Blog

Why Mobile Browsers Are Harder to Tell Apart

Fingerprinting works by finding rare combinations of ordinary properties. On mobile devices those combinations are far less rare, and the reasons are structural rather than a matter of technique.

Hardware and software variety is narrower

A given phone model ships in a handful of configurations and runs a browser version that most owners update to within weeks. Millions of devices end up genuinely identical.

Desktops accumulate difference: installed fonts, attached displays, graphics drivers, peripheral software. Mobile platforms deliberately prevent most of that accumulation.

The result is large equivalence classes. Two phones producing the same fingerprint is common rather than a coincidence worth investigating.

Platform APIs expose less

Mobile browser engines restrict several of the enumeration surfaces that produce desktop entropy. Font lists in particular are effectively fixed by the operating system.

Where a capability is exposed, the answer is often the same across the whole platform. A property that every device answers identically contributes nothing.

Some platforms also normalise rendering output specifically to reduce this signal, so techniques that rely on subtle drawing differences return uniform results.

Screen and font sets cluster tightly

Screen geometry is one of the more useful desktop attributes because window sizes vary continuously. On phones the viewport is dictated by the device and the browser chrome.

That produces a small number of very common values. Knowing the viewport narrows a visitor to a device family, which is useful for layout and nearly useless for identification.

Pixel ratio behaves the same way, taking a handful of standard values across the entire installed base.

Network addresses move constantly

Mobile networks assign addresses from shared pools and reassign them frequently. A device can change address mid-session simply by moving between cells.

Large numbers of subscribers also share a single public address through carrier-grade translation, so the address identifies a carrier region rather than a subscriber.

Network signals that are moderately useful on fixed connections therefore contribute little, and rate limits keyed to an address punish unrelated users.

Detection leans on behaviour and account history

With attribute entropy reduced, mobile detection depends more on what a session does than on what the device is. Interaction timing, navigation order and request sequencing carry the weight.

Account-level history matters more too, since a long-lived account with consistent usage is stronger evidence than any device property a phone can offer.