Ad tech stocks
TEAD0.58▲ +13.19%186013.51▲ +7.48%PSKY9.79▼ -5.18%CDLX2.80▼ -4.77%DSP12.70▲ +3.17%U42.19▲ +3.07%SAX36.50▲ +2.93%MNTN10.46▲ +2.85%OMC75.61▲ +2.68%APP282.96▼ -2.57%INUV0.58▲ +2.49%STGW8.34▲ +2.46%IHRT2.05▼ -2.38%CCO2.40▲ +2.34%WPP384.90▲ +2.34%SIRI25.39▼ -1.89%RDDT145.07▲ +1.85%LFTO15.53▼ -1.74%CPNG13.63▼ -1.69%TBLA3.31▼ -1.64%PUB96.04▲ +1.61%APPS11.28▲ +1.58%NFLX68.48▼ -1.58%SST2.58▼ -1.53%TRU62.02▲ +1.47%SCOR4.75▲ +1.39%035420191200.00▼ -1.29%4755681.70▼ -1.26%AZRN0.82▼ -1.20%ZETA31.92▲ +1.11%PUBM18.92▲ +1.00%HAVAS17.80▲ +0.85%PINS18.73▼ -0.82%GOOGL341.74▼ -0.68%ROKU151.32▼ -0.63%SNOW341.70▲ +0.63%AAPL330.96▼ -0.62%47511238.50▲ +0.57%BIDU86.44▼ -0.50%SFOR45.80▼ -0.43%24331308.00▲ +0.38%BABA107.82▲ +0.26%0700431.00▼ -0.23%RAMP37.60▲ +0.23%PERI8.67▼ -0.23%CART43.04▼ -0.19%IBTA39.47▲ +0.18%OUT27.70▼ -0.18%VER12.10▲ +0.17%DEC24.68▲ +0.16%CRTO15.18▼ -0.13%TTD12.19▲ +0.12%NEXN8.99▼ -0.11%META725.80▲ +0.09%SNAP5.41▲ +0.09%DV13.48▼ -0.04%SPOT487.50▲ +0.03%43243564.00▲ +0.03%WBD30.95▼ -0.02%ILLM0.65▲ 0.00%MGNI25.26▲ 0.00%
Ticker byClearTrust

Invalid traffic & fraud · also called Browser fingerprinting, fingerprinting

Device fingerprinting

Device fingerprinting is identifying or characterising a device from the combination of its technical attributes, such as browser, fonts, screen, graphics and network traits, instead of a stored cookie or ID.

The short answer, from the AdTech Sumo glossary

Every browser and device leaks small details: operating system, screen resolution, time zone, language, installed fonts, graphics card behaviour, audio processing quirks and many more. Combined, they can form a pattern distinctive enough to recognise the same device again, or to tell whether a device is what it claims to be.

Fingerprinting has two uses that must be kept apart. For tracking and targeting, it is controversial: users cannot clear it like a cookie, and the W3C, browser makers and regulators treat covert fingerprinting as a privacy concern. Apple bans using it for tracking in apps, and data protection laws such as GDPR generally treat it like other identifiers.

For fraud detection, fingerprints are a key SIVT signal. The question is not "who is this?" but "is this consistent?" A claimed iPhone that renders graphics like a Linux server, a "new" device whose traits exactly match thousands of others, or a browser exposing automation flags are strong indicators of device spoofing, emulators or headless bots. Fraud detection is one of the purposes privacy frameworks commonly recognise as legitimate.

Think of it like this

Fingerprinting is like recognising a friend's handwriting: no name on the envelope, but the loops and slants give it away, and a forgery looks subtly wrong.

An example

A verification vendor sees 50,000 "different" Android phones in Nigeria sharing an identical combination of screen size, GPU string, fonts and audio signature, which is statistically near-impossible for real devices, and flags them as an emulator cluster.

Related terms

Sources: W3C: Mitigating Browser Fingerprinting in Web Specifications, Apple: User privacy and data use, MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update)