You opened Tor Browser, connected to a relay, and felt anonymous. Then you checked your fingerprint on a testing site and saw a unique hash. That’s the moment most users realize Tor alone doesn’t hide everything.
Your browser fingerprint can still include resolution, timezone, installed fonts, and WebGL data that differ from the Tor default. If any of those values leak, you’re trackable across sessions—even while using Tor.
This checklist takes under ten minutes. Run it every time you update Tor Browser or change any privacy setting.
Step 1: Confirm You’re Using Tor Browser, Not a Modified Fork
Only the official Tor Browser from torproject.org includes the fingerprinting defenses you need. Using a generic Firefox build with a proxy setting or a “Tor-enabled” Chrome fork breaks those protections.
Open Help → About Tor Browser. The version number should match the latest release. If you see an unfamiliar build name, reinstall from the official source.
Step 2: Verify Your Browser Window Size Is a Standard Resolution
Tor Browser defaults to a 1000×900 or 1000×1000 window. If you resized it, your window dimensions become a unique identifier.
Open a new window and check its size using the browser’s developer tools or a fingerprint test site. If the width or height differs from the standard Tor values, reset it via Window → Reset Window Size.
Step 3: Check That WebRTC Is Completely Disabled
WebRTC can leak your real IP address even when you’re connected to Tor. Tor Browser disables WebRTC by default, but some extensions or config changes can re-enable it.
Search about:config and look for media.peerconnection.enabled. It must be set to false. If it’s true, toggle it immediately and restart the browser.
Step 4: Confirm Canvas and WebGL Spoofing Is Active
Canvas fingerprinting draws an invisible image and generates a unique hash based on your GPU and rendering engine. Tor Browser adds noise to canvas reads, but you should verify this is working.
Visit a canvas fingerprint test page. The hash should change slightly each time you load the page. If you see the same hash twice, your canvas spoofing is broken.
Also check about:config for privacy.resistFingerprinting. It must be true.
Step 5: Test for Timezone, Language, and Keyboard Leaks
Your real timezone, language preference, and keyboard layout are strong identity markers. Tor Browser spoofs these to match the exit node’s region, but misconfigurations happen.
Check your timezone in the browser’s JavaScript console: Intl.DateTimeFormat().resolvedOptions().timeZone. It should not match your physical location.
Also test your language settings. If you see your native language listed first, Tor’s spoofing might not be active.
Step 6: Verify That JavaScript Is Not Exposing Your Real Data
Even with fingerprinting resistance enabled, some JavaScript calls can still leak screen resolution, color depth, or installed plugins.
Use a browser fingerprint test site that shows raw JavaScript values. Compare what the site reports to what you expect from a clean Tor setup. If you see your real screen resolution or a long list of plugins, disable JavaScript globally for that session.
Step 7: Run a Live Fingerprint Test and Compare Results Across Two Sessions
Open a new identity in Tor Browser (Ctrl+Shift+U) and visit the same fingerprint test site. The fingerprint hash should be completely different. If it’s similar or identical, your browser is leaking persistent data.
Repeat this test with a third identity. All three hashes must differ. If they don’t, your browser fingerprint isolation is failing.
Common Mistakes That Break Your Tor Fingerprint
- Installing extensions: Any add-on changes your fingerprint. Tor Browser blocks extensions by default for a reason.
- Maximizing the window: This sets unique dimensions that identify you across sessions.
- Using a regular browser over Tor: This is the most common error. Chrome over Tor leaks WebRTC, DNS, and resolution data. You need the official Tor Browser.
- Changing
about:configsettings without understanding them: Disablingprivacy.resistFingerprintingor enabling WebRTC breaks your entire fingerprint protection.
Mini Scenario: The Researcher Who Used a Tor-Enabled Chrome Extension
A researcher needed to access a .onion site for a security audit. They installed a “Tor proxy” extension in Chrome, connected to the relay, and started working. Their browser fingerprint included their real screen resolution, installed fonts, and a unique WebGL hash. The site they visited logged that fingerprint. Two days later, they accessed a different site using the same Chrome profile—and the site linked both visits to the same person.
The fix was simple: switch to the official Tor Browser and run this checklist before the next session.
For users who need to manage multiple isolated sessions without relying on Tor’s single-identity model, an anti-detect browser provides separate profiles with independent fingerprints. Our pick for anti-detect browser workflows is a solution that allows you to configure timezone, language, and WebGL per profile.
FAQ
Q: What should I check first when comparing browser fingerprint tor checklist?
A: Start with the real use case, pricing, setup difficulty, limits, support quality, and whether the option matches your workflow instead of choosing only by brand name.
Q: Is browser fingerprint tor checklist enough on its own?
A: Usually no. It should be evaluated together with your process, budget, risk level, and the other tools or accounts involved in the workflow.
Q: How do I avoid choosing the wrong option?
A: Use a short checklist, test on a small use case first, read the refund policy, and avoid tools or services that make unrealistic promises.
