PowerScan

PowerScan Blog

What is browser fingerprinting, and what can a website actually read?

· 6 min read

Every time you open a page, the browser hands the site a long list of facts about itself. None of them is secret, none of them asks for permission, and most of them are there so the page can render correctly. Fingerprinting is what happens when a site stops using those facts to render and starts using them to recognise you.

What a page can read without asking

A script running in an ordinary tab can read, among other things: the user agent string, the list of preferred languages, the time zone, the screen size and pixel density, the number of CPU threads, a rounded figure for device memory, the colour depth, whether touch is supported, the name of the graphics renderer behind WebGL, and the outcome of drawing a small image to a canvas or rendering a short audio buffer. It can also observe how long certain operations take, which fonts change the width of a line of text, and which media devices exist (counts, not names, unless you grant access).

Individually these are boring. A time zone narrows you to a few hundred million people. Together, they narrow you much further, because the combination is what is rare. A Windows machine with a specific NVIDIA renderer string, 12 threads, a 2560×1440 screen, French and English in that order, and a particular canvas hash is not a crowd.

What makes a signal useful for identification

Three properties matter. The signal has to be stable: the same browser should give the same value tomorrow. It has to be diverse: different browsers should give different values. And it has to be cheap: readable in milliseconds without a permission prompt. The canvas hash scores well on all three, which is why it shows up in every fingerprinting library. The screen size scores well on the first two and perfectly on the third. The user agent used to score well on diversity and has been deliberately flattened by browser vendors for exactly that reason.

What a page cannot read

This part gets exaggerated. A page script cannot see your real address if you are behind a proxy: it sees whatever the proxy presents. It cannot read other tabs, your history, your bookmarks or your saved passwords. It cannot tell with certainty whether you are in a private window; the heuristics that claim to break regularly. It cannot know your name. And it cannot decide on its own whether an address is a proxy or a data centre: that verdict comes from a reputation database the site pays for, not from anything your browser said.

Sites that show a "bot score" or a "proxy: yes" are combining what your browser reported with data from a third party. That is a legitimate thing to do, but it is important to know which half is measurement and which half is lookup.

Why diagnostic pages exist

A diagnostic page like PowerScan reads the same signals a tracker would and shows them to you instead of storing them. The point is not to score you. It is to let you check two things: whether a signal you expected to be hidden is visible, and whether the signals are consistent with each other. Inconsistency is what gets accounts flagged: an address in one country, a browser clock in another, a WebRTC candidate that does not match the address you arrived from.

When you read a report, treat every line as an answer to one question: "what did this browser tell this page just now?" Nothing more. A hash is not a verdict, and a number of signals read is not a measure of how real you look.

All articles · Run the scan