Tor and a VPN together do not disable browser fingerprinting — they reduce it, but not to zero

Browser fingerprinting works by collecting dozens of small details about your device and browser: your screen resolution, installed fonts, timezone, language settings, browser version, and how your graphics card renders images. Tor and a VPN each hide some of these details, but they work in different ways and neither one erases them all. Using both together makes you harder to track than using either alone, but a determined tracker can still build a profile of you across visits.

The confusion comes from mixing up two different privacy problems. A VPN hides your IP address from websites. Tor does the same thing but also bounces your traffic through multiple servers so even the exit node does not know where you started. Browser fingerprinting ignores your IP address entirely — it looks at what your browser reveals about itself. That is why you can use Tor, use a VPN, or use both, and a website can still recognize you by your fingerprint alone.

Key Takeaways

  • Browser fingerprinting collects details about your device and browser settings, not your IP address, so hiding your IP does not stop it.
  • Tor randomizes some fingerprint details (like your apparent timezone) but keeps others stable so you can actually use the internet, which makes you recognizable.
  • A VPN does almost nothing to prevent fingerprinting because it only hides your IP address and does not change how your browser identifies itself.
  • Using Tor and a VPN together offers more protection than either alone, but you are still more fingerprintable than someone using a common browser with default settings.
  • The Tor Browser is designed to reduce fingerprinting more effectively than Tor alone, because it standardizes browser details across all users.

What browser fingerprinting actually collects

A fingerprinting script runs when you visit a website and reads dozens of properties from your browser without asking permission. It records your screen resolution, color depth, timezone, language, installed fonts, browser plugins, your graphics card's capabilities, and how fast your device can perform certain calculations. It also notes whether you have JavaScript enabled, whether you accept cookies, and how your browser handles certain web standards.

The script sends this data to a server, which creates a hash — a unique digital fingerprint. If you visit the same website weeks later, the script runs again, creates a new hash, and compares it to the old one. If they match, the server knows it is you, even if you have cleared your cookies, switched networks, or used a different device. Services like FingerprintJS and Cloudflare use this technique to recognize returning visitors and detect fraud.

How Tor changes your fingerprint

The Tor Browser (the official browser built to use Tor) deliberately standardizes many fingerprint details across all users. It sets your timezone to UTC, disables plugins, limits font information, and rounds your screen resolution to common sizes. This means your fingerprint looks similar to millions of other Tor users, which is the whole point — you blend in with the crowd.

However, Tor cannot standardize everything without breaking the internet. Your browser still needs to report some real information: which version of Tor Browser you are running, whether you have JavaScript enabled, and how your specific graphics card renders certain images. These details remain stable across your sessions, which means a fingerprinting script can still recognize you as the same person if you visit the same site multiple times. Tor makes you less unique, but not invisible.

Tor also has a second problem: if you customize your browser at all — change your zoom level, install an extension, or adjust your language settings — you when ready become more fingerprintable. The Tor Browser team warns against customization for exactly this reason.

Why a VPN does almost nothing for fingerprinting

A VPN hides your IP address and encrypts your traffic so your internet service provider cannot see which websites you visit. But it does not change how your browser identifies itself. When you visit a website through a VPN, the fingerprinting script still sees your screen resolution, your fonts, your timezone, your browser version, and your graphics card details. The only thing it does not see is your real IP address — which fingerprinting scripts do not need anyway.

Some VPN providers claim they reduce fingerprinting by randomizing your user agent (the string that identifies your browser type and version). In practice, this helps very little. A user agent is just one data point among dozens, and changing it actually makes you more fingerprintable because you become unusual. Most people do not randomize their user agent, so doing so makes you stand out.

What happens when you use Tor and a VPN together

Using both Tor and a VPN adds a layer of protection, but not in the way most people think. The combination does not disable fingerprinting — it just makes it slightly harder for someone to connect your fingerprint to your real identity.

If you use a VPN first, then connect to Tor, the Tor exit node sees your VPN's IP address instead of your real one. If you use Tor first, then a VPN, the VPN sees the Tor exit node's IP address. Either way, someone watching your traffic cannot easily trace it back to you. But the fingerprinting script still sees the same browser details it always did. Your fingerprint remains recognizable to any website that has seen it before.

The real benefit is that Tor and a VPN together make it harder for your internet service provider, your VPN provider, and the Tor network to build a complete picture of your browsing. But that is a different problem from fingerprinting.

How to actually reduce your fingerprint

If you want to be harder to fingerprint, use the Tor Browser without customization. Do not install extensions, do not change your zoom level, do not adjust your language settings, and do not resize your window. The Tor Browser's strength is that it looks identical to millions of other Tor Browser users. The moment you make it unique, you lose that advantage.

If you cannot use Tor, use a common browser with default settings. Chrome and Firefox are so widespread that your fingerprint is less unique straightforward because millions of other people have the same one. Unusual browsers, old versions, and customized settings all make you more fingerprintable.

Disable JavaScript if you can, because fingerprinting scripts rely on it. This breaks some websites, but it is the single most effective fingerprinting defense. Use a browser extension like uBlock Origin or Privacy Badger to block fingerprinting scripts before they run. These extensions cannot stop all fingerprinting, but they stop the most common trackers.

When fingerprinting matters and when it does not

Fingerprinting is most useful to websites for detecting fraud and recognizing returning users. A bank might use it to notice if your account is suddenly accessed from an unusual device. An advertising network uses it to track you across sites and build a profile of your interests. A data broker uses it to connect your browsing history to your real identity.

Fingerprinting is less useful for identifying you if you are one of millions. If you use Tor Browser without customization, your fingerprint is shared with so many other people that it is nearly worthless for tracking. If you use a common browser with default settings, your fingerprint is common enough that a tracker needs other information (like your IP address or login data) to identify you with confidence.

Fingerprinting is most dangerous when combined with other data. A tracker who knows your IP address, your email address, and your browser fingerprint can be very confident they have identified you. A tracker who only has your fingerprint, with no other context, has much less power.

Frequently Asked Questions

Can I use a VPN inside Tor to get better fingerprinting protection?

No. Using a VPN inside Tor (connecting to Tor first, then to a VPN) does not reduce fingerprinting because the VPN only hides your IP address. Your browser still reports the same fingerprint details to any website you visit. The combination may help with other privacy goals, but fingerprinting is not one of them.

Does disabling JavaScript in Tor Browser stop fingerprinting completely?

Disabling JavaScript stops most fingerprinting scripts from running, but not all. Some websites use server-side fingerprinting, which collects information about your browser without running JavaScript. However, disabling JavaScript is still one of the most effective defenses available. The downside is that many websites will not work properly without it.

If I use Tor Browser, can a website still recognize me on repeat visits?

Yes, if the website uses fingerprinting. Your Tor Browser fingerprint is more common than a regular browser fingerprint, but it is not unique to you. A website that has seen your fingerprint before can recognize it again on your next visit, especially if you visit within a short time period or from the same Tor exit node.

Does using a bridge in Tor help with fingerprinting?

No. Tor bridges hide the fact that you are using Tor from your internet service provider, but they do not change your browser fingerprint. Bridges are useful for evading censorship, not for reducing fingerprinting.

What is the difference between Tor and Tor Browser?

Tor is the network that routes your traffic through multiple servers. Tor Browser is the official browser designed to use Tor safely and reduce fingerprinting. You can use Tor with other browsers, but they will not have the same fingerprinting protections because they do not standardize browser details the way Tor Browser does.