Device Fingerprinting: How It Works, Where It Fails
Device fingerprinting builds an identifier for a phone or browser from its attributes, such as model, operating system, screen and network details, so a business can recognise the same device again. It helps link fake accounts and spot returning fraudsters. But emulators, spoofed specs and factory resets can break it, so fraud teams pair fingerprints with device risk signals.
What Device Fingerprinting Is
Put simply, device fingerprinting is a way to recognise a device without asking the user anything. First, the system collects a set of attributes from the phone or browser. Then it combines them and turns them into an identifier. Later, when the same device returns, the attributes produce the same, or a very similar, identifier.
Fraud teams use that identifier for three jobs. First, they spot one device behind many accounts, which points to fake signups or promo abuse. Second, they recognise a returning device that earlier cases tied to fraud. Third, they notice when a known customer suddenly logs in from an unfamiliar device, which can signal an account takeover.
A fingerprint is not a password or a hardware serial number. Instead, it is a best guess built from many small clues. That makes it useful, but also fragile in ways that matter, as later sections show.
Signals a Device Fingerprint Uses

No single attribute identifies a device on its own. Instead, the strength comes from combining many attributes that vary between devices. However, the exact mix depends on whether the fingerprint runs in a browser or inside a mobile app.
| Signal group | Browser examples | Mobile app examples |
|---|---|---|
| Hardware | Screen size, colour depth, CPU cores, GPU details | Device model, manufacturer, screen, sensors present |
| Operating system | OS and version reported by the browser | OS version, build number, security patch level |
| Software | Browser version, fonts, plug-ins, language | App version, install source, system settings |
| Rendering | Canvas and WebGL drawing differences | Rarely used in apps |
| Network | IP address, time zone | IP address, carrier, Wi-Fi or mobile data |
| App-scoped IDs | Cookies and local storage | Install IDs and vendor IDs that reset on reinstall |
Meanwhile, some identifiers that once made this easy are now off-limits. For example, Android 10 restricted ordinary apps from reading non-resettable IDs such as the IMEI. Apple removed app access to the device’s unique ID back in 2013. Since iOS 14.5 in 2021, apps also need permission to use the advertising ID for tracking. So modern fingerprints rely on combinations of softer signals rather than one fixed number.
How Stable a Fingerprint Is Across Resets and Updates

In practice, a fingerprint has to balance two goals. It must be unique enough to tell devices apart, yet stable enough to recognise the same device next week. For example, push too far towards uniqueness, and a minor update creates a “new” device. Push too far towards stability, and different devices start to look alike.
| Event | Typical effect on a fingerprint |
|---|---|
| App or browser update | Small change, so good systems still match the device |
| Operating system update | Several attributes change, so matching becomes probabilistic |
| App reinstall or cleared browser data | App-scoped IDs reset, so hardware attributes carry the match |
| Factory reset | Most software attributes reset, so the device may look brand new |
| Network change | IP and carrier change, but these are weak signals on their own |
Good fingerprinting therefore uses fuzzy matching. Rather than demanding an exact match, it scores how similar a new fingerprint is to known ones. In practice, that keeps genuine customers recognisable through updates, while still flagging devices that change too much, too fast.
Where Device Fingerprinting Breaks: Emulators, Spoofed Specs and Factory Resets
Unfortunately, fraudsters know how fingerprints work, and they attack the weak points directly. These are the failure modes every fraud team should plan for.
Emulators and Virtual Devices
Emulators simulate an Android phone on a desktop computer. Because the attacker controls every reported attribute, they can create endless “new” devices from one machine. Without emulator detection, each one looks like a fresh customer.
Spoofed Device Specs
Device masking tools and anti-detect browsers report fake models, screen sizes and system details. With that spoofing, one real phone can pretend to be many different ones. A fingerprint built only from reported attributes cannot tell the difference.
Factory Resets
A factory reset wipes most software attributes. Fraud rings use resets to recycle a phone after a ban, so the next account appears to come from a new device. Of course, a single reset is normal, but a pattern of resets is a strong fraud signal.
Shared and Second-Hand Devices
Failure also runs the other way, however. Families share phones, and second-hand phones change owners. A naive rule that blocks “one device, several accounts” will reject genuine people. So fingerprint links should feed a risk score, not trigger automatic bans.
These failure modes explain why fraud teams treat a fingerprint as one input among several. For the wider toolkit, see how a fraud detection system combines device, identity and transaction signals.
How to Use Device Fingerprints in Fraud Rules
A fingerprint becomes valuable when you turn it into rules. These patterns work well as a starting point, and you can tune them with your own data.
- Accounts per device. Flag a device that creates several accounts in a short window, but allow for households.
- Devices per account. Watch accounts that hop between many devices, which often signals sharing or resale.
- New device plus high value. When a known customer moves money from an unfamiliar device, ask for a step-up check.
- Known bad devices. Link new signups to devices tied to past fraud, then route them to review.
- Reset frequency. Treat repeated factory resets on one handset as a risk signal, especially after a ban.
Above all, score these patterns rather than blocking on any single one. That way, genuine customers rarely notice, while organised fraud rings stand out quickly.
Browser vs Mobile SDK Fingerprinting
Importantly, where the fingerprint runs changes what it can see. Browser scripts and mobile SDKs have very different access.
| Browser fingerprinting | Mobile SDK fingerprinting | |
|---|---|---|
| How it runs | JavaScript on a web page | A library inside your app |
| Attributes available | Limited to what the browser exposes | Richer hardware, OS and app details |
| Stability | Lower, because privacy features block or randomise signals | Higher, within OS privacy limits |
| Tamper detection | Weak, since the attacker controls the browser | Stronger, because it can check for root, hooking and emulators |
| Best fit | Web signups and logins | Mobile banking, e-wallets, delivery and gaming apps |
For mobile-first businesses in Southeast Asia, the SDK route usually wins. After all, most customers use apps, and an SDK can check the device’s integrity as well as its identity.
Privacy Considerations for Device Fingerprinting
Because fingerprinting collects information from a user’s device, privacy rules apply. In the EU, regulators read the ePrivacy rules on accessing device information as covering fingerprinting techniques, according to European Data Protection Board guidelines adopted in 2024. Similarly, many Asian privacy laws treat device identifiers as personal data when they link to a person.
- Be clear about purpose. Say in your privacy notice that you use device signals for security and fraud prevention.
- Do not repurpose. Avoid using a fraud fingerprint for advertising or cross-site tracking.
- Collect only what you need. Skip attributes that add privacy risk without improving fraud detection.
- Set retention limits. Keep fingerprints only as long as the security purpose requires.
- Check platform policies. App stores restrict certain identifiers, so confirm your SDK follows their rules.
This is general guidance rather than legal advice, so confirm requirements with counsel in each market you serve.
Device ID vs Device Risk: When a Fingerprint Is Not Enough
Ultimately, a fingerprint answers one question: have we seen this device before? It does not answer a second, often more important one: can we trust this device right now? For example, a known phone might run with root access today, host a cloned app, or share its screen with a scammer.
By contrast, device risk signals answer that second question. They look at the state of the device and the session, not just its identity. On the Verihubs Device Intelligence page, for example, the listed signals include:
- Integrity: root or jailbreak, emulator, app hooking, debug mode, app tampering and cloned apps.
- Disguise: device masking, virtual OS, secondary user profiles and suspicious factory resets.
- Network and location: VPN, proxy and GPS spoofing.
- Session context: active calls, screen sharing and auto clickers.
- Usage patterns: one device shared across several user IDs, and tampered payloads in transit.
You need device risk, not just a device ID, when attackers can reuse clean-looking devices. That covers account takeover, scams that coach victims through transfers, and automated fraud from emulator farms. In those cases, the fingerprint says “known device”, while the risk signals say “do not trust it today”. Our checklist of fraud detection software features covers how to evaluate both.
Frequently Asked Questions About Device Fingerprinting
What is device fingerprinting?
Device fingerprinting is a technique that recognises a phone or browser by combining its attributes, such as model, operating system, screen and network details, into an identifier. It helps businesses spot returning devices without asking users for anything.
Is device fingerprinting accurate?
It is good at recognising devices that behave normally, but it weakens when attackers use emulators, spoofed specs or factory resets. Fuzzy matching and device risk signals make it far more reliable for fraud prevention.
Can someone change a device fingerprint?
Partly. Updates, reinstalls and factory resets change many attributes, and spoofing tools can fake them. Well-designed systems still link many of these changes back to the same device and flag suspicious patterns of change.
What is the difference between browser and mobile fingerprinting?
Browser fingerprinting runs as a script and sees only what the browser exposes. Mobile SDK fingerprinting runs inside the app, sees richer device details and can check for tampering such as root access or emulators.
Is device fingerprinting legal?
Generally, yes, when used for security and fraud prevention with clear notice, limited data and set retention. Some regimes, including EU ePrivacy rules, apply specific conditions, so check local requirements.
How do fraudsters bypass device fingerprinting?
They use emulators, device masking tools, anti-detect browsers, frequent factory resets and cloned apps. Detecting those tools directly is more effective than relying on the fingerprint alone.
Device Fingerprinting Tells You Who the Device Is, Not Whether to Trust It
Device fingerprinting remains one of the most useful fraud tools available. It links fake accounts, recognises returning attackers and gives every session a history. Yet on its own, it is a memory, not a judgement.
However, the attacks that cost the most today target that gap. They arrive on clean-looking devices, recycled phones or emulators built to look new. So treat the fingerprint as the foundation, then add the risk signals that show what the device is doing right now. That combination turns a device ID into a decision.
Want to see which risk signals your current fingerprinting misses? Talk to Verihubs about device risk checks for your app.
and experience faster,
smarter verification with us