Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

What a website knows about you before you click anything

Identification does not require cookies any more. Understanding what replaced them explains why blocking cookies changed so little.

Black and white abstract image with the word 'ENCRYPTION' prominently displayed.
Photograph by Ann H via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

The options around online tracking are set out side by side below, with the conditions that genuinely favour one over the other.

The difference in one place

  • Fingerprinting identifies a browser from configuration, with no storage required.
  • Third-party cookies are being retired; server-side and first-party methods are not.
  • The most effective defences reduce the value of tracking rather than preventing it.

Fingerprinting needs no storage at all

A browser reveals its user agent, screen dimensions, timezone, language, installed fonts, and how it renders graphics and audio. Combined, these are frequently sufficient to identify a specific browser among millions without setting anything. Because nothing is stored, clearing cookies has no effect on it whatsoever.

This is the main reason cookie blocking produced far less improvement in tracking than users expected.

Third-party cookies are being retired unevenly

Several browsers block third-party cookies by default and others have repeatedly delayed doing so. The replacement mechanisms — server-side tagging, first-party identifiers, hashed email matching — are less visible and in some respects more durable. The trend is toward identification that a browser cannot see, let alone block.

Removing them also concentrates measurement in the hands of the few companies large enough to see most people logged in already, which makes it a competition outcome as much as a privacy one.

First-party data has become the currency

Logging in ties activity to a stable identifier that works across devices and survives every browser-side defence. This is why so many sites now require or strongly encourage an account for content that previously needed none. An email address given at checkout can be matched across services without any cookie being involved.

Hashing that address before matching is routinely described as anonymisation and is not, because the same address produces the same hash everywhere, which is precisely the property that makes the matching work.

What defences actually do

Content blockers prevent many trackers loading at all, which is the most effective single measure available to most people. Anti-fingerprinting features work by making browsers look alike rather than by hiding information, which is why they sometimes break sites.

The short version: private browsing prevents local storage persisting and does essentially nothing about fingerprinting or server-side identification. Unusual configurations can backfire, since a heavily customised browser is rarer and therefore easier to pick out, which is the counterintuitive reason the strongest designs aim to look ordinary rather than hidden.

Regulation shifts the ground

Consent requirements and the definition of personal data under regimes like GDPR apply to fingerprinting as well as to cookies, whatever the storage mechanism. Enforcement has been uneven and is increasing, and several large fines have concerned consent interfaces specifically. The practical effect for readers is that a consent banner is a legal artefact rather than a technical control.

In practice, obligations also differ by jurisdiction and are applied according to where a site believes you are, so the same page can present a full consent dialogue to one reader and nothing at all to another.

Figures here are typical rather than guaranteed — check the spec sheet for your part.

What leaves before any script runs

Simply connecting discloses your address, the name you asked to resolve, the time, and enough of the connection handshake to characterise the software making it. Server logs record all of that by default and no browser setting removes it, because it is the information required to send a reply at all.

In the datasheet, prefetching and link previews mean requests can be made from your address for pages you never opened, which shows up in logs as a visit you did not make. Encrypted transport hides the content of a request from the network in between and hides nothing from the site you contacted, which is the distinction most padlock explanations skip.

Side by side

ConsiderationWhat it means in practice
Fingerprinting needs no storage at allFingerprinting identifies a browser from configuration, with no storage required.
Third-party cookies are being retired unevenlyThird-party cookies are being retired; server-side and first-party methods are not.
First-party data has become the currencyThe most effective defences reduce the value of tracking rather than preventing it.

The takeaway

Blocking storage stopped being the defence. Blocking the request is what still works.

Once you know what it is trading away, the design stops looking arbitrary.

Questions readers ask

Does private browsing hide me?

From other users of the same device, largely. From websites, very little — it does not change your address, your fingerprint or anything a server records.

Is a VPN enough for privacy?

It hides your address from sites and your traffic from your network provider, and it does nothing about fingerprinting, logins or cookies. It moves trust to the VPN operator rather than removing it.

Data & Privacytrackingprivacyfingerprintingbrowsers
Farida Osei
Networks writer, Tech Behind Things

Farida writes about wireless standards and spent six years in network engineering before switching to explaining it.

Also by Farida Osei