Why Randomised APIs Break Naive Fingerprinting
Browsers have begun perturbing the outputs of certain identifying interfaces rather than removing them. The approach is deliberately asymmetric: it costs legitimate uses almost nothing and costs exact-match identification everything.
Noise is added per session and per origin
The perturbation is derived from a value that varies by browsing session and by the site being visited, so the same interface returns different results on different sites at the same moment.
Within a session and a site the noise is consistent, which means a page reading the same value twice gets the same answer and does not observe obvious inconsistency.
Because the noise varies per origin, two sites cannot compare results and find them equal, which is the specific capability being removed.
The magnitude is chosen to be functionally invisible
Perturbations are small relative to what the interface is used for. Slight variation in rendering output or in a measured value does not change how a page displays or behaves.
This is what makes the approach viable where outright removal is not. Removing these interfaces would break genuine functionality, while perturbing them breaks only the identifying use.
The trade-off is that applications with legitimate need for precise values are affected, and those cases have to be handled through permissioned interfaces instead.
Exact-match schemes fail immediately
Any system that hashes collected values into a single label produces a different label on every session, because one changed input changes the whole hash.
From the collector's perspective every visit appears to be a new device, which is the same failure mode as heavy configuration churn but occurring universally and constantly.
Systems built on exact matching therefore stop functioning rather than degrading, which is a more visible outcome than the gradual entropy reduction happening elsewhere.
Statistical recovery is possible but expensive
Noise can in principle be averaged out by sampling the same value many times, since the underlying signal is constant and the perturbation is not.
Implementations counter this by keeping the noise stable within a session, so repeated sampling returns the same perturbed value rather than independent draws.
Recovering the underlying value then requires observations across many sessions, which takes time, is detectable as unusual behaviour, and delivers a result long after it would have been useful.
The effect is to raise cost, not to end identification
Randomisation does not make devices indistinguishable, since many identifying properties are not perturbed and behavioural signals are untouched.
What it does is remove the cheapest and most widely deployed technique, pushing identification towards methods that are harder, slower and more conspicuous. That is the same economic logic detection systems apply in the other direction, and both sides are playing the same game from opposite ends.