How fingerprinting works
Every browser gives away small details as it loads a page: the operating system, screen size, timezone, language, installed fonts, graphics behaviour, audio processing, which extensions have altered the page. Individually none of these identifies anyone. Combined, they form a pattern distinctive enough to recognise the same device on a later visit, or on another website, with no cookie stored anywhere.
Passive fingerprinting reads what the browser announces anyway. Active fingerprinting goes further and asks the device to perform small tasks — draw a shape, process a sound — because the tiny differences in the result vary between hardware and driver combinations. The output is turned into an identifier and stored on a server, not on the device, which is the whole point: there is nothing for the visitor to clear.
Browsers now push back. Safari and Firefox both reduce or randomise the signals available, Firefox blocks known fingerprinting scripts in its stricter mode, and privacy-focused browsers make devices look deliberately alike.
Why fingerprinting matters
It matters mostly because it is what gets sold to you. As third-party cookies became unreliable, a wave of tools appeared promising cookieless identity, full attribution or complete recovery of lost conversions. A fair number of them are doing some form of fingerprinting under a friendlier name.
That creates real exposure. Removing the cookie does not remove the legal question: European and UK rules treat reading information from someone’s device, and building a profile from it, as something that needs a lawful basis and usually consent. Ad platform policies have long restricted it, and although the wording on some platforms has been loosened, data protection regulators have been openly critical of that direction. Browsers, meanwhile, are moving the other way. A technique that is simultaneously being blocked and being questioned by regulators is a poor foundation for a measurement plan.
Where fingerprinting goes wrong
The first failure is the assumption that no cookie means no consent needed. That is not how the law reads, and it is the reasoning most often used to justify buying one of these tools.
The second is accuracy. Fingerprints drift. A browser update, a new monitor, a font install or a switch from mobile data to wi-fi can change the pattern, so the same person is counted twice or two similar office laptops are merged into one. Reports built on it look precise and are not.
The third is a confusion of purpose. Checking a device signal to stop repeated fraud on a payment form is a narrower and more defensible use than following someone around the web to sell them a sofa. Vendors often quote the first to justify the second.
What to do about it
Do not buy identity you are not allowed to keep. Ask any vendor promising cookieless measurement exactly what signals they read and where the identifier is stored; if the answer is vague, that is your answer.
Build on data people knowingly give you instead: an email address at checkout, a phone number on an enquiry form, a logged-in account. That information can be hashed before it is sent to an ad platform, which is a different thing entirely from covertly identifying a device. Pair it with server-side collection and honest reconciliation against your own sales records, and you end up with numbers you can defend to a client and to a regulator.