What is device fingerprinting? | Transmit Security

Glossary

What is device fingerprinting?

Device fingerprinting identifies a device from its attributes to recognize returning users and detect fraud.
by Transmit Security

Device fingerprinting is a technique that identifies and recognizes a device by collecting and combining its many attributes (hardware, software, browser, and configuration details) into a distinctive "fingerprint," even without cookies or a logged-in user. It’s a foundational fraud-detection signal, letting a business recognize a returning device, spot suspicious or spoofed environments, and link fraudulent activity across accounts.

Because a device’s exact combination of characteristics is often close to unique, fingerprinting can recognize the same device across sessions, powerful for both distinguishing trusted returning customers and catching fraudsters trying to hide behind new accounts.

What goes into a device fingerprint

A fingerprint is assembled from many signals, no single one identifying, but distinctive in combination:

  • Hardware and OS: device model, operating system and version, screen resolution, CPU/GPU characteristics.
  • Browser attributes: browser and version, installed fonts, plugins, language, time zone, canvas/WebGL rendering quirks.
  • Network: IP address and connection characteristics (used cautiously, as IPs change).
  • Configuration: settings and capabilities that vary from device to device.

Combined, these produce an identifier stable enough to recognize a device over time, yet independent of cookies (which users clear and privacy tools block).

How device fingerprinting fights fraud

Fingerprinting drives fraud prevention in several ways. It recognizes trusted devices, so a returning customer on a known device can be treated with less friction (supporting risk-based authentication). It flags suspicious environments: emulators, virtual machines, anti-detect browsers, or spoofed configurations that fraudsters use to appear as many different users. And it links activity across accounts: if one device is behind dozens of "different" registrations or login attempts, that connection exposes fraud rings, credential-stuffing campaigns, and mass fake-account creation that would otherwise look independent.

Device fingerprinting vs. cookies

Cookies were the traditional way to recognize returning users, but they’re easily cleared, blocked, or isolated by privacy features, and they don’t survive incognito mode. Device fingerprinting is more resilient because it derives identity from the device’s inherent characteristics rather than a stored file, which is exactly why it’s valuable for fraud detection, where adversaries deliberately clear cookies to appear new. Modern approaches also use cryptographic device identifiers (see crypto binding and device identity) for even more durable, tamper-resistant recognition.

The privacy dimension

Device fingerprinting sits in a sensitive area, because the same technique that fights fraud can also track users. Responsible use focuses fingerprinting on security and fraud-prevention purposes, is transparent about it, and complies with privacy regulations (GDPR and others treat fingerprinting as personal-data processing requiring a lawful basis). The distinction that matters is purpose: using device signals to protect accounts and stop fraud is defensible and expected; using them to covertly track users for advertising is what regulators scrutinize.

Fingerprinting as part of a broader signal set

Device fingerprinting is powerful but strongest in combination. On its own it can be spoofed by determined fraudsters using anti-detect browsers that fake attributes. Fused with behavioral signals (how the user interacts), network intelligence, and identity context, it becomes far harder to defeat, which is why leading fraud engines treat the device fingerprint as one input into a unified risk decision rather than a standalone verdict. As a durable, cookieless recognition signal that works across the lifecycle, it remains one of the most important tools in fraud detection.

The arms race with spoofing

Device fingerprinting is locked in an ongoing arms race with evasion tools. As fingerprinting matured, fraudsters built anti-detect (or "antidetect") browsers designed specifically to defeat it, spoofing or randomizing fingerprint attributes so each session looks like a fresh, distinct device. These tools let one operator appear as thousands of unique users, undermining the linking that makes fingerprinting valuable. The defensive response is twofold: detect the spoofing itself (anti-detect browsers, emulators, and virtual machines leave their own tells and inconsistencies), and fuse the device signal with others that are harder to fake in concert: behavior, network, and identity. A spoofed fingerprint might fool a naive check, but it’s far harder to simultaneously fake a convincing fingerprint, human-like behavior, a clean network origin, and a consistent identity history. This is why modern device intelligence emphasizes detecting tampering and evasion, not just reading attributes at face value.

Frequently asked questions

Can fraudsters defeat device fingerprinting?

They try, using anti-detect browsers, emulators, and VMs to spoof attributes, which is why detecting evasion and fusing device signals with behavior and network intelligence matters.

What is device fingerprinting?

A technique that identifies a device from its combined attributes to recognize returning users and detect fraud, without relying on cookies.

What data does a device fingerprint use?

Hardware and OS details, browser attributes (fonts, plugins, rendering), configuration, and network characteristics, combined into a distinctive identifier.

How is device fingerprinting different from cookies?

Fingerprinting derives identity from the device’s inherent characteristics, so it’s resilient to cookie clearing, blocking, and incognito mode.

Is device fingerprinting legal?

Used for security and fraud prevention with transparency and a lawful basis, yes: but privacy laws treat it as personal-data processing, and covert tracking is scrutinized.

Can device fingerprinting be spoofed?

Determined fraudsters use anti-detect browsers to fake attributes, which is why fingerprinting is strongest combined with behavioral and network signals.

Related: Device Identity / Device ID · Behavioral Biometrics · Anti-Detect Browser Detection · Emulator Detection · Crypto Binding · Fraud Detection

Request a Demo

By clicking the button, you agree to the Terms and Conditions