# What is device fingerprinting?

Source: https://kavralab.com/glossary/device-fingerprinting/

**Device fingerprinting** is a way to recognize a device from the combination of traits it exposes, such as screen size, graphics hardware, installed fonts, operating system, language and timezone. No single trait is unique, but together they usually are. Fraud teams use it to spot returning devices, link accounts and notice when a device is lying about itself.

## How device fingerprinting works

When a page or app loads, a script collects many small facts about the environment it runs in. Some are declared, like the browser version or language. Others are measured, like how the device draws a hidden image or how fast it performs a task. The collected values are combined into a profile of the device.

Unlike a cookie, nothing needs to be saved on the device. If the same traits appear again next week, the device can be recognized even after cookies are cleared. Good systems also tolerate small changes, such as a browser update or a new external monitor, without treating the device as new.

- **Hardware traits**: screen, CPU cores, memory, graphics card, touch support, battery behavior.
- **Software traits**: operating system, browser build, fonts, plugins, media codecs.
- **Settings**: language, timezone, color scheme, accessibility preferences.
- **Rendering output**: how the device draws text, images and 3D scenes, as in [canvas fingerprinting](https://kavralab.com/glossary/canvas-fingerprinting/).
- **Mobile signals**: in native apps, sensor data and platform attestation.

## Device fingerprinting vs browser fingerprinting

The terms are often used as synonyms. The difference is what the fingerprint tries to describe.

|  | Device fingerprinting | Browser fingerprinting |
|---|---|---|
| Describes | The physical or virtual machine | One browser install on that machine |
| Survives a browser switch | Aims to, using hardware traits | Usually not |
| Where it runs | Web, iOS and Android apps | Web pages only |
| Main use | Linking accounts and returning devices | Recognizing a returning browser session |
| Weak point | Virtual machines and emulators fake hardware | Antidetect browsers rewrite browser values |

## Why device fingerprinting matters for fraud

Most online abuse depends on looking like many different people. [Multi-accounting](https://kavralab.com/solutions/multi-accounting/), free-trial farming and [account takeover](https://kavralab.com/solutions/account-takeover/) all get easier when every attempt appears to come from a new device. A fingerprint lets a site say "this device has been here before, with a different account" or "this login comes from a device the account owner has never used".

Fraud tools know this, so they fight back. [Antidetect browsers](https://kavralab.com/glossary/antidetect-browser/), emulators and spoofing extensions change the reported values, and some rotate them on every visit. A fingerprint that only records what the device says about itself is easy to fool.

## Where simple fingerprinting falls short

- **Identical devices**: Thousands of people own the same phone model with the same settings. Their fingerprints can collide.
- **Faked values**: Spoofing tools rewrite what the page reads, so each profile looks unique on purpose.
- **Rotation**: A device that changes its fingerprint every visit looks like a stream of new visitors.
- **Privacy limits**: Browsers now reduce or randomize some values, and fingerprints must respect consent rules.

## How Kavra uses device fingerprinting

Kavra treats the fingerprint as evidence, not as an identity. It compares what the device claims with how it actually behaves and with the network it uses, and looks for contradictions between those layers. When a returning device changes its fingerprint but stays the same actor, Kavra keeps one identity and counts the rotations. The fingerprint is never the visitor identifier; Kavra issues opaque IDs instead. Read more on [detecting fingerprint spoofing](https://kavralab.com/detect/fingerprint-spoofing/).

## FAQ

### Is device fingerprinting legal under GDPR?

It can be, but it is regulated. In the EU, reading device information generally needs consent unless it is strictly necessary, and fraud prevention is often argued under legitimate interest. The practical rule is to respect the visitor's consent choices, collect no more than needed, avoid personal data where possible and document the legal basis per region.

### How accurate is device fingerprinting?

It depends on how many traits are collected and how well the system handles change. Fingerprints built only from a few declared values collide often and break after updates. Systems that combine many measured traits, tolerate small changes and link devices over time recognize returning devices far more reliably, though no fingerprint is perfect on its own.

### Can clearing cookies stop device fingerprinting?

No. Clearing cookies removes stored identifiers, but a fingerprint is built from traits the device exposes every time it loads a page. Only changing those traits, for example with a different device, a virtual machine or a spoofing tool, changes the fingerprint, and those changes can themselves be detected.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
