How device fingerprinting works
When a page or app loads, a script collects many small facts about the environment it runs in. Some are declared, like the browser version or language. Others are measured, like how the device draws a hidden image or how fast it performs a task. The collected values are combined into a profile of the device.
Unlike a cookie, nothing needs to be saved on the device. If the same traits appear again next week, the device can be recognized even after cookies are cleared. Good systems also tolerate small changes, such as a browser update or a new external monitor, without treating the device as new.
- Hardware traits: screen, CPU cores, memory, graphics card, touch support, battery behavior.
- Software traits: operating system, browser build, fonts, plugins, media codecs.
- Settings: language, timezone, color scheme, accessibility preferences.
- Rendering output: how the device draws text, images and 3D scenes, as in canvas fingerprinting.
- Mobile signals: in native apps, sensor data and platform attestation.
Device fingerprinting vs browser fingerprinting
The terms are often used as synonyms. The difference is what the fingerprint tries to describe.
| Device fingerprinting | Browser fingerprinting | |
|---|---|---|
| Describes | The physical or virtual machine | One browser install on that machine |
| Survives a browser switch | Aims to, using hardware traits | Usually not |
| Where it runs | Web, iOS and Android apps | Web pages only |
| Main use | Linking accounts and returning devices | Recognizing a returning browser session |
| Weak point | Virtual machines and emulators fake hardware | Antidetect browsers rewrite browser values |
Why device fingerprinting matters for fraud
Most online abuse depends on looking like many different people. Multi-accounting, free-trial farming and account takeover all get easier when every attempt appears to come from a new device. A fingerprint lets a site say "this device has been here before, with a different account" or "this login comes from a device the account owner has never used".
Fraud tools know this, so they fight back. Antidetect browsers, emulators and spoofing extensions change the reported values, and some rotate them on every visit. A fingerprint that only records what the device says about itself is easy to fool.
Where simple fingerprinting falls short
Identical devices
Thousands of people own the same phone model with the same settings. Their fingerprints can collide.
Faked values
Spoofing tools rewrite what the page reads, so each profile looks unique on purpose.
Rotation
A device that changes its fingerprint every visit looks like a stream of new visitors.
Privacy limits
Browsers now reduce or randomize some values, and fingerprints must respect consent rules.
How Kavra uses device fingerprinting
Kavra treats the fingerprint as evidence, not as an identity. It compares what the device claims with how it actually behaves and with the network it uses, and looks for contradictions between those layers. When a returning device changes its fingerprint but stays the same actor, Kavra keeps one identity and counts the rotations. The fingerprint is never the visitor identifier; Kavra issues opaque IDs instead. Read more on detecting fingerprint spoofing.