Skip to main content

Your digital fingerprint is tracked everywhere online. Brave wants to change that

Westend61/Getty Images

We have more tools to secure our identity online than ever before. You can ban cookies — the little pieces of information websites deposit in our browsers to identify us — block invasive trackers from tailing our machines, switch to incognito mode, opt out of cross-app tracking with Apple’s latest iOS update, or even go as far as to surf the web only through highly encrypted virtual private networks.

But there’s a tracking method that can still slip past these defenses and it’s growing in popularity: Fingerprinting.

The anatomy of a fingerprint

What makes fingerprinting so elusive and difficult to defend against is the fact that the data it exploits is essential to the web’s foundational functions.

Apps and websites look to collect all sorts of information from us (GPS coordinates, our personal details, etc.) that we pay attention to and usually have the option to keep to ourselves. But a cursory review of just about any tech company’s privacy policy will tell you that they also gather a range of other miscellaneous data that you don’t pay attention to and that you can’t easily stop them from tracking — such as what software your device runs on and to which network operator you subscribe.

“Fingerprinting is a threat to user privacy because it enables a nontransparent way for companies to track and identify users and devices.”

There’s a legitimate reason behind why companies need this data and why they can get it without even asking for your explicit permission. You see, all of us web users access the internet from a wide variety of different means, and in order to ensure that a website or app loads as intended for every user, no matter what browser or app or phone or computer they’re using, these sites need to know certain details about your method of access. But this seemingly innocuous data collection is also what powers fingerprinting.

Trackers stitch together your device’s properties like its display size, its operating system, your language preferences, and more to form your unique fingerprint. They match this pattern across sites and apps to identify you and target you with relevant ads.

Once a website captures your fingerprint, it’s possible for it to track you for up to 100 days — no matter how many safeguards you’ve put up on your browser.

Since all this takes place quietly in the background as you surf the internet, you can’t trace fingerprinting, nor is it possible for you to delete your fingerprints — like how you can in the case of third-party cookies. As your device’s fingerprint will always remain the same, this tracking method also can’t be limited through typical boundaries such as switching to a private window or clearing your browser’s cache.

“Fingerprinting is a threat to user privacy because it enables a nontransparent way for companies to track and identify users and devices,” says Patrick Jackson, the chief technology officer of Disconnect, a privacy app for iOS and Mac.

Finding a fix

There’s currently no great way to stop fingerprinting, but internet companies have started addressing the threat and looking for potential ways to deal with it. The Chromium-based browser Brave takes the most compelling shot at thwarting malicious fingerprinting that we’ve seen so far.

Brave’s solution is simple: Whenever a website requests the kind of data that could potentially enable fingerprinting, the browser obliges — but it also mixes in just enough noise or random information that it doesn’t end up crippling your web experience. This allows you to have a unique fingerprint for every session and every webpage. Therefore, trackers can no longer capture one single fingerprint of yours and match it across websites to follow you because your device will signal a different fingerprint every time.

Image used with permission by copyright holder

In our tests, Brave was the only mainstream browser that passed the Electronic Frontier Foundation’s Cover Your Tracks test, which determines how effectively your browser can protect against practices like fingerprinting.

Other browsers including Safari, Google Chrome, and Mozilla Firefox have had limited success with their existing anti-fingerprinting mechanisms. Unlike Brave, which takes a more dynamic approach to tackle fingerprinting, these apps have a one-size-fits-all implementation that attempts to limit how much information your device’s data websites can access and relies on a list of known fingerprinting domains to block them.

Hitting a moving target

The reason these outdated efforts are no longer effective is that fingerprinting is a broad, evolving concept. It’s a practice that has gotten increasingly more complex with the internet’s advancements and that becomes more sophisticated every year.

Some trackers, for instance, force your browser to draw on an invisible canvas on a web page. When your computer does that, it releases information like its screen’s resolution. Similarly, trackers can determine your fingerprint by how your device processes acoustic signals when it plays an audio file online.

Benoit Baudry, a software technology professor at the KTH Royal Institute of Technology, Stockholm, believes it’s hard to mitigate fingerprinting “since its boundaries are fuzzy and keep changing.”

“A cookie has one single, specific purpose: To identify a user,” Baudry adds. “Meanwhile, browser fingerprinting ‘repurposes’ technology that is meant for something else. This is why it is much more difficult to grasp than cookies: there is not one specific script, object, or packet to intercept.”

In addition to capitalizing on essential web data, the other aspect that prevents browser makers from outright banning fingerprinting is because it’s also employed for positive purposes like fraud detection. When websites detect a user is attempting to sign in from a new fingerprint (which essentially means a new machine), they request additional data for authentication to make sure the source isn’t malicious.

However, experts like Zubair Shafiq, an associate computer science professor at the University of California, Davis, argue fingerprinting is “overkill for fraud detection use cases.”.

Several companies are, at the moment, working toward this exact goal — including Google, which is actively researching ways to curb fingerprinting.

Fingerprinting has largely flown under the radar so far since advertisers and tracking firms have had reliable and direct channels to profile users. Now, as the web’s biggest gatekeepers, including Google and Apple, crack down on traditional tracking frameworks like cookies, fingerprinting has been pushed into the spotlight and, if its adoption goes widespread, it might end up being the most significant threat to our privacy ever. And that’s where it seems to be headed.

The presence of fingerprinting trackers has doubled in websites since 2014 and Disconnect’s Jackson also mentions that in anticipation of cookie and Apple’s cross-app tracking ban, companies are “collecting vast amounts of device data to either compute (and collect) a fingerprint on the device or doing the computation on their servers with the raw data.”

Pierre Laperdrix, a researcher at the French National Centre for Scientific Research who’s been studying fingerprinting for over a decade, believes it will always remain a whack-a-mole game for internet companies. All they can do is stay a step ahead of trackers.

“In my opinion,” Laperdrix said, “I don’t think we can completely put an end to fingerprinting without a reengineering of the way browsers and servers work.”

Editors' Recommendations

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Dell is having a secret sale on refurbished laptops — from $99
The Dell XPS 13

The Dell Memorial Day deals this year not only cover brand new devices such as laptops and gaming PCs -- there are also huge discounts on hundreds of models of refurbished laptops, with prices that go as low as $99. To help you make a quick decision on what to purchase, we've rounded up our favorite refurbished laptop deals for the holiday below. Feel free to browse through everything that's on sale, but you still need to hurry as there's a chance that these offers expire as soon as the holiday ends.

What to buy in Dell's Memorial Day sale on refurbished laptops
The cheapest refurbished laptop from Dell's Memorial Day sale is the 11-inch Dell Chromebook 3100, which is from its original price of $285 for savings of $186. It's only got the Intel Celeron N4020 processor, Intel UHD Graphics, and 4GB of RAM, but as an internet-focused Chromebook, it will perform faster that you expect. Another affordable option is the 15-inch Dell Inspiron 3520, which can go for savings of $135 on its original price of $450. The laptop comes with the 12th-generation Intel Core i3 processor, Intel UHD Graphics, and 8GB of RAM. Both of these refurbished laptops, however, come with scratches and dents, but they still work properly.

Read more
Best Apple deals: Save on AirPods, Apple Watch, iPad, MacBook
Apple MacBook Air M1 open, on a table.

Between some of the best wireless earbuds, the best smartwatches, the best laptops, and even the best tablets, Apple is one of the biggest tech companies in the world, and it's hard to argue with how popular it's become. Of course, being a premium brand with some of the best gear does mean that it's pretty expensive, and for those who love the Apple ecosystem, it can be hard to justify buying something within it, given the price. Luckily, there are a lot of excellent deals floating around from various online retailers, like Amazon or Best Buy, and that includes things like trade-in offers and special offers for Prime and My Best Buy members.

That's why we've gone out and searched through various big retailers to find you some of the best deals we can find. That includes everything from the MacBook deals, AirPods deals, Apple TV deals and Apple Watch deals to the AirTag, so hopefully, you can find the perfect deal that fits your needs and budget.
Apple AirTag (4-Pack) -- $79, was $99

Read more
Hacker group says it carried out Christie’s cyberattack
A digital depiction of a laptop being hacked by a hacker.

A hacker group has claimed responsibility for a cyberattack that targeted auction house Christie’s earlier this month, the New York Times reported on Monday.

The attack, which disrupted the auction house's website, took place just before the start of its high-profile spring sales event involving more than $850 million worth of art, forcing Christie's to suspend online bidding and accept offers only by phone or in person.

Read more