I spent an afternoon running the same scan on fifty of the most visited websites on the internet.
The Duelling Hares tracking scanner checks four things: how many third-party trackers a page loads, whether it runs fingerprinting scripts, whether it uses canvas or WebGL fingerprinting specifically, and whether it sets basic security headers. No deep packet inspection. No man-in-the-middle setup. Just the same checks a normal browser would expose.
The results were what I expected. That does not make them any less depressing.
The average site on my list loaded 23 third-party trackers. The median was lower at 17, which means a few sites are dragging the average up with extreme numbers. The worst offender loaded 67 trackers on a single page.
Twelve sites loaded 40 or more trackers. Those are mostly content platforms and news organizations. The tracker-to-content ratio was absurd. One article page with 1,200 words of text loaded 51 trackers. That is four trackers per sentence. The advertising infrastructure on that page outweighed the actual content by every possible measure.
Thirty-four sites ran at least one fingerprinting script. Of those, 19 used canvas fingerprinting and 11 used WebGL fingerprinting. Seven sites ran audio fingerprinting through AudioContext. Audio fingerprinting is less common because it is newer and less reliable across devices. But it is growing.
Twenty-eight sites lacked a Content Security Policy header. CSP is one of the most effective defenses against data exfiltration through XSS. It tells the browser what sources can load scripts and make connections. Without it, a compromised ad script can phone home to any server it wants. That is not a theoretical risk. Supply chain attacks through ad networks have compromised major sites before. The absence of CSP on 28 of the top 50 sites means the security baseline is still too low.
Forty-one sites had no Referrer-Policy header. That means your browser sends the full URL of the page you are on when it requests resources from third parties. If you are on a page with sensitive URL parameters like password reset tokens or session IDs, those leak to every third-party resource on the page. This is one of the easiest headers to set and one of the most commonly missing.
The sites with the most trackers were the ones you would guess. Major news portals. Large social platforms. Free content sites that monetize through advertising. The relationship between “free content” and “aggressive tracking” is not a coincidence. If you are not paying for the product, you are the product.
The site with 67 trackers was a news aggregator. Every article page loaded tracking scripts from ad networks, analytics firms, social media widgets, content recommendation engines, and user behavior analytics platforms. The recommendation engine trackers were the most aggressive. They not only tracked what you read. They tracked how long you read it, where you scrolled, what you hovered over. They built a behavioral profile in real time.
I categorized the fingerprinting scripts I detected. The most common was FingerprintJS, which appeared on 14 of the 50 sites. FingerprintJS is open source and widely used. It collects canvas fingerprints, WebGL fingerprints, audio fingerprints, and font enumeration. It generates a visitor ID that persists across clearing cookies and changing IP addresses. Clearing your cookies does nothing against it.
Several sites used proprietary fingerprinting scripts that could not be attributed to any public library. Those are custom-built and harder to detect. They tend to be more aggressive because they are not bound by the norms of open source projects. One of these proprietary scripts was collecting mouse movement patterns on a news site. Mouse tracking is part of behavioral fingerprinting. It maps how you move your cursor and uses that as an identifier. Your mouse movements are as unique as your signature.
HSTS headers were present on 31 sites. That means those sites tell the browser to always use HTTPS. The remaining 19 are vulnerable to SSL stripping attacks where an attacker downgrades the connection to HTTP and intercepts the traffic. SSL stripping is a well known attack. The fix is a single HTTP header. Nineteen of the fifty most visited sites on earth do not set it.
X-Content-Type-Options nosniff headers were present on 27 sites. Without this header, older browsers can MIME-type sniff the response and execute content as a different format. This is how some XSS attacks work. It is also a single header to fix.
Feature-Policy headers were almost nonexistent. Only 4 sites set them. Feature-Policy restricts which browser APIs a page can use. You can block access to the microphone, the camera, the accelerometer. If you are not setting Feature-Policy headers, every third-party script on your page can access every API the browser exposes.
The state of web privacy is not getting better. It is getting more complex. The tools for tracking have become more sophisticated while the tools for protection have barely kept pace. Most sites are not malicious. They are just using the tracking infrastructure that the advertising industry has built over the last twenty years. That infrastructure is now so deeply embedded that removing it would break the business model of half the internet.
You can check any site yourself with the Duelling Hares tracking scanner. Paste a URL and see how many trackers load, which fingerprinting scripts run, and which security headers are missing. The results might surprise you. Or they might just confirm what you already suspected.
The internet is watching you. Every page you load is a data collection opportunity. Some sites collect less. Some collect everything. The only way to know the difference is to check.