POST /loginVerifySame actor, 7th fingerprint this week
- Fingerprint rotated 6 times
- Graphics claim contradicts render
- Home ISP matches account history
Detection
Fingerprint spoofing is faking the device details a browser or app reports, such as screen, graphics, fonts, timezone or device ID. Rotation changes those values on every visit so one actor looks like many new visitors. Kavra checks the claims against each other and the network, keeps one actor, and treats the rotation as a signal.
POST /loginVerifySame actor, 7th fingerprint this week
Every browser and phone gives away a set of details when it loads a page or opens an app: screen size, graphics card, installed fonts, language, timezone, operating system version, how it draws images and, on mobile, device identifiers. Combined, those details form a browser fingerprint or device fingerprint that is often distinctive enough to recognize a returning device without cookies.
Device spoofing means lying about those details. Instead of reporting its real hardware, the device reports values chosen by a tool. Fingerprint rotation takes this one step further: the values change on every visit or every account, so the same machine never looks the same twice. To a system that counts fingerprints, one person becomes a hundred first-time visitors.
Spoofing ranges from a browser add-on to a fully modified phone. Each tool changes a different set of values.
| Tool category | What it changes | Typical use |
|---|---|---|
| Antidetect browsers | Every reported browser value, per profile, with separate storage | Running many accounts from one laptop |
| Spoofing extensions | A few values, such as user agent, canvas output or timezone | Low-effort rotation on a normal browser |
| Automation with stealth plugins | Values that reveal a scripted browser | Bots that must look like people |
| Device ID changers | Phone model, device IDs and ad IDs on rooted or jailbroken phones | Farming app bonuses and referrals |
| Emulators and virtual machines | Hardware that does not exist, presented as real | Cheap, disposable devices at scale |
| Privacy browsers | Small random noise added to some values | Legitimate privacy, not fraud |
Rotation targets any rule that counts devices. A typical run against a signup offer looks like this.
The tool creates a new profile with a plausible device: a common laptop screen, a mainstream graphics card, fonts to match, and a timezone for the target country.
Each profile gets its own proxy exit, so the device and the IP address are both new at the same time.
The profile signs up, claims the welcome offer or trial, and moves on. The site sees a first-time device.
The next visit gets a new fingerprint. Banned accounts come back, device limits reset, and velocity rules never trigger because no device repeats.
Basic fingerprinting trusts what the device says about itself. It reads the values, hashes them and compares the hash. That is exactly the layer spoofing tools rewrite, so a check that only reads reported values will always see what the tool wants it to see.
Rotation also breaks the usual logic of fraud rules. Most rules ask "have we seen this device before?" and a rotating actor always answers no. Blocking unknown fingerprints is not an option, because every real customer on a new phone or a fresh browser update is unknown too. The answer is to stop asking whether the fingerprint is new and start asking whether the device behind it is.
A tool can change what a device reports. Keeping every layer consistent is much harder.
A browser reports a phone screen with a desktop graphics card, or fonts that do not ship with the claimed operating system.
The device says it has one graphics chip, but the way it actually draws shapes and text matches another.
The timezone and language say one country, while the connection and its route say another.
Values drawn from a template: perfectly common combinations, noise that changes every page load, or empty storage on every visit.
Some traits are hard to fake and rarely change. When they stay the same while the surface fingerprint rotates, it is the same device.
Typing rhythm, pointer movement and the path through the site stay the same across fingerprints, because the same person or script is behind them.
Not every changed fingerprint is fraud. Some privacy browsers add small random noise to values such as canvas output to stop tracking. Browsers that aim for uniformity make every user look alike. Browser updates, new monitors, docking stations and travel all change a fingerprint honestly. Developers and QA teams switch user agents all day.
The difference is intent and pattern. Privacy protection changes a few values in known ways and does not come with a new proxy, a new account and a bonus claim each time. A good system recognizes those browsers for what they are, weighs rotation together with network, behavior and what the visitor is trying to do, and steps up only when the combination points to abuse.
The aim is not to catch every changed value. It is to recognize the same device and the same actor, whatever the surface says, and to decide at the moments that matter: signup, login and reward claims.
Related reading: fingerprint rotation and device spoofing in the glossary, and how the same evidence stops multi-accounting.
How Kavra helps
Kavra analyzes 3,000+ data points on every visit and looks for contradictions between layers, so a changed fingerprint does not make a changed actor.
A device that changes its fingerprint but stays the same actor is kept as one actor with N rotations, not N new visitors.
Device, browser integrity, network and behavior are checked against each other. A disguise that fools one layer rarely fools all of them.
Kavra's own edge network sees how the device actually connects, not only what the browser claims, and its proxy intelligence flags rotating exits.
Returning devices are recognized across visits and accounts, with trusted devices per account and logins compared with each account's own history.
Visitor IDs are opaque and the fingerprint is never the identifier. No names or emails are required, and data is never shared across customers.
Each assessment shows the rotation count and the findings behind it. Allow, verify or block with your rules, or start in observe-only mode.
FAQ
Something else? Talk to our team.
The reported values can. Antidetect browsers, extensions and device ID changers rewrite screen, graphics, fonts, timezone and device IDs. What is hard to fake is consistency: every claim has to agree with how the device actually renders, behaves and connects. Detection that checks those layers against each other catches most spoofed devices even when each value looks plausible.
Fingerprint rotation is changing a device's fingerprint on every visit or every account, so one machine appears as many new devices. It is used to reset device limits, claim one-time offers again and return after bans. Kavra treats it as a signal: the actor is kept as one, with a count of how many times it rotated.
Using a privacy tool that changes your fingerprint is generally legal, and many people do it to avoid tracking. It becomes a problem when spoofing is used to break terms of service, claim offers repeatedly, evade bans or commit fraud. Businesses usually respond by closing accounts and withholding rewards rather than by legal action.
They should not be blocked for protecting privacy. Privacy browsers change a few values in known, consistent ways, and good detection recognizes them. Risk rises when rotation comes with other evidence, such as a new proxy exit, a new account and a bonus claim on each visit. That combination points to abuse; privacy alone does not.
On mobile, spoofing usually means a rooted or jailbroken phone with tools that change the model and device IDs, or an emulator posing as a phone. A native SDK can compare the claimed hardware with how the device behaves and connects, notice modified environments, and link a reset device back to its earlier history.
Because real customers produce new fingerprints all the time: a new phone, a browser update, a new monitor or a borrowed laptop. Blocking unknown fingerprints punishes them and barely slows fraudsters, who rotate anyway. The better question is whether the device behind the new fingerprint is one you have seen before.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.