Glossary

What is device fingerprinting?

Device fingerprinting is a way to recognize a device from the combination of traits it exposes, such as screen size, graphics hardware, installed fonts, operating system, language and timezone. No single trait is unique, but together they usually are. Fraud teams use it to spot returning devices, link accounts and notice when a device is lying about itself.

How device fingerprinting works

When a page or app loads, a script collects many small facts about the environment it runs in. Some are declared, like the browser version or language. Others are measured, like how the device draws a hidden image or how fast it performs a task. The collected values are combined into a profile of the device.

Unlike a cookie, nothing needs to be saved on the device. If the same traits appear again next week, the device can be recognized even after cookies are cleared. Good systems also tolerate small changes, such as a browser update or a new external monitor, without treating the device as new.

  • Hardware traits: screen, CPU cores, memory, graphics card, touch support, battery behavior.
  • Software traits: operating system, browser build, fonts, plugins, media codecs.
  • Settings: language, timezone, color scheme, accessibility preferences.
  • Rendering output: how the device draws text, images and 3D scenes, as in canvas fingerprinting.
  • Mobile signals: in native apps, sensor data and platform attestation.

Device fingerprinting vs browser fingerprinting

The terms are often used as synonyms. The difference is what the fingerprint tries to describe.

Device fingerprintingBrowser fingerprinting
DescribesThe physical or virtual machineOne browser install on that machine
Survives a browser switchAims to, using hardware traitsUsually not
Where it runsWeb, iOS and Android appsWeb pages only
Main useLinking accounts and returning devicesRecognizing a returning browser session
Weak pointVirtual machines and emulators fake hardwareAntidetect browsers rewrite browser values

Why device fingerprinting matters for fraud

Most online abuse depends on looking like many different people. Multi-accounting, free-trial farming and account takeover all get easier when every attempt appears to come from a new device. A fingerprint lets a site say "this device has been here before, with a different account" or "this login comes from a device the account owner has never used".

Fraud tools know this, so they fight back. Antidetect browsers, emulators and spoofing extensions change the reported values, and some rotate them on every visit. A fingerprint that only records what the device says about itself is easy to fool.

Where simple fingerprinting falls short

  • Identical devices

    Thousands of people own the same phone model with the same settings. Their fingerprints can collide.

  • Faked values

    Spoofing tools rewrite what the page reads, so each profile looks unique on purpose.

  • Rotation

    A device that changes its fingerprint every visit looks like a stream of new visitors.

  • Privacy limits

    Browsers now reduce or randomize some values, and fingerprints must respect consent rules.

How Kavra uses device fingerprinting

Kavra treats the fingerprint as evidence, not as an identity. It compares what the device claims with how it actually behaves and with the network it uses, and looks for contradictions between those layers. When a returning device changes its fingerprint but stays the same actor, Kavra keeps one identity and counts the rotations. The fingerprint is never the visitor identifier; Kavra issues opaque IDs instead. Read more on detecting fingerprint spoofing.

FAQ

Frequently asked questions

Something else? Talk to our team.

Is device fingerprinting legal under GDPR?

It can be, but it is regulated. In the EU, reading device information generally needs consent unless it is strictly necessary, and fraud prevention is often argued under legitimate interest. The practical rule is to respect the visitor's consent choices, collect no more than needed, avoid personal data where possible and document the legal basis per region.

How accurate is device fingerprinting?

It depends on how many traits are collected and how well the system handles change. Fingerprints built only from a few declared values collide often and break after updates. Systems that combine many measured traits, tolerate small changes and link devices over time recognize returning devices far more reliably, though no fingerprint is perfect on its own.

Can clearing cookies stop device fingerprinting?

No. Clearing cookies removes stored identifiers, but a fingerprint is built from traits the device exposes every time it loads a page. Only changing those traits, for example with a different device, a virtual machine or a spoofing tool, changes the fingerprint, and those changes can themselves be detected.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.