PowerScan

PowerScan Blog

User-Agent strings and Client Hints: what they reveal and what was frozen

· 6 min read

The user agent string is the oldest identification signal on the web and the one that has changed most in the last few years. Reading it well means knowing what is still in it, what was deliberately frozen, and where the removed detail went.

What the string says

A current Chromium string on Windows looks like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/154.0.0.0 Safari/537.36. The historical tokens (Mozilla/5.0, AppleWebKit, like Gecko, Safari) are there for compatibility with scripts written decades ago and carry no information. The useful parts are the platform (Windows NT 10.0, even on Windows 11), the architecture and the major browser version.

What used to be there has been removed on purpose. The minor and patch version is now 0.0.0. The Windows version is pinned to 10.0. Android strings no longer include the device model. This is the "user agent reduction" that Chromium shipped between 2022 and 2023 precisely because the string had become a fingerprinting surface.

Client Hints: the same data, on request

The removed detail did not vanish; it moved to User-Agent Client Hints. A server can ask for specific fields with an Accept-CH header, and the browser will then send headers such as Sec-CH-UA-Platform-Version or Sec-CH-UA-Model on later requests. The low-entropy hints (brand and major version, platform, mobile flag) are sent by default. The high-entropy ones (full version, architecture, bitness, model, platform version) are only sent to sites that ask, and a script can request the same set through navigator.userAgentData.getHighEntropyValues().

The design goal is that the site has to declare what it wants, which makes the collection visible and auditable. In practice, a site that wants to fingerprint can still ask for everything; the difference is that the asking is a request the browser can see, log or refuse.

The consistency problem

Because the same facts are now available from two sources, they can be compared. A browser that changes its user agent string to claim macOS but leaves navigator.userAgentData.platform reporting Windows has created a contradiction that is trivial to detect. The same applies to the navigator.platform property, the OS-specific fonts visible to the page, and the WebGL renderer string, which names a graphics driver that exists only on one operating system. Spoofing the string alone has been a losing strategy for years.

Reading your own

A diagnostic shows the raw string, the browser and version it parses out of it, and the engine (Blink, Gecko or WebKit). Note that every browser on iOS reports WebKit, whatever the brand says, because Apple requires it. If the parsed browser name surprises you, the string is being altered by an extension or a profile setting; whether that is a problem depends on whether the rest of the browser agrees with the alteration.

All articles · Run the scan