also called device fingerprint.

Fingerprinting is building a likely-unique signature from device and browser traits instead of storing an ID. Fonts, screen size, graphics output, and language settings are typical inputs.

How it is measured

A script reads dozens of attributes and combines them into a hash. If the combination is rare, it works like an ID. Test by running the same script on two browsers and comparing outputs.

The strength depends on entropy. A fingerprint that matches 1 in 2,000 browsers is weak. One that matches 1 in 200,000 follows people reliably.

Worked example

A researcher tests a fingerprint script on 3,000 volunteers. 2,100 get a unique value. After a browser update, 400 of them change value, which shows a fingerprint is less stable than it first looks.

The ad vendor using it must now re-match those people by other signals.

How it differs

Fingerprinting derives an ID from traits. Cookieless tracking avoids any lasting ID. Fingerprinting excludes the stored key but still tracks; cookieless excludes both the stored key and the signature.

Common errors

Calling it privacy-friendly. Believing no consent is needed because nothing is stored. Using it silently. Ignoring that browsers now resist it. Treating a fingerprint as stable.

In practice

Check your scripts and vendors for fingerprinting. Ask them directly. Remove any that cannot say no.

See also

Cookieless tracking, Device ID, Personal data

Sources

Count this on a real site.

Watch my website