you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 13 min ago 255 onions tracked
home / news / security
07 October 2025 security 3 min read

Fingerprinting in Tor Browser: What Still Leaks and What Does Not

Tor Browser is widely regarded as the strongest mainstream defense against browser fingerprinting, and for good reason. But it never promised to make you untraceable by every tracker on the web. Its promise is narrower and more interesting: make you look exactly like every other Tor Browser user.

The uniformity defense, explained

Most anti-fingerprinting tools try to hide your device by changing its values on every visit. Tor Browser takes the opposite approach, spelled out in the official design and implementation specification: all users of one browser version should behave as uniformly as possible. The Tor team explicitly rejected randomization as a primary strategy. Incomplete randomization can be averaged out, modeled, or simply ignored by sophisticated trackers, which makes it a false comfort. Uniformity is also easier to audit, because tools like EFF's Cover Your Tracks, the successor to Panopticlick, can directly measure whether one browser build produces one fingerprint.

Canvas, fonts, and WebGL under control

The design document calls HTML5 canvas extraction the single largest fingerprinting threat browsers face, since a hash of rendered pixels acts much like a tracking cookie. Tor Browser's answer is blunt. Unless you approve a per-site prompt, JavaScript receives pure white image data instead of your GPU's handiwork. Fonts get similar treatment. Enumeration is restricted to a small allowlist, and system font names are normalized so a customized Windows setup looks like any other. WebGL runs in a reduced capability mode that strips driver and vendor details, closing the channel researchers once used to identify video cards.

Letterboxing kills the resolution leak

Your exact window size used to be a gift to trackers, because odd dimensions are nearly unique. Since 2019, Tor Browser has shipped letterboxing, a Mozilla-developed technique that rounds the content viewport to multiples of 200x100 pixels and fills the leftover space with gray bars. The result is that screen and window queries return one of a few common buckets rather than your true monitor geometry. It is visually noticeable and occasionally annoying. That trade-off is deliberate: convenience spent here buys a far larger anonymity set.

What still leaks

Some attributes cannot be hidden without breaking the web entirely. The Tor Project notes that operating system family and language remain partially visible, limited rather than eliminated. Timezone is pinned to UTC, yet finer signals such as performance timing, keyboard layout quirks, and writing style sit largely outside any browser patch. Cross-browser fingerprinting remains unsolved by design. If your hardware clock drifts oddly or your connection behaves unusually, no uniformity setting will erase it. The defense only shrinks differences among Tor Browser users, and it does that job, nothing more.

How users undo everything

The defenses hold only inside a stock configuration. Real-world deanonymization usually begins with the user, not the code. Common self-inflicted wounds include:
  • Installing extra extensions, themes, or fonts that carve you out of the crowd
  • Tweaking about:config values such as disabling resistFingerprinting
  • Granting permanent canvas or WebGL permissions to sites you revisit
  • Browsing in fullscreen or resized windows that fall outside common buckets
Each change shrinks your anonymity set, sometimes to a handful of people worldwide. As our tor guide stresses, keep the defaults and use New Identity between sessions. For ongoing coverage of tracking techniques, see our security notes. The browser does its part; the rest is discipline.

more notes

all news ›