Device Fingerprinting Explained: The Phone Sensor Attack and How to Reduce Tracking

Logeshwaran
—

Device fingerprinting identifies your phone or computer without cookies, from the combination of things a website can measure: browser version, screen size, fonts, graphics card behavior, language, time zone, and sometimes sensor data. In 2019, Cambridge researchers showed a striking example, calibration fingerprinting or SensorID. A website could read the tiny factory calibration errors of a phone's motion sensors and use them as a fingerprint that survived even a factory reset. Apple fixed it in iOS 12.2. You cannot block fingerprinting completely, but you can make it much harder. Use a browser with fingerprinting protection (Safari, Firefox, Brave, or Edge on strict tracking prevention), keep it updated, limit sensor and permission access, avoid unnecessary extensions, and use private browsing for sensitive sites.

Ethan had done everything he thought mattered for privacy: he cleared cookies weekly, used private windows for shopping and deleted his phone's advertising ID. Yet some ads still seemed to follow him from site to site. He asked Jake how. Jake opened a fingerprinting test site on Ethan's laptop: it reported that his browser was unique among hundreds of thousands tested, cookies or not. The fonts installed by a design program, a rare screen resolution and a long list of extensions together made his browser as distinctive as a name badge. Jake explained fingerprinting, told him the story of the sensor calibration attack, and changed a handful of settings. The test site's verdict changed from "unique" to "common". This page explains how fingerprinting works and what actually reduces it.

⚡ Quick Answer

• What it is → identifying a device from its measurable traits, no cookies needed. Fingerprinting.

• Sensor attack → motion sensor calibration as a permanent ID, fixed in iOS 12.2. SensorID.

• Best defense → a browser with fingerprinting protection, kept updated. Browsers.

• Blend in → fewer extensions, common settings. Blend in.

Test your browser with a fingerprinting test site. Test.

Fingerprinting is a fast-moving area; browser makers add protections every year. The principles below stay the same even as specific settings change.

What device fingerprinting is

When a browser loads a page, it tells the website a lot about itself so the page displays correctly: the browser and its version, the operating system, screen size, preferred language and time zone. Scripts on the page can measure more: which fonts are installed, how the graphics hardware draws a hidden image, how audio is processed, how many processor cores there are, and which features are supported. Each detail is shared by millions of people. Combined, they often form a pattern that is rare or unique.

That pattern is a fingerprint. Unlike a cookie, it is not stored on your device, so clearing cookies or using a private window does not remove it. A site, or an advertising network present on many sites, can recognize the same fingerprint again and link your visits. Fingerprinting is used for fraud prevention and security, such as spotting a stolen account logging in from an unusual device, and for tracking and advertising, which is where privacy concerns arise.

Signal What it reveals How identifying
Browser and OS versionSoftware you useLow alone, adds up
Screen size and pixel densityDevice model, display settingsMedium
Installed fontsSoftware and languages installedHigh on PCs
Canvas and WebGL renderingGraphics hardware and driversHigh
Audio processingAudio stack differencesMedium
Language and time zoneRegion and settingsMedium
ExtensionsDetectable add-onsHigh with many
Sensor calibration (2019)Factory errors in motion sensorsVery high, now restricted

The key difference from cookies is control: you can see and delete cookies, but you cannot see or delete a fingerprint, because it is computed on the tracker's side each time. The only controls are what your browser reveals and which scripts it lets run.

Work and school devices

On a laptop managed by an employer or school, the organization can see far more than any website: managed browsers report activity, and security software monitors the device. Fingerprinting is not the main concern there; the organization's own policies are. Keep personal browsing on personal devices, and read the acceptable-use and privacy notices for managed devices. If a work browser shows "Managed by your organization", that is the signal that policies apply.

Equally, avoid installing personal browser extensions or tools on managed devices; they may conflict with the organization's security software and can expose work data.

Canvas fingerprinting explained

Canvas fingerprinting is one of the most widely used techniques, and it shows how subtle fingerprints can be. A script asks the browser to draw a hidden image, typically text in several fonts with colors, shapes and effects, using the page's canvas drawing feature. It then reads back the pixels. Tiny differences in graphics hardware, drivers, font rendering and anti-aliasing make the result differ slightly between devices, invisibly to the eye but measurably in the data. Hashed into a short code, those differences become a stable identifier. WebGL, the browser's 3D graphics feature, allows similar measurements of the graphics card itself.

Browsers fight back by adding small random noise to canvas output, by asking permission before sites read canvas data, or by blocking scripts known to fingerprint. Each approach has trade-offs, since legitimate sites use canvas for charts, games and editing tools.

Some fingerprinting scripts run in a fraction of a second and leave no visible trace, which is why relying on the browser to block or blur them works better than trying to spot them yourself.

Why PCs are easier to fingerprint than phones

On a PC, every program you install can add fonts, and every language pack, design tool and office suite leaves its mark. The resulting font list is often close to unique. PCs also vary widely in graphics hardware, screen resolutions and drivers. Phones are more uniform: millions of people carry the same iPhone model with the same software, so iPhones in particular tend to blend in. Android phones vary more by maker and model but are still more uniform than PCs. That is part of why Ethan's laptop was unique while his phone was not.

Browsers have started limiting which fonts websites can detect, exposing only standard system fonts by default, which removes one of the strongest signals on PCs without affecting how pages look for most people.

The 2019 sensor calibration attack (SensorID)

In May 2019, researchers from the University of Cambridge and Polymath Insight presented SensorID at the IEEE Symposium on Security and Privacy. Phones contain motion sensors, the accelerometer, gyroscope and magnetometer, which have tiny manufacturing errors. To make them accurate, makers measure each phone's errors at the factory and store correction values, called calibration data. The researchers found that by reading sensor values through a web page or app and analyzing them, they could work out a phone's calibration data, which differs for every device.

That made a near-perfect fingerprint: it was unique, it took about a second to collect, it needed no special permission on the affected devices, and it never changed, even after a factory reset. They demonstrated it on iPhones and on Google's Pixel 2 and Pixel 3. Apple, informed in 2018, fixed the issue in iOS 12.2 in March 2019 by adding random noise to sensor output so each reading produces a different result, and by turning off motion sensor access for websites in Safari by default. Google said it was investigating the issue for Pixel phones.

The research also set a pattern for sensor privacy that persists: treat any stable, device-specific measurement as a potential identifier, even when it looks like harmless technical data.

How the researchers did it

The SensorID technique relied on how sensors report values. A sensor's raw readings are whole numbers from its analog-to-digital converter, and the phone applies the factory calibration to turn them into the values apps see. By collecting a short burst of readings and analyzing the tiny, regular gaps between the possible output values, the researchers could work backward to the calibration values themselves. Because every phone's calibration differs slightly, the recovered values formed a fingerprint with enough variety to tell devices apart across very large populations, collected in about a second with no visible sign to the user.

Disclosure and the fix timeline

The researchers followed responsible disclosure. They reported the issue to Apple in August 2018 and to Google in December 2018. Apple released its fix in iOS 12.2 in March 2019. The paper was published in May 2019, with a public website explaining the attack and letting people test their devices. Google responded that it was investigating the issue for its Pixel phones. The episode is often cited as an example of a hardware-level privacy flaw that a software update could address, by changing what software reveals rather than the hardware itself.

Researchers continue to study sensor fingerprinting on newer devices, and browser makers now treat sensor access as a privacy-sensitive feature by default, which is the lasting legacy of the 2019 work.

Why the sensor attack mattered

SensorID was important less for the specific trick than for what it showed. First, fingerprints can come from hardware, not just software, and hardware fingerprints are much harder to escape: you cannot reinstall your way out of a sensor's manufacturing quirks. Second, web pages had access to sensors with no prompt, because motion data seemed harmless; it was used for games, step counters and rotating images. Third, it showed that privacy problems are often hidden in features designed for accuracy, in this case factory calibration meant to make sensors better.

The broader response was a shift in how browsers treat sensors: requiring permission before websites can use motion and orientation data, reducing precision, and adding noise. That same thinking now shapes how browsers handle many fingerprinting signals.

It also showed the value of independent security research: the flaw was found by academics, not by the companies that built the phones, and their work protected millions of users before any known abuse.

Other hardware-based fingerprints

SensorID was not the last hardware fingerprinting discovery. Researchers have shown that the tiny performance differences between individual graphics processors, even of the same model, can be measured through WebGL timing, a technique published in 2022 as DrawnApart. Earlier, the web's Battery Status feature, which let websites read battery level and charging time, was found to be usable for short-term tracking, and Firefox removed it for web content in 2017. The pattern repeats: a feature meant to be harmless leaks a stable characteristic, and browsers restrict it once researchers show the risk.

Each discovery like this tends to be followed by browser changes within months, which is another reason prompt browser updates matter for privacy as well as security.

Test your own browser

  1. Open a reputable fingerprinting test site in your browser, such as the Electronic Frontier Foundation's Cover Your Tracks.
  2. Run the test with your usual settings and note whether your browser is reported as unique.
  3. Look at which details stand out, such as fonts, screen size or extensions.
  4. Change one setting, such as turning on stronger tracking protection, and test again.
  5. Repeat on your phone's browser.

Being reported as unique is common and does not mean you are being tracked right now; it means a tracker could recognize you if it tried. The goal is to become one of many, or to have a fingerprint that changes, so it cannot be linked across visits.

Test in a private window as well as a normal one, since some browsers apply stronger protections in private mode, and compare the results to understand what each mode is doing for you.

What "bits of identifying information" means

Fingerprinting test sites often report results in bits of identifying information. Each bit halves the number of people who share that trait: one bit means one in two people share it, ten bits about one in a thousand, twenty bits about one in a million. A whole fingerprint adds up the bits from each signal, which is why individually common traits combine into a rare result. When you reduce extensions or turn on protections, watch the total bits fall; that number is a simple way to measure progress.

Results depend on the test site's own visitors, so treat the numbers as a rough guide for comparing your settings, not as an exact measure of how trackable you are everywhere.

🧭 NEW HERE? READ THESE FIRST

Working on your online privacy? These five pages pair with this one:

📌 Bookmark this; blend in, or let your browser randomize.

Browsers and their fingerprinting protections

The strongest defense is a browser built to resist fingerprinting, because it can change what websites are able to measure. Approaches differ:

  • Safari presents a simplified, more uniform configuration to trackers and adds fingerprinting protections that Apple has expanded over time, particularly in private browsing and, on recent versions, more broadly.
  • Firefox blocks known fingerprinting scripts in its Enhanced Tracking Protection, with stronger protections in Strict mode.
  • Brave randomizes many fingerprinting values on each site and session, so the fingerprint does not stay the same.
  • Tor Browser makes all users look identical, the strongest protection, at the cost of speed and convenience.
  • Microsoft Edge blocks known fingerprinting trackers in its Strict tracking prevention level; our guide to tracking prevention in Edge covers the levels.
  • Chrome has reduced some information it shares, such as detail in its user-agent string, but relies mostly on other privacy measures.

Whichever you use, keep it updated, since protections improve with each release, and turn on its strongest practical tracking protection setting.

Browser Approach Everyday convenience
Tor BrowserEveryone looks the sameLow: slow, sites may block
BraveRandomizes values per site and sessionHigh
SafariUniform configuration, noise on key signalsHigh on Apple devices
FirefoxBlocks known fingerprinters; stronger in StrictHigh
EdgeBlocks known fingerprinting trackers in StrictHigh
ChromeReduced user-agent detail; limited blockingHigh

Version matters more than people think: a browser several versions behind not only misses security fixes but also stands out, since most people update automatically, making an old version itself a distinguishing signal.

If you switch browsers, import bookmarks and passwords, then give it a week: most people find the more private browser just as convenient once their sites and sign-ins are set up.

See what your browser is blocking

Most privacy-focused browsers show what they block. In Firefox, open about:protections to see counts of blocked trackers, including fingerprinters, over the past week. In Edge, select the lock icon in the address bar and then tracking prevention to see blocked trackers on the current site. Brave's Shields panel shows blocked items per site. Watching these numbers for a few days is an eye-opening way to see how common tracking scripts are on everyday websites, including ones you trust.

If counts drop to zero on a site you know is full of ads, protection may have been switched off for that site; check the exception list.

These dashboards also help when troubleshooting: if a site misbehaves, the list of blocked items often shows what to allow.

When protection breaks a site

Strong anti-fingerprinting settings occasionally break sites that rely on canvas, WebGL or other features for legitimate reasons, such as online editors, maps or video calls. Instead of lowering protection for everything, add the site as an exception: in Firefox, use the shield icon in the address bar; in Edge, add it to tracking prevention exceptions; in Brave, lower Shields for that site only. Keep exceptions to sites you trust and use often.

Review the exception list every few months and remove sites you no longer use, so temporary exceptions do not quietly become permanent weak spots.

Harden your browser in ten minutes

  1. Update the browser to the latest version.
  2. Set tracking protection to its strongest practical level: Strict in Firefox and Edge, Shields on in Brave.
  3. Remove extensions you do not use every week.
  4. Review site permissions and turn off location, camera, microphone, notifications and motion sensors for sites that do not need them.
  5. Block third-party cookies.
  6. Use private windows for sites you do not want linked to your usual browsing.
  7. Run a fingerprinting test before and after to see the difference.

These steps take about ten minutes on each device and make the biggest practical difference for most people.

Do the same on every browser you use, since a protected main browser does little if you also browse unprotected in a second one.

Blend in: make your fingerprint common

A fingerprint works by being rare. Making yours more common reduces how identifying it is. Remove browser extensions you do not need, since each detectable extension narrows the crowd. Keep the browser at default settings for things like fonts and zoom where you can. Avoid unusual screen resolutions in the browser window if fingerprinting concerns you, though few people will want to change their display for this. Use a widely used browser in a common configuration. Ethan's laptop went from unique to common mainly by removing six old extensions and switching his browser's tracking protection to strict.

Ironically, some privacy tools can make you more unique: an unusual combination of privacy extensions is itself a distinctive signal. Built-in browser protections are usually better than stacking add-ons.

Realistic expectations

Complete invisibility online is not a realistic goal for everyday browsing. Websites need some information to work, and signing in to accounts identifies you by design. The practical goal is narrower and achievable: stop companies you have no relationship with from quietly following you across the web. A protected browser, few extensions, careful permissions and signed-out browsing where it does not matter get most people most of the way there, without making the web harder to use.

Think of it like closing the curtains rather than becoming invisible: people who need to know you are home still can, but passers-by cannot look in.

The role of content blockers

Many fingerprinting scripts arrive through advertising and analytics networks. A reputable content blocker, or a browser with built-in blocking, prevents those scripts from loading at all, which stops fingerprinting before it starts, rather than trying to disguise the results. That is why blocking known trackers is the backbone of most browsers' protection. One well-maintained blocker is enough; several overlapping ones add little and make your setup more distinctive.

Blocking also speeds up pages and saves data, since tracking scripts are often among the heaviest parts of a page, which makes this one of the few privacy steps that improves everyday browsing too.

Choose a blocker from a well-known developer with an open, regularly updated filter list, and avoid little-known ones that may themselves collect browsing data.

Fingerprinting myths

A few beliefs get in the way. "Incognito mode makes me anonymous" is the most common; it only stops your browser saving local history. "Changing my user-agent string hides me" is mostly false, since many other signals remain and a mismatched user agent can make you stand out more. "More privacy extensions means more privacy" often backfires, as the combination itself becomes distinctive. "Fingerprinting only happens on shady sites" is wrong too; fingerprinting scripts appear on mainstream sites through advertising and analytics partners. The reliable approach is a protected browser kept at sensible defaults.

Another myth is that only advertisers fingerprint. Analytics companies, fraud prevention services and some security tools do too, which is why fingerprinting scripts appear even on sites that show no ads.

Children and fingerprinting

Children's devices are tracked like anyone else's, and many privacy laws give children's data extra protection. On a child's tablet or phone, use a browser with strong tracking protection, keep extensions to a minimum, and use the platform's family controls to limit apps that rely on advertising. Kid-focused browsing modes, such as Edge's Kids Mode, restrict sites and settings in ways that also cut down tracking. Teaching older children that clearing cookies is not the same as being invisible helps them understand why these settings matter.

School-issued devices are usually managed by the school, which applies its own settings; check with the school about what is collected and how it is used.

Limit sensor and device permissions

Browsers now ask before websites use many sensitive features: location, camera, microphone, notifications and, increasingly, motion sensors. Deny these unless a site genuinely needs them. In Chrome on Android, Settings > Site settings lists permissions such as Motion sensors, which can be turned off globally or per site. In Safari on iPhone, motion and orientation access for websites is off by default since iOS 12.2. Review site permissions periodically and remove those you no longer use.

Apps have broader access than websites. Our guide to what data your phone sends covers app permissions, the advertising ID and the privacy dashboard, all of which matter alongside browser fingerprinting.

On shared family computers, separate browser profiles or Windows accounts for each person also reduce how much one person's browsing reveals about another's, and let each choose their own protection level.

Motion sensor access in particular is rarely needed outside games, maps and fitness sites, so blocking it by default and allowing it per site costs almost nothing.

On your phone's browser

Phones deserve the same attention as laptops. On iPhone, Safari's Advanced Tracking and Fingerprinting Protection, found under Safari's Advanced settings on recent versions of iOS, can be applied to private browsing or to all browsing; choosing all browsing gives the widest protection. Firefox on Android offers Enhanced Tracking Protection with a Strict option, and Brave on Android and iPhone has Shields with fingerprinting protection on by default. Chrome on Android lets you turn off motion sensors and other permissions per site, and block third-party cookies. Whatever you use, update it promptly, since mobile browsers receive privacy improvements regularly.

Phone browsers also inherit protections from the operating system, such as limited access to device identifiers, so a fully updated phone and browser together give the best result.

Fingerprinting in apps

Apps can collect even more device characteristics than websites, and mobile platforms have responded with rules. Apple requires apps to declare their use of certain APIs often used for fingerprinting and prohibits fingerprinting for tracking under its App Tracking Transparency rules. Google Play has policies on device identifiers and has restricted access to permanent identifiers such as hardware serial numbers. Both platforms now give apps resettable identifiers instead of permanent ones. Deleting or limiting the advertising ID, as described in our phone privacy guide, removes the easiest identifier, which reduces the incentive to fingerprint.

Much in-app tracking comes from third-party code bundled into apps, called SDKs, for advertising and analytics. The app's developer may not even know everything those components collect. App store privacy labels and data safety sections are the best available guide to what an app and its partners gather.

On Android, the Privacy dashboard and permission settings described in our phone privacy guide are the practical controls; on iPhone, the App Privacy Report shows which domains each app contacts, often revealing analytics partners.

Network-level fingerprints

Fingerprinting does not happen only in the browser. When your device connects to a website, the way it sets up an encrypted connection, the order of supported encryption methods and other details, forms a TLS fingerprint that identifies the type of software making the connection. Websites and security services use it to spot bots and fraud, since automated tools often have telltale connection fingerprints. Combined with IP address, it adds to the picture a server can build. Ordinary users cannot easily change it, but it identifies software types rather than individuals, so it matters more for fraud detection than for tracking people.

For most people, the takeaway is reassuring: network fingerprints are mainly a fraud-detection tool, and the steps on this page for the browser matter far more for everyday privacy.

Your public IP address is the simplest network signal of all; it changes when you switch networks, which is why some trackers combine it with browser fingerprints rather than relying on it alone.

Cross-device tracking

Trackers also try to link your phone, laptop and tablet as belonging to one person. The most reliable method is simply logging in: if you use the same account on several devices, the service knows they are yours. Others infer links from shared Wi-Fi networks and IP addresses, or patterns of activity. Years ago, some marketing software experimented with inaudible high-frequency sounds played in ads and picked up by phone apps to link devices, a practice that drew regulatory warnings in the United States. Using different browsers or profiles for different activities, and signing out of accounts where you do not need them, limits cross-device linking.

Password managers and browser sync are worth keeping despite this; the account linking they involve is with services you chose, and the security benefits far outweigh the small privacy cost.

Shared home IP addresses also mean that everyone in a household can look like one user to some trackers, which is one reason ads sometimes reflect a family member's browsing rather than your own.

Smart TVs and connected devices

Fingerprinting and tracking are not limited to phones and computers. Smart TVs can identify what is on screen using automatic content recognition, sharing viewing data with the manufacturer and advertisers unless you turn it off in the TV's privacy settings, often labeled viewing information or similar. Streaming devices, game consoles and smart speakers have their own identifiers and analytics. Reviewing each device's privacy settings once, and turning off data sharing you do not want, closes gaps that browser settings cannot reach.

Many TVs bury these options several menus deep and may turn them back on after updates, so check again after major firmware updates.

Connected cars deserve a mention too: many record location and driving data and share it through companion apps, so review the car maker's app privacy settings as well.

Fingerprinting and the advertising industry

Fingerprinting sits in a gray area in advertising. Privacy regulators in Europe and elsewhere consider fingerprinting for tracking to require consent, just like cookies. Browser makers have treated it as something to block. In 2025, Google changed the rules of its advertising platform to permit advertisers to use fingerprinting techniques, a change criticized by privacy advocates and by the UK's data protection regulator, which warned that fingerprinting reduces people's control over their data. As third-party cookies decline, fingerprinting is likely to remain a contested tool, which makes browser-level protections more important.

Whatever the policies of any one company, the protections in your own browser apply everywhere you go, which is why this page focuses on them.

Your rights over fingerprinting

In the European Union and the UK, rules on device storage and access, together with data protection law, mean that fingerprinting for tracking or advertising generally needs your consent, just as tracking cookies do. That is why consent banners in those regions sometimes mention "device characteristics" or "precise device identification" as purposes you can refuse. Refusing them is worth the extra click. In parts of the United States, state privacy laws let you opt out of targeted advertising and the sale or sharing of personal data, which covers data gathered through fingerprinting. Browser signals such as Global Privacy Control, supported by some browsers and extensions, communicate that opt-out automatically to sites that honor it.

Exercising these rights is easiest at the moment of choice, in consent banners, rather than afterwards, so choosing reject or manage options when a banner appears saves effort later.

Where fingerprinting is heading

For years the industry expected third-party cookies to disappear from Chrome, which would push advertisers toward other methods. In 2025, Google abandoned its plan to remove third-party cookies from Chrome, keeping them as a user choice, while browser makers such as Apple, Mozilla and Brave continued tightening protections. Meanwhile, machine learning has made it easier to link partial fingerprints and other signals into probable identities. Expect a continuing contest: trackers finding new signals, browsers closing them, and regulators deciding where the lines are. The practical advice for individuals stays steady through all of it: a protected, updated browser and careful permissions.

Following the release notes of your browser, even briefly, is a good way to notice new privacy features as they arrive and switch them on.

When fingerprinting protects you

Fingerprinting is not only a tracking tool. Banks, email providers and online stores use device recognition to protect accounts: if someone logs in with your password from an unfamiliar device, the service can ask for extra verification or block the attempt. Fraud prevention systems use device fingerprints to detect stolen cards and fake accounts. Strong anti-fingerprinting protection can occasionally trigger these checks, leading to more verification prompts or captchas. That trade-off is usually worth it, but it explains why some sites react differently when you use privacy-focused browsers.

If a bank or shopping site keeps asking you to verify after you tighten protections, add it as an exception in the browser's tracking protection settings rather than lowering protection everywhere.

What private browsing does and does not do

Private or incognito windows prevent your browser from saving history, cookies and form data on your device after you close the window. They do not, by themselves, hide your fingerprint, your IP address, or your activity from the websites you visit, your employer's network or your internet provider. Some browsers add extra fingerprinting protection in private windows, which helps. Use private windows for what they do well, keeping activity off a shared device, and rely on tracking protection for the rest.

Signing in to an account inside a private window identifies you to that site immediately, fingerprint or not, so private browsing only helps for sites where you stay signed out.

Closing all private windows when you finish is important, since a private session that stays open keeps its cookies until it ends.

Do VPNs stop fingerprinting?

A VPN hides your IP address from websites, replacing it with the VPN server's address. IP address is one tracking signal, so a VPN helps, but it does not change your browser's fingerprint at all. A unique browser on a VPN is still a unique browser. VPNs are useful on public Wi-Fi and for hiding your browsing from your network, but for fingerprinting, browser protections matter far more.

VPN providers can also see your traffic metadata in place of your internet provider, so choose one with a clear no-logs policy and an independent audit if privacy is the reason you use it. Combined with a protected browser, a VPN covers both the network signal and the browser signal.

Free VPNs deserve extra caution, since some fund themselves by collecting and selling the very browsing data you hoped to protect.

If you need real anonymity

For journalists, activists, people escaping abuse and others who face real risk if identified, ordinary privacy settings are not enough. Tor Browser is designed for this: every user presents the same fingerprint, and traffic is routed through several relays. Using a separate device or user account for sensitive activity, never signing in to personal accounts there, and keeping that device updated add further protection. Organizations that support at-risk groups publish detailed safety guides, and seeking their advice is wise, since the right setup depends on who you are protecting yourself from.

For most readers, these measures are more than needed, but knowing they exist helps you recognize when a situation calls for them, such as researching a sensitive health or legal matter.

What this page said in 2019

The original version of this page, from June 2019, reported the SensorID calibration fingerprinting research shortly after it was published. That specific attack was largely closed on iPhones within months and pushed browsers toward permission prompts for sensors. Fingerprinting as a whole has only grown since. This rewrite keeps the SensorID story as a case study and turns it into a practical guide to fingerprinting today.

Revisiting old privacy news this way is useful: it shows which problems were fixed, which spread, and which habits still matter years later.

The researchers' practice of reporting the flaw to Apple and Google months before publishing is also a model for how such findings should be handled.

Ethan's settings after the test

  1. Edge tracking prevention set to Strict.
  2. Six unused extensions removed, leaving a password manager and one blocker.
  3. Third-party cookies blocked.
  4. Site permissions reviewed; motion sensors, location and notifications off by default.
  5. Safari on his iPhone set to protect all browsing from fingerprinting.
  6. A separate browser profile for work, without personal sign-ins.

None of these broke anything he uses daily, and the fingerprinting test moved his laptop from unique to common.

He repeats the test every few months, and after any new extension, to make sure the browser stays in the crowd.

Device fingerprinting: frequently asked questions

What is device fingerprinting?

Identifying a device from its measurable traits, such as browser, fonts and hardware, without cookies.

What was the SensorID attack?

A 2019 technique that used motion sensor calibration errors as a unique, permanent device fingerprint.

Which phones were affected by SensorID?

iPhones, until iOS 12.2, and Google Pixel 2 and Pixel 3 in the researchers' tests.

How did Apple fix it?

iOS 12.2 added noise to sensor data and turned off website motion sensor access by default in Safari.

Does clearing cookies stop fingerprinting?

No. Fingerprints are not stored on your device.

Does private browsing stop fingerprinting?

Not by itself, though some browsers add protections in private windows.

Which browser protects best against fingerprinting?

Tor Browser is strongest; Brave, Firefox Strict and Safari offer good everyday protection.

Does a VPN stop fingerprinting?

No. It hides your IP address but not your browser's fingerprint.

How do I test my browser's fingerprint?

Use a test site such as Cover Your Tracks.

Do extensions make me easier to fingerprint?

Yes, detectable extensions make your browser more distinctive.

Is fingerprinting legal?

It depends on the place and purpose; many privacy laws require consent for tracking.

Can websites read my phone's sensors?

Some can with permission; browsers increasingly require it.

Is fingerprinting used for good purposes?

Yes, for fraud prevention and spotting account takeovers.

Can I change my fingerprint?

Browsers like Brave randomize it; otherwise, blending in with common settings helps.

Does Edge protect against fingerprinting?

Strict tracking prevention blocks known fingerprinting trackers.

What is canvas fingerprinting?

Drawing a hidden image and measuring tiny rendering differences from graphics hardware.

Do apps fingerprint devices?

Some try; Apple and Google restrict it with platform rules.

Did Google allow fingerprinting for ads?

In 2025, Google's ad platform rules began permitting it, drawing regulator criticism.

Ethan still sees ads, but fewer of them seem to know where he has been. His browser runs with strict tracking protection, a handful of extensions instead of a dozen, and site permissions he actually chose. The sensor attack story stuck with him most: a phone's factory quirk turned into a permanent name tag, fixed only because researchers found it first. Fingerprinting will keep evolving. The best defense is a browser that evolves with it, kept up to date.

📌 If you keep one line from this page

Fingerprinting tracks devices without cookies; use a browser with fingerprinting protection, remove extra extensions and limit site permissions.

Test your browser, and keep it updated as protections improve.

Revision note. Written October 2, 2026, rewriting our 2019 news note on the SensorID calibration fingerprinting attack into a complete guide to device fingerprinting and how to reduce it. May your browser look like everyone else's to those who would track it.

Related