You Blocked the Cookies. They Still Know It Is You.
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
You cleared your cookies, switched to private browsing, and the ads still follow you. That is not your imagination, and it is not a cookie you missed.
Browser fingerprinting identifies you without storing anything on your device at all. Instead of leaving a marker and looking for it later, it reads the characteristics your browser reveals automatically and combines them into something distinctive enough to recognise.
What it reads
Each of these is individually unremarkable. Combined, they are often unique:
- Screen resolution and colour depth
- Time zone and language settings
- Operating system and browser version
- Installed fonts
- Graphics hardware, revealed through how your machine renders a test image
- Audio processing characteristics
- Number of processor cores, available memory
- Whether you have "do not track" enabled — itself a distinguishing signal
Millions of people share any one of these values. Very few share all of them at once. That combination is the fingerprint.
Why it is genuinely hard to stop
Cookies are easy to block because they are a distinct thing that gets stored. You can find them and delete them.
Fingerprinting reads information the browser must expose for pages to work correctly. A site legitimately needs to know your screen size to lay out responsively, and your language to serve the right text. There is no clean line between the data a page needs and the data that identifies you.
Worse, standing out makes it worse. Install an unusual set of privacy extensions, disable a common feature, use a niche browser — and you become more identifiable, not less. Blending in beats locking down, which is the opposite of most security advice.
What actually helps
Browsers with built-in anti-fingerprinting. The effective approaches either return standardised values so many users look identical, or add controlled randomness so the fingerprint does not stay stable between sessions. Some mainstream browsers now include protection of this kind; the strongest implementations are in browsers built specifically for the problem.
Not customising much. Every deviation from default is an identifying bit. A stock configuration is a more anonymous one.
Content blockers that stop the scripts loading. A fingerprinting script that never executes gathers nothing. This is the most practical everyday measure, and it improves page speed as a side effect.
What does not help
Private or incognito mode. It clears history and cookies when you close the window. It does not change your screen resolution, fonts or graphics hardware. Your fingerprint is identical.
A VPN, by itself. A VPN changes your apparent location and hides traffic from your network provider — both genuinely useful, neither related to fingerprinting. Your browser still reports the same configuration from the new address. A VPN and anti-fingerprinting solve different problems, and a service that implies otherwise is overselling.
Clearing cookies more often. Nothing is being stored. There is nothing to clear.
Why a handful of ordinary details identifies you
The arithmetic is the part that makes this click, so here is an illustrative version. The figures below are invented for the sake of the example — the point is the shape of the multiplication, not the values.
Suppose one person in twenty shares your exact screen resolution. On its own that narrows nothing useful; in a city of a million people it still leaves fifty thousand.
Add time zone, and say one in forty matches. Fifty thousand becomes about twelve hundred. Add browser and version, one in thirty, and you are down to around forty. Add the specific set of fonts your system has installed, which for many people is unusual because software installs fonts, and you are frequently down to one.
Nothing in that chain required a rare characteristic. Each individual value was shared by thousands of people. Combining a handful of unremarkable facts produced something close to a name, which is the entire principle, and it is why "but everyone has a screen resolution" misses the point.
It also explains why the countermeasures look strange at first. Making one value unusual makes the multiplication converge faster, not slower. The two things that genuinely help are removing values from the calculation altogether, or making your values match a very large crowd.
What to check on your own setup
You can test this rather than take anyone's word for it.
Public fingerprinting-test tools exist that report which of your browser's characteristics are unusual and roughly how distinctive the combination is. The Electronic Frontier Foundation runs one of the better-known ones. Treat the exact number it gives you as indicative rather than precise, because it is measured against whoever else has visited that site, not against the whole internet.
What is worth doing with the result is comparative rather than absolute:
- Run it in your everyday browser, then in a fresh install of a mainstream browser with nothing added. If the stock browser looks less distinctive, your customisations are costing you.
- Run it with your content blocker on and off, to see how many trackers were reaching you.
- Run it in a private window. Watch how little changes. That is the most instructive result on the page.
- Try a browser with built-in anti-fingerprinting and compare. Some report standardised values deliberately.
The awkward truth about who uses this
Fingerprinting is usually described as an advertising technique. It is also a fraud-prevention technique, and that is where the tidy story breaks down.
When your bank recognises the device you normally log in from, and challenges a login from an unfamiliar one, it is fingerprinting you. When a shop declines a card order because the device does not match the customer's usual pattern, same technique. When a service blocks an account-takeover attempt, this is frequently how it noticed.
So the same mechanism that follows you around for advertising is also quietly protecting your accounts, and the browser cannot tell the two apart because they are technically identical.
This produces a real and specific annoyance. Aggressive anti-fingerprinting makes you look like a brand-new, unrecognised device on every visit. The practical results are constant extra verification steps at your bank, more frequent security challenges, more failed card transactions, and more of the puzzles that ask you to identify traffic lights. People commonly conclude the tool is broken and turn it off entirely, which leaves them worse off than a measured setting would have.
The workable answer is per-site rather than global. Keep strong protection as the default for general browsing, and make deliberate exceptions for the handful of financial and account-critical sites where being recognised is doing you a favour. Most browsers and blockers support exactly that.
A realistic expectation
Perfect resistance is not achievable while still using the web normally, and anyone promising it is selling something. The workable goal is raising the cost: block the scripts where you can, avoid unnecessary customisation, and use a browser that actively works on the problem.
It is also worth being clear about what this does and does not buy you. Defeating fingerprinting reduces commercial profiling. It does not hide you from a site you have logged into, which knows exactly who you are because you told it. It does not affect what your internet provider can see, which is a different problem addressed by a VPN. And it does not touch the data you have already handed over, which is the territory of removing your data from brokers and protecting your privacy online more broadly.
For most people the sensible position is a mainstream browser with tracking protection turned up and a good content blocker — enough to defeat routine commercial tracking without making your setup so unusual that it defeats itself, and with exceptions where being recognised is the point. Fingerprinting is not the only way a browser gives you away — DNS and WebRTC requests can expose your real address even behind a VPN, which our sister site VPNTex explains in DNS and WebRTC leaks. The blockers and browser settings worth using are in our shortlist of privacy and security tools.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
The Free Fraud Protection Almost Nobody Turns On
A credit freeze stops new accounts being opened in your name. It is free in many countries, takes minutes, and is more effective than most paid identity-theft products.
privacy
Give Every Company a Different Email Address
One address per service sounds like admin overhead. It takes seconds, kills spam at the source, and tells you exactly who leaked your data.
guides
Best Password Managers 2026: Our Top Picks, Reviewed
The best password managers of 2026, chosen on security, usability and value. How we selected them, who each one suits, and links to our reviews.
