I pulled up the Duelling Hares browser fingerprint tool and hit the scan button.
Three seconds later, I was staring at a number that made me pause. 17.82 bits of entropy. That is the statistical uniqueness of my browser configuration. In plain English: out of every 200,000 browsers on the web, mine is the only one with this exact combination of properties.
Two hundred thousand.
And I had not changed a thing. I was running a stock browser with a couple of extensions. No VPN. No fingerprinting protection. Just a normal setup that most people would call “private enough.”
It is not private enough.
Cookie banners are a distraction. They make you think the privacy fight is about opting in or out of a tracking database. That is not how modern web tracking works. Cookies are the visible layer. They are the thing websites ask about because regulations force them to. Beneath that layer, browser fingerprinting runs silently. No popup asks for your permission. No dialog box explains what data is being collected. The site just reads your browser’s characteristics and assembles a profile.
Every browser has a fingerprint. It is made of properties that websites can access through JavaScript without asking. Screen resolution, installed fonts, GPU model, the way your browser renders a hidden canvas element. Individually each property is harmless enough. Together they form a pattern that can identify you across sessions and across sites.
The Duelling Hares tool runs through dozens of these properties and shows you the full picture. I watched it enumerate every font installed on my system. It drew a hidden canvas and extracted a hash of the rendering. It checked my WebGL renderer, my timezone, my language settings. Each check took less than a second.
Canvas fingerprinting works by exploiting a tiny difference in how browsers render graphics. Every combination of hardware, operating system, browser version, and GPU driver produces a slightly different image. The same canvas element drawn on two different machines will never hash the same way. The site draws the canvas, converts it to a hash, and stores it. Next visit, it draws again and checks. Same hash. Same visitor.
No cookie required.
Apple tried to block canvas fingerprinting in Safari by returning a blank canvas. Fingerprinting scripts adapted. They moved to WebGL. They moved to AudioContext, which measures how your device processes sound. The adaptation is constant. You fix one leak and three more open.
The Duelling Hares tool checks for canvas, WebGL, and AudioContext fingerprinting. It also checks for canvas fingerprinting with font enumeration. That method loads a hidden font, renders text with it, and checks whether the hash changed. If it changed, the fingerprinting script just gained one more vector.
My browser was flagged for WebGL fingerprinting susceptibility. That means a site could use my GPU model and driver version as part of my identity. Most people do not change their GPU. It is practically permanent. My screen resolution was 1920×1080, which is the most common resolution and therefore not very identifying by itself. But my color depth, my system font list, and my timezone offset combined narrowed the field fast.
The tool assigned me a fingerprint uniqueness score. 1 in 200,000. That is not the worst I have seen. It is not good either.
I ran the same test on a browser with privacy protections enabled. Canvas blocked. WebGL disabled. Font enumeration blocked. The entropy dropped to 7.3 bits. That means my configuration was now one in about 150. Not anonymous, but far harder to track across the open web. The difference between “uniquely identifiable” and “one person in a small crowd” is a few settings changes.
Cookie education has been happening for fifteen years. Most internet users understand at a basic level that cookies track them. Fingerprinting has no such awareness campaign. It runs silently in the background on thousands of major websites. The scripts are tiny, fast, and invisible to the user. If you do not know what to look for, you will never see it.
I run these scans every few months. Every time, my fingerprint changes slightly as my browser updates, as fonts get added or removed, as my screen setup evolves. But the uniqueness stays high. The browser updates sometimes reduce entropy. More often they increase it. New features mean new fingerprintable properties.
Run the scan on your own browser at the Duelling Hares browser fingerprint tool. It takes five seconds. Look at your entropy score. Look at which properties are leaking the most identifying data. Then decide what you want to do about it.
You do not have to accept being tracked. But you have to know what tracking looks like first. And it does not look like a cookie consent popup.