Blog

What a Fingerprint Collision Means in Practice

A collision occurs when two different devices yield the same fingerprint. This is often discussed as an edge case, when in reality it is a routine occurrence whose frequency depends on the population being measured.

Collisions are common in uniform populations

Where devices are standardised, identical fingerprints are expected. Managed corporate fleets, mobile devices of the same model and freshly installed systems all produce large groups of identical values.

The uniformity is not a flaw in the collection. It reflects the genuine fact that the devices are configured identically, and no amount of additional collection creates difference that does not exist.

Collision rate is therefore a property of the population rather than of the technique, which is why a scheme that appears precise on one site behaves poorly on another.

Reduced entropy raises the rate deliberately

Browser changes that suppress identifying properties work by increasing collisions, since making more devices look alike is exactly what reducing entropy means.

Privacy-focused browsers take this further by presenting deliberately uniform values, so their users collide with each other by design rather than by coincidence.

From the collecting side this appears as degraded accuracy. From the user's side it is the mechanism working as intended, and both descriptions are correct.

Consequences depend on how the value is used

Used as a key, a collision merges two people's records: one person's history, preferences or risk score is attached to another. The failure is silent and can persist indefinitely.

Used as evidence with a weight, a collision merely means one signal agreed when it should not have, and other signals in the model can outweigh it.

This is the single most consequential design decision in a fingerprinting system, and it is usually made implicitly by whoever wrote the storage schema.

Risk systems suffer specific harms

If a fingerprint carries a reputation, a collision transfers that reputation to an unrelated person. Someone can be treated as suspicious because a stranger with an identical configuration behaved badly.

The affected user has no visibility into this and no way to change it, since the cause is a configuration they share with others rather than anything they did.

Systems that require corroboration before acting on a fingerprint-linked history avoid most of this, at the cost of catching less.

Measuring the rate is possible and rarely done

Collision rate can be estimated by comparing fingerprint groupings against a stronger identifier, such as authenticated accounts, within the site's own traffic.

The result is often much higher than assumed, and it varies enough between sites that borrowing another site's figures is meaningless. Measuring it locally is the only way to know what a match is actually worth.