Browser Fingerprinting: What a VPN Does and Does Not Change, and What the Research Shows

A tracking method a VPN does not address on its own

A VPN changes the IP address websites see. Browser fingerprinting is different: it combines details your browser volunteers, such as screen size or language, into an identifier that does not depend on cookies. This article summarises what two academic studies and a 2025 comparison of earlier ones actually measured, and then explains, as reasoning rather than measurement, what that means for VPN users. None of the studies read here tested VPN use.

The first big study, and its bias

In 2010 Peter Eckersley of the Electronic Frontier Foundation published “How Unique Is Your Web Browser?”, collecting fingerprints from 470,161 browsers that visited the Panopticlick test site. He describes the sample as quite biased, but likely representative of internet users who pay enough attention to privacy to take minimal steps such as limiting cookies. In that sample, 83.6 per cent of browsers had an instantaneously unique fingerprint, rising to 94.2 per cent among browsers with Flash or Java enabled. The distribution carried at least 18.1 bits of entropy, meaning at best about one in 286,777 other browsers would share a random browser’s fingerprint.

Two other findings matter. Fingerprints changed quickly: among 8,833 returning visitors who accepted cookies, 37.4 per cent showed at least one change. But a simple heuristic could often link a changed fingerprint back to its earlier version, with 99.1 per cent of guesses correct and a 0.86 per cent false positive rate. Eckersley also noted that a fingerprint carrying only 15 to 20 bits would usually be enough to identify a browser when combined with its IP address, subnet or even autonomous system number.

Later studies disagree

A 2025 paper by Alex Berke and colleagues, published in the Proceedings on Privacy Enhancing Technologies, reviews what followed. It notes that a 2016 study of 118,934 browsers via AmIUnique reported 90 per cent of desktop and 81 per cent of mobile fingerprints as unique, while a 2018 study of over 2 million fingerprints collected on a French news site reported only 33.6 per cent unique using the same 17 attributes.

Berke and colleagues then collected browser data, with informed consent, from 8,400 US participants, using 13 attributes chosen for stability and uniqueness. Approximately 60 per cent of users in their dataset had a unique overall fingerprint. They caution that the figures are specific to their dataset, and that a larger dataset may yield lower uniqueness. They also say browsers have since made privacy changes: some now return random or hard-coded values for plugin and font lists, which is why they collected but did not use those attributes.

Why the numbers differ so much

The spread from about 34 per cent to 94 per cent is not a contradiction so much as a reminder that the answer depends on who is sampled, which attributes are collected, how large the sample is, and when the study was done. Volunteer samples drawn from technology-focused sites, as in the early studies, differ from news-site visitors or a recruited panel. Attributes also change with browser updates. A single headline such as “84 per cent of browsers are unique” should therefore be read as the result of a specific 2010 sample, not a current universal statistic.

Berke and colleagues also report that fingerprinting risk differed across demographic groups in their data, with lower-income users more at risk, which is a reminder that the risk is not uniform. This guide does not examine the details of that analysis.

What a VPN changes, by reasoning

The attributes measured in these studies come from the browser: user agent, languages, time zone, screen resolution, graphics renderer and similar. Berke and colleagues say they collected them through client-side JavaScript. A VPN changes the network path and the IP address, not those browser settings, so by reasoning it would not change those attributes. That is an inference, not a tested result, since none of the papers evaluate VPNs. The one place a VPN may help is the IP-address link Eckersley describes, where a fingerprint plus an IP address can tie a new cookie to an old one; switching IP addresses could weaken that particular link, though other identifiers might still connect sessions.

Time zone and language settings are among the attributes in these datasets, so they may still point to your real region even when your IP address suggests another.

What helps, as far as these sources go

Eckersley concluded that anti-fingerprinting privacy tools can be self-defeating if not used by enough people, because unusual settings can make a browser stand out. Berke and colleagues note that some browsers have introduced privacy-protective changes, such as returning random or hard-coded plugin and font values. Neither paper measures a full protection strategy, so treat browser hardening, tracker blocking and a VPN as complementary measures with different jobs rather than as guarantees.

The bottom line

Fingerprinting studies report uniqueness from about 34 per cent to 94 per cent depending on sample, attributes and date, and none tested VPNs. A VPN hides your IP address but, by reasoning, leaves browser-reported attributes such as screen size and time zone untouched. Do not rely on a VPN alone for anonymity, and treat any single uniqueness figure as tied to its dataset.

Sources