Canvas fingerprinting is one of the more technically specific fingerprinting methods — exploiting small, consistent differences in how different devices render graphics, rather than relying on explicitly declared browser settings.
How it actually works
A webpage can instruct your browser to draw text or shapes onto a hidden HTML canvas element, then read back the resulting pixel data. Due to differences in graphics hardware, drivers, font rendering, and anti-aliasing across different devices and configurations, the exact pixel output can vary in small, consistent ways — differences imperceptible to a human eye but detectable and hashable by a script.
Why this produces a stable identifier
Because the same device with the same configuration tends to produce the same rendering output consistently, the resulting hash can serve as a relatively stable identifier across browsing sessions — similar in spirit to other fingerprinting techniques, but based on a rendering quirk rather than an explicitly reported browser setting.
Stability and its limits
Canvas fingerprints are reasonably stable for a given device/browser/OS combination, but can change with graphics driver updates, browser updates, or hardware changes — meaning they're a strong but not permanent identifier.
Permissions and defenses
Because canvas fingerprinting doesn't require any special permission — it uses a standard, widely-supported web API — it's harder to block through permission prompts alone. Some browsers have implemented specific defenses: adding subtle, randomized noise to canvas output, or prompting users before allowing canvas data extraction on suspicious scripts.
FAQ
How do I know if a site is using canvas fingerprinting?
It's not visible without technical inspection tools — browser privacy extensions that specifically detect and block canvas fingerprinting attempts are the practical way to gain visibility and protection.