Browsers have fingerprints, and sneaky web developers can use them to learn all sorts about you, and to pick you out, without you ever knowing.
What your browser told us
For instance, you’ve only just landed on this page, and look how much we know about you already.
The second you got here, your browser told us what time it is where you are (it’s — on a —), what time zone you’re in (—), what languages you read (—), the size of your screen (—), how powerful your device is (—), whether you like dark mode (—) and what your connection’s like (—).
It had a good guess at what you’re reading on, too: —. Open the bar at the bottom of the screen to see the rest.The rest is down the side.
Your fingerprint
All of this (and more) can be used by a website to identify you, and on a lot of sites it’s enough to identify you uniquely.
On its own, your screen size says almost nothing. Add your time zone, your languages, your core count, your memory and the tiny differences in how your graphics card draws a test image, and the combination gets rare. Often it’s rare enough to tell you apart from everyone else on a site, with no cookie, and to recognise you again tomorrow after you’ve cleared your cookies. That’s browser fingerprinting. When the Electronic Frontier Foundation measured it in 2010, 84% of the browsers it tested were unique.
In fact, we made a fingerprint for you. It’s being worked out. Close this tab, come back, and you’ll see it’s the same. Some fingerprinting tools are clever enough to give you the same fingerprint in a private window as in your normal one, so even incognito won’t hide you.
Your battery
What else can we see? Let’s try… battery levels. The idea was that a site could spot someone about to run out and go easy on the animations and whatnot. Uber noticed another use for it: people whose battery is about to die are more willing to pay extra for a ride, before their phone gives out.
How you read
We’ve been timing you, too.
Analytics tools call this “engagement”. Some go further and record everything you do, every scroll, click and keystroke, so a marketing team can play your visit back like a video and watch how you used the page. In 2017, researchers at Princeton found scripts like that on 482 of the 50,000 most popular websites.
When you look away
We can see where your cursor goes as well. Move it up towards the tabs at the top of the window, as if you were about to leave. That’s the moment a lot of sites throw a pop-up at you. Try it, and watch what we write down.
We can even see a bit of what you do away from this page. Open a new tab and check the news or something. When you do, you’ll notice our tab’s name changes straight away. Give it a little while, then come back.
We’ll wait.
We know when you stop, too. Sit still for twenty seconds and see. Ad companies use the same signal to work out whether an ad was actually seen, and whether to pay for it. Pretty creepy.
What we know about you
So, to recap, here’s what we know:
What can you do?
- Use a browser that pushes back. Safari and Firefox both block known trackers by default and blur some of the signals fingerprinting relies on.
- Block third-party scripts. A content blocker such as uBlock Origin stops most of the companies that would collect this.
- Say no to what a site doesn’t need. Location, notifications, camera, microphone: if a site asks and doesn’t need it, refuse it.
Stay safe. Big Brother is watching you.
An experiment by Mutual. Nothing this page reads about you is stored or sent anywhere: close the tab and it’s gone. Sources: Eckersley, How Unique Is Your Web Browser? (EFF, 2010); Englehardt, Acar & Narayanan, No boundaries (Princeton, 2017).