Browser fingerprinting doesn't rely on any single piece of information — it's the combination of many individually ordinary characteristics that, together, can make a specific browser instance identifiable across sessions, even with cookies fully disabled.

What contributes to a fingerprint

  • Screen resolution and color depth
  • Installed fonts
  • Browser and operating system version
  • Timezone and language settings
  • Installed plugins and their versions
  • Hardware characteristics exposed through certain browser APIs

Individually, most of these are common — many people share the same screen resolution or timezone. It's the specific combination across many characteristics simultaneously that becomes distinctive.

Why it works without cookies

Unlike a cookie, which is explicitly stored and can be deleted, a fingerprint is derived from characteristics your browser exposes as part of normal operation — there's no single piece of stored data to clear. This is exactly why fingerprinting is discussed as a cookie-independent tracking method, and why clearing cookies alone doesn't defeat it.

Why uniqueness varies by population

How identifying a fingerprint actually is depends on how common your specific combination of characteristics is within the broader population of browsers being compared against — a highly standard, common configuration is less uniquely identifying than an unusual one, though "average" configurations have become somewhat less common as fingerprinting awareness has grown.

What reduces fingerprinting exposure

Browsers increasingly standardize what they expose specifically to reduce fingerprint uniqueness, and some offer dedicated fingerprint-resistance modes. Using a widely common browser/OS/settings combination reduces (though doesn't eliminate) how distinctive your specific fingerprint is.

FAQ

Does a VPN protect against fingerprinting?

No — fingerprinting is independent of your IP address; a VPN changes your address but not your browser's other characteristics.