Verihubs Logo
Home Blog Device Fingerprinting: How It Works, Where It Fails
10 min read • ID Check • Published on October 5, 2026

Device Fingerprinting: How It Works, Where It Fails

Device Fingerprinting: How It Works, Where It Fails

Device fingerprinting builds an identifier for a phone or browser from its attributes, such as model, operating system, screen and network details, so a business can recognise the same device again. It helps link fake accounts and spot returning fraudsters. But emulators, spoofed specs and factory resets can break it, so fraud teams pair fingerprints with device risk signals.

What Device Fingerprinting Is

Put simply, device fingerprinting is a way to recognise a device without asking the user anything. First, the system collects a set of attributes from the phone or browser. Then it combines them and turns them into an identifier. Later, when the same device returns, the attributes produce the same, or a very similar, identifier.

Fraud teams use that identifier for three jobs. First, they spot one device behind many accounts, which points to fake signups or promo abuse. Second, they recognise a returning device that earlier cases tied to fraud. Third, they notice when a known customer suddenly logs in from an unfamiliar device, which can signal an account takeover.

A fingerprint is not a password or a hardware serial number. Instead, it is a best guess built from many small clues. That makes it useful, but also fragile in ways that matter, as later sections show.

Signals a Device Fingerprint Uses

Device fingerprint signals - hardware, operating system, software, rendering, network and app-scoped IDs

No single attribute identifies a device on its own. Instead, the strength comes from combining many attributes that vary between devices. However, the exact mix depends on whether the fingerprint runs in a browser or inside a mobile app.

Signal groupBrowser examplesMobile app examples
HardwareScreen size, colour depth, CPU cores, GPU detailsDevice model, manufacturer, screen, sensors present
Operating systemOS and version reported by the browserOS version, build number, security patch level
SoftwareBrowser version, fonts, plug-ins, languageApp version, install source, system settings
RenderingCanvas and WebGL drawing differencesRarely used in apps
NetworkIP address, time zoneIP address, carrier, Wi-Fi or mobile data
App-scoped IDsCookies and local storageInstall IDs and vendor IDs that reset on reinstall

Meanwhile, some identifiers that once made this easy are now off-limits. For example, Android 10 restricted ordinary apps from reading non-resettable IDs such as the IMEI. Apple removed app access to the device’s unique ID back in 2013. Since iOS 14.5 in 2021, apps also need permission to use the advertising ID for tracking. So modern fingerprints rely on combinations of softer signals rather than one fixed number.

How Stable a Fingerprint Is Across Resets and Updates

Device fingerprint stability - how app updates, OS updates, reinstalls, factory resets and network changes affect matching

In practice, a fingerprint has to balance two goals. It must be unique enough to tell devices apart, yet stable enough to recognise the same device next week. For example, push too far towards uniqueness, and a minor update creates a “new” device. Push too far towards stability, and different devices start to look alike.

EventTypical effect on a fingerprint
App or browser updateSmall change, so good systems still match the device
Operating system updateSeveral attributes change, so matching becomes probabilistic
App reinstall or cleared browser dataApp-scoped IDs reset, so hardware attributes carry the match
Factory resetMost software attributes reset, so the device may look brand new
Network changeIP and carrier change, but these are weak signals on their own

Good fingerprinting therefore uses fuzzy matching. Rather than demanding an exact match, it scores how similar a new fingerprint is to known ones. In practice, that keeps genuine customers recognisable through updates, while still flagging devices that change too much, too fast.

Where Device Fingerprinting Breaks: Emulators, Spoofed Specs and Factory Resets

Unfortunately, fraudsters know how fingerprints work, and they attack the weak points directly. These are the failure modes every fraud team should plan for.

Emulators and Virtual Devices

Emulators simulate an Android phone on a desktop computer. Because the attacker controls every reported attribute, they can create endless “new” devices from one machine. Without emulator detection, each one looks like a fresh customer.

Spoofed Device Specs

Device masking tools and anti-detect browsers report fake models, screen sizes and system details. With that spoofing, one real phone can pretend to be many different ones. A fingerprint built only from reported attributes cannot tell the difference.

Factory Resets

A factory reset wipes most software attributes. Fraud rings use resets to recycle a phone after a ban, so the next account appears to come from a new device. Of course, a single reset is normal, but a pattern of resets is a strong fraud signal.

Shared and Second-Hand Devices

Failure also runs the other way, however. Families share phones, and second-hand phones change owners. A naive rule that blocks “one device, several accounts” will reject genuine people. So fingerprint links should feed a risk score, not trigger automatic bans.

These failure modes explain why fraud teams treat a fingerprint as one input among several. For the wider toolkit, see how a fraud detection system combines device, identity and transaction signals.

How to Use Device Fingerprints in Fraud Rules

A fingerprint becomes valuable when you turn it into rules. These patterns work well as a starting point, and you can tune them with your own data.

  • Accounts per device. Flag a device that creates several accounts in a short window, but allow for households.
  • Devices per account. Watch accounts that hop between many devices, which often signals sharing or resale.
  • New device plus high value. When a known customer moves money from an unfamiliar device, ask for a step-up check.
  • Known bad devices. Link new signups to devices tied to past fraud, then route them to review.
  • Reset frequency. Treat repeated factory resets on one handset as a risk signal, especially after a ban.

Above all, score these patterns rather than blocking on any single one. That way, genuine customers rarely notice, while organised fraud rings stand out quickly.

Browser vs Mobile SDK Fingerprinting

Importantly, where the fingerprint runs changes what it can see. Browser scripts and mobile SDKs have very different access.

Browser fingerprintingMobile SDK fingerprinting
How it runsJavaScript on a web pageA library inside your app
Attributes availableLimited to what the browser exposesRicher hardware, OS and app details
StabilityLower, because privacy features block or randomise signalsHigher, within OS privacy limits
Tamper detectionWeak, since the attacker controls the browserStronger, because it can check for root, hooking and emulators
Best fitWeb signups and loginsMobile banking, e-wallets, delivery and gaming apps

For mobile-first businesses in Southeast Asia, the SDK route usually wins. After all, most customers use apps, and an SDK can check the device’s integrity as well as its identity.

Privacy Considerations for Device Fingerprinting

Because fingerprinting collects information from a user’s device, privacy rules apply. In the EU, regulators read the ePrivacy rules on accessing device information as covering fingerprinting techniques, according to European Data Protection Board guidelines adopted in 2024. Similarly, many Asian privacy laws treat device identifiers as personal data when they link to a person.

  • Be clear about purpose. Say in your privacy notice that you use device signals for security and fraud prevention.
  • Do not repurpose. Avoid using a fraud fingerprint for advertising or cross-site tracking.
  • Collect only what you need. Skip attributes that add privacy risk without improving fraud detection.
  • Set retention limits. Keep fingerprints only as long as the security purpose requires.
  • Check platform policies. App stores restrict certain identifiers, so confirm your SDK follows their rules.

This is general guidance rather than legal advice, so confirm requirements with counsel in each market you serve.

Device ID vs Device Risk: When a Fingerprint Is Not Enough

Ultimately, a fingerprint answers one question: have we seen this device before? It does not answer a second, often more important one: can we trust this device right now? For example, a known phone might run with root access today, host a cloned app, or share its screen with a scammer.

By contrast, device risk signals answer that second question. They look at the state of the device and the session, not just its identity. On the Verihubs Device Intelligence page, for example, the listed signals include:

  • Integrity: root or jailbreak, emulator, app hooking, debug mode, app tampering and cloned apps.
  • Disguise: device masking, virtual OS, secondary user profiles and suspicious factory resets.
  • Network and location: VPN, proxy and GPS spoofing.
  • Session context: active calls, screen sharing and auto clickers.
  • Usage patterns: one device shared across several user IDs, and tampered payloads in transit.

You need device risk, not just a device ID, when attackers can reuse clean-looking devices. That covers account takeover, scams that coach victims through transfers, and automated fraud from emulator farms. In those cases, the fingerprint says “known device”, while the risk signals say “do not trust it today”. Our checklist of fraud detection software features covers how to evaluate both.

Frequently Asked Questions About Device Fingerprinting

What is device fingerprinting?

Device fingerprinting is a technique that recognises a phone or browser by combining its attributes, such as model, operating system, screen and network details, into an identifier. It helps businesses spot returning devices without asking users for anything.

Is device fingerprinting accurate?

It is good at recognising devices that behave normally, but it weakens when attackers use emulators, spoofed specs or factory resets. Fuzzy matching and device risk signals make it far more reliable for fraud prevention.

Can someone change a device fingerprint?

Partly. Updates, reinstalls and factory resets change many attributes, and spoofing tools can fake them. Well-designed systems still link many of these changes back to the same device and flag suspicious patterns of change.

What is the difference between browser and mobile fingerprinting?

Browser fingerprinting runs as a script and sees only what the browser exposes. Mobile SDK fingerprinting runs inside the app, sees richer device details and can check for tampering such as root access or emulators.

Generally, yes, when used for security and fraud prevention with clear notice, limited data and set retention. Some regimes, including EU ePrivacy rules, apply specific conditions, so check local requirements.

How do fraudsters bypass device fingerprinting?

They use emulators, device masking tools, anti-detect browsers, frequent factory resets and cloned apps. Detecting those tools directly is more effective than relying on the fingerprint alone.

Device Fingerprinting Tells You Who the Device Is, Not Whether to Trust It

Device fingerprinting remains one of the most useful fraud tools available. It links fake accounts, recognises returning attackers and gives every session a history. Yet on its own, it is a memory, not a judgement.

However, the attacks that cost the most today target that gap. They arrive on clean-looking devices, recycled phones or emulators built to look new. So treat the fingerprint as the foundation, then add the risk signals that show what the device is doing right now. That combination turns a device ID into a decision.

Want to see which risk signals your current fingerprinting misses? Talk to Verihubs about device risk checks for your app.

Client Verihubs
Trusted by 400+ clients and experience faster, smarter verification with us
Get FREE Trial
View Blog