Online trackingExplainer
Browser fingerprinting: why clearing cookies isn't enough
Browser fingerprinting tracks you even without cookies. How unique a browser fingerprint really is, what signals it reads, and what actually helps.
Blocking cookies is a genuine privacy control, but it governs one thing: what a website is allowed to put on your device. Browser fingerprinting runs the opposite direction. It reads characteristics your browser hands over anyway — the headers it sends, the fonts it can render, the way it draws a shape on screen — and combines them into an identifier. Fingerprinting typically leaves nothing on your computer to find or delete, unlike a cookie file. That asymmetry is why cookie banners and "delete cookies" buttons leave a gap, and why both a standards body and a national regulator have written about the problem in unusually blunt language.
What is browser fingerprinting?
The World Wide Web Consortium (W3C), which writes the specifications browsers implement, published guidance for people designing web features on 25 September 2025. Its central observation is that a fingerprint isn't scoped to a single site the way a cookie is. Because the same combination of characteristics is visible everywhere, the W3C's fingerprinting guidance warns that "different sites may be able to combine information about a single user even where a cookie policy would block accessing of cookies between origins, because the fingerprint is relatively unique and the same for all origins".
A cookie is a file with a delete button. The W3C note says a browser fingerprint "typically cannot be cleared or re-set", so tracking happens without clear or effective user controls, and that clearing cookies or using a VPN does not prevent further correlation. Even an anonymity network isn't a fix: a user might employ onion routing such as Tor to limit network-level linkability "but still face the risk of correlating Web-based activity through browser fingerprinting."
What signals does fingerprinting read?
Fingerprinting splits into two kinds. Passive fingerprinting relies on characteristics observable in the contents of ordinary web requests, without any code running on your machine. According to the W3C, passive material includes cookies themselves, the set of HTTP request headers, and the IP address and other network-level information. The User-Agent header alone typically identifies the browser, renderer, version and operating system, and for some groups of users, the guidance notes, User-Agent combined with IP address is often enough on its own to uniquely identify a particular browser.
Active fingerprinting asks your browser questions: accessing window size, enumerating fonts or connected devices, evaluating performance characteristics, reading device sensors and rendering graphical patterns, such as canvas images. CSS, not just JavaScript, can be abused this way. Some signals are inferred rather than read directly: timing channels commonly deduce hardware details such as GPU capability, gauge network conditions from load speed, and even reveal what has been previously cached.
The UK's Information Commissioner's Office (ICO) publishes a similar catalogue in its guidance on storage and access technologies, naming clock information, TCP stack variation, installed fonts, browser plugins and the use of any APIs, alongside CSS information, JavaScript objects and HTTP header information, and noting these can be combined with IP addresses or other unique identifiers. The rules cover web browsers, mobile apps and connected devices alike.
How unique is a browser fingerprint, really?
The W3C offers a yardstick: roughly 30 bits of entropy would be enough to uniquely identify every individual person, and even a single distinguishing bit can single someone out, if they are the only person for whom it is true.
The canonical measurement is Peter Eckersley's Panopticlick paper, How Unique Is Your Web Browser?, published by the Electronic Frontier Foundation in 2010. Built from eight signals — User-Agent, HTTP Accept headers, cookie status, screen resolution, timezone, plugins, fonts and a supercookie test — the sample found 83.6% of browsers instantaneously unique, with a further 5.3% sharing a fingerprint with exactly one other browser. Among browsers with Flash or Java enabled — at the time, the usual route to enumerating fonts and plugins — 94.2% were instantaneously unique. The fingerprint carried at least 18.1 bits of entropy, roughly a one-in-286,777 chance another browser matches yours. Desktop browsers fared worst, around 90% unique; the least unique were browsers with JavaScript switched off. Plugins and fonts carried the most identifying information per signal, followed by User-Agent, HTTP Accept headers and screen resolution — but every signal proved uniquely identifying for someone.
Two caveats matter. The sample was self-selected and skewed toward privacy-conscious, technically educated users, and the paper's own authors declined to extrapolate it to the whole internet. It's also from 2010. What the W3C states today is narrower but still pointed: measured data has shown mobile devices to have substantially larger anonymity sets than desktop browsers.
The same paper dismantled the idea that fingerprints drift out of usefulness on their own. They do change — 37.4% of returning users showed at least one change — but a crude heuristic linked a changed fingerprint back to its earlier version with 99.1% of guesses correct. A print carrying only 15 to 20 bits, combined with an IP address, subnet or even just an ASN, was in almost all cases enough to pin down a particular browser, letting a tracker relink a freshly set cookie to an old profile.
A regulator's verdict: clearing site data doesn't reset you
The ICO addressed this directly on 19 December 2024, after Google told advertisers that "from 16 February 2025, it will no longer prohibit them from employing fingerprinting techniques." The regulator's response to that policy change explains the mismatch plainly: "Privacy controls are built around existing technologies. When you choose an option on a consent banner or 'clear all site data' in your browser, you are generally controlling the use of cookies and other traditional forms of local storage." Fingerprinting relies on signals you cannot easily wipe, it continues, so even after clearing all site data, "the organisation using fingerprinting techniques could immediately identify you again." The ICO is candid about the limits of self-help too: "Fingerprinting is harder for browsers to block and therefore, even privacy-conscious users will find this difficult to stop."
The ICO called the change to Google's policy irresponsible, and it says plainly that businesses do not have free rein to use fingerprinting as they please, and that the ICO will act if it isn't deployed lawfully and transparently, per its blog post. The regulator's own judgement is that fingerprinting reduces the choice and control people have over how their information gets collected, which it treats as unfair. The post also recalls that Google itself once objected to fingerprinting on the grounds that people cannot consent to it the way they can to cookies. The legal hook, per the ICO's guidance, is that PECR Regulation 6 applies to any technology that stores or accesses information on a user's terminal equipment — a list naming "fingerprinting techniques" alongside cookies, tracking pixels, link decoration, web storage, and scripts and tags. Some organisations assume Regulation 6 doesn't cover fingerprinting; the guidance says it applies wherever fingerprinting stores information on, or accesses information already stored on, a device, and where that information is personal data, the UK GDPR applies on top. This is the UK position; nothing here describes EU or US law.
Do Safari and Firefox protect against fingerprinting?
The W3C sets out four levels of success for a defence: shrink the fingerprinting surface, grow the anonymity set, make fingerprinting detectable, and make state clearable. It prefers standardising values over randomising them, since "it's difficult to measure how well randomization will work as a mitigation" and randomisation is costly in usability, processing and development. The goal is an increased anonymity set: "an individual can look the same as a larger group of people rather than trying to look like a number of different individuals."
Apple describes exactly that strategy. Every site gathers data about your device, such as system configuration, to serve pages that work on it; some companies use that same data to try to uniquely identify your device. To counter that, Apple's Safari user guide explains that Safari shows websites "a simplified version of your system configuration", so "your Mac looks more like everyone else's Mac". Safari's cookie control is a separate setting doing different work: Prevent cross-site tracking, under Safari > Settings > Privacy, deletes third-party cookies and website data unless you visit and interact with them as a first-party site, and blocks tracking by embedded Share, Like or Comment buttons.
Mozilla combines blocklisting with misdirection. Firefox's fingerprinting documentation, updated 4 November 2025, says Known Fingerprinters Protection is on in normal browsing and when Enhanced Tracking Protection is set to Strict, while both Known and Suspected Fingerprinters Protection are on in Private Browsing and Strict mode. Mozilla admits the blocklist's limits: it "does not safeguard you against companies that are not included in the list", and exceptions are sometimes made so sites keep working. For scripts it can't block, Firefox limits what every page can see: random noise is added to canvas images on readback; locally installed fonts outside the operating system's standard set aren't used to render text; supported touch points are reported as 0, 1 or 5; processor cores are reported as either 4 or 8. Capping font lists is a shared approach — the W3C notes it as a technique used in Tor Browser, Firefox and Safari alike.
The tweak that makes you easier to spot
Instinct misleads here. The Panopticlick data found that anti-fingerprinting adjustments are themselves distinctive unless a large number of other people make the identical adjustment. Flash blockers and User-Agent spoofing made users more identifiable, not less; all seven users of one privacy-enhancing browser in the sample were unique. The exceptions were script blocking via NoScript and Tor's TorButton, designed against fingerprinting. Don't expect a "Do Not Track" toggle to help here either: the W3C's guidance says sending, and honouring, that signal does nothing to limit what browser fingerprinting can do.
Does clearing cookies or using incognito mode stop fingerprinting?
No. Cookie deletion, incognito or private windows, and VPNs each address a different layer of tracking than fingerprinting operates on. The W3C is explicit that "tools such as clearing cookies or using a VPN do not prevent further correlation." The ICO's blog makes the same point from the consumer side: clearing all site data generally controls only cookies and traditional local storage, while fingerprinting relies on signals you cannot easily wipe. Private browsing in Firefox does turn on stronger fingerprinting protections by default, but that's a documented feature of that specific mode, not a general property of private browsing across browsers.
Realistic moves
Pick a browser whose default strategy is blending you into a crowd, and switch on the protections it already ships rather than hand-assembling exotic ones. In Firefox, that means Enhanced Tracking Protection set to Strict, or the Custom level under Privacy & Security if you want the two fingerprinting protections controlled separately. Expect some breakage: Mozilla documents emoji detection failures, custom fonts being ignored, broken greenscreen and progressive video effects, missing glyphs, multi-touch problems, window sizing issues and pages "performing complex calculations" running slower. Knowing the symptoms lets you loosen a setting deliberately instead of giving up on protection altogether. Treat cookie controls as a separate, still-worthwhile job — they're not the same setting and don't do the same work.
Then lean on the law, because the technical route is partial by design. In the UK, the ICO says businesses "do not have free rein to use fingerprinting as they please", and anyone using it for advertising must provide transparency, secure freely given consent, ensure fair processing and uphold information rights including erasure — a bar the regulator calls "a high bar to meet" given how the techniques are currently used. Detectability matters for the same reason: the W3C argues that making fingerprinting observable gives outside researchers and regulators a chance to "detect and investigate the use of fingerprinting." The W3C's own summary is the right expectation to carry: the measures it recommends "are simply mitigations, not solutions", and, as the guidance puts it, "Users of the Web cannot confidently rely on sites being completely unable to correlate traffic, especially when executing client-side code."
Sources
- the W3C's fingerprinting guidance w3.org
- guidance on storage and access technologies ico.org.uk
- How Unique Is Your Web Browser? coveryourtracks.eff.org
- response to that policy change ico.org.uk
- Apple's Safari user guide support.apple.com
- Firefox's fingerprinting documentation support.mozilla.org