THE DECLASSIFIED
COLLECTION
← All articles

Society & surveillance

Your browser could identify you without a tracking cookie

The 2010 Panopticlick study showed that combinations of ordinary browser properties could distinguish users. Its lesson is about uniqueness within a population, not a permanent identification rate.

Recognized without a saved tag

A tracking cookie stores a label that a website can recognize later. Browser fingerprinting attempts something different: it combines observable properties of the browser and device into a distinguishing pattern. Peter Eckersley's 2010 study measured how effective that could be among visitors to the Electronic Frontier Foundation's Panopticlick test.

The analysis included 470,161 browser instances after processing. In that historical sample, 83.6 percent had an instantaneously unique fingerprint. The paper examined features including browser identification, screen information, plugins and fonts. None needed to be a person's name for their combination to become distinctive.

Ordinary details can make an unusual combination

Imagine describing a car by colour, model and a distinctive accessory. Each property may be common, while the combination is rare in a particular parking lot. Fingerprinting uses that combinatorial effect. It can distinguish an endpoint before its observer knows the human identity behind it.

Recognition and identification are therefore separate steps. Linking several visits to the same browser does not automatically reveal a legal name. But if one of those visits later includes an authenticated identity, the earlier linkage can acquire a different significance. Evaluating privacy requires following the whole chain, rather than asking whether the first measurement contained an obvious personal identifier.

Unique where, and for how long?

The paper explicitly discusses its non-random, privacy-conscious sample. Uniqueness among test visitors is not the same as uniqueness among all browsers on Earth. The reported 2010 percentage should not be used as a current measurement after years of changes in software, device populations and privacy features.

Stability matters too. A fingerprint may change when software or settings change. The study examined whether changing patterns could still be linked. A privacy evaluation thus needs both distinctiveness and persistence: how unusual a pattern is now, and how reliably an observer can connect it to an earlier one. These are related but different questions.

Individual changes can have collective effects

A counterintuitive issue is that a rare protective configuration can itself become identifying. The relevant protection is not always maximizing the number of unusual settings. It can depend on looking similar to a sufficiently large group. That is a design problem involving a population of users, not merely an individual checklist.

The archive preserves this paper as a historical demonstration of the problem. It is not a current recommendation to copy its browser settings or rely on technologies that have since changed. Read its results alongside its measurement definitions and sample limitations. The enduring insight is that privacy can be lost through combination: small technical details, individually mundane, may together support recognition across otherwise separate encounters.

Sources and further reading

  1. How Unique Is Your Web Browser? ↗

    Eckersley, PETS 2010; §§1, 3–5, Figures 1–3; 470,161 analyzed instances

Continue reading

Facebook changed 689,003 people's feeds for an emotion experiment ↗The U.S. experiments that exposed people to disease without consent ↗The Army dispersed tracer particles over American cities ↗