Cookies and fingerprinting both aim to recognize a returning visitor, but they work in fundamentally different ways — and those differences directly determine which privacy defenses are actually effective against each.
Storage
A cookie is explicitly stored data on your device, set by a site or third party. A fingerprint is derived, not stored — computed on the fly from characteristics your browser already exposes as part of normal operation, with nothing saved locally to identify.
Deletability
Cookies can be cleared directly through browser settings, removing the stored identifier entirely. A fingerprint can't be "deleted" the same way, since there's no stored file — it can only be changed by altering the underlying characteristics it's derived from (which isn't always practical).
Consent and disclosure
Cookie usage is subject to explicit consent requirements in many jurisdictions (the basis for cookie-consent banners), a legal framework that generally hasn't been applied with the same specificity to fingerprinting, which operates more invisibly.
Stability
Cookies persist exactly until deleted or expired — fully under the user's control once they know to act. Fingerprints can drift over time as software updates, hardware changes, or settings adjustments alter the underlying characteristics, making them somewhat less stable long-term but harder to intentionally reset on demand.
Scope
A cookie is typically scoped to a specific domain (with third-party cookies as the cross-site exception). A fingerprint, being derived from browser-level characteristics, can potentially be computed and compared across entirely unrelated sites without any explicit cross-site mechanism required.
Accuracy
A cookie, when present, is a highly reliable identifier — nearly always correctly re-identifies the same browser. Fingerprinting is probabilistic, with accuracy depending on how distinctive a given browser's combination of characteristics actually is within the broader population.
FAQ
Which is easier for a site to defend or attack privacy with?
Cookies are easier for users to defend against (clearing/blocking is straightforward and visible); fingerprinting is harder to defend against precisely because it doesn't rely on anything a user can simply delete.