# Brave removes strict fingerprinting protection

**URL:** https://discuss.privacyguides.net/t/brave-removes-strict-fingerprinting-protection/16302
**Category:** General
**Tags:** browsers, article
**Created:** 2024-01-18T17:46:23Z
**Posts:** 46

## Post 1 by @anon39816623 — 2024-01-18T17:46:23Z

What do you all think about this?

> **[Brave browser simplifies its fingerprinting protections | Brave](https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/)**
>
> With desktop and Android version 1.64 in a couple of months, Brave will sunset Strict fingerprinting protection mode.

---

## Post 2 by @anon21666177 — 2024-01-18T18:07:56Z

> Fewer than 0.5% of Brave users are using Strict fingerprinting protection mode, based on our [privacy-preserving telemetry](https://github.com/brave/brave-browser/wiki/P3A) data.

The telemetry is opt out so most people using strict mode are likely not being counted there.

---

## Post 4 by @Reset0609 — 2024-01-18T18:42:56Z

> [@anon21666177](#):
>
> The telemetry is opt out so most people using strict mode are likely not being counted there.

I use it and I can count with one hand the websites that gave me trouble over the span of several years

---

## Post 5 by @davidcollini — 2024-01-18T21:47:43Z

Here’s the pull request for more context  
[https://github.com/brave/brave-browser/issues/31229](https://github.com/brave/brave-browser/issues/31229)

---

## Post 6 by @xe3 — 2024-01-18T21:55:50Z

> [@anon21666177](#):
>
> The telemetry is opt out so most people using strict mode are likely not being counted there.

This was my thought as well, obviously people who go out of their way to use enhanced privacy settings will also be less likely to leave telemetry enabled.

BUT even if that wasn’t the case. Brave claims over 50 million users, meaning that 0.5% would still be _ ~~half~~ a quarter million users using strict mode_ which is still a decent sized crowd to blend in with (quite possibly more than the entire active userbase of Mullvad Browser)

I don’t recall strict mode breaking websites in my experience.

In my opinion this is the reason Brave is discontinuing it, (the other stated reasons seem like just attempts to justify the decision):

> Maintaining Strict mode and debugging why some websites are broken on Brave takes our engineers’ time away from focusing on default privacy protections that can benefit all of our users.

---

## Post 7 by @xe3 — 2024-01-18T21:59:50Z

> [@davidcollini](#):
>
> Here’s the pull request for more context  
> [https://github.com/brave/brave-browser/issues/31229](https://github.com/brave/brave-browser/issues/31229)

I see you’ve been keeping up with that github issue for a few months now, I’m curious what your perspective is on this change?

---

## Post 8 by @Reset0609 — 2024-01-18T22:01:13Z

They already warn that it can break websites, perhaps they could simply stop dedicating resources to debug such issues

---

## Post 9 by @davidcollini — 2024-01-18T22:35:05Z

I’ve used Brave as my main browser with aggressive fingerprinting enabled for around 3 years and have only had issues on google docs and maybe two or three other sites. I’m of the opinion that many features of aggressive fingerprinting mode can be moved into normal fingerprinting mode, or made into their own toggles in shields, due to how few sites I’ve seen break from this feature.

Dark mode detection (makes sites think you’re using light mode) - should be made an option in shield settings since many users are confused by this feature or don’t like that it can’t be toggled on its own.

For navigator.useragent farbling, there may be multiple reasons why Brave doesn’t want to hide the user’s browser by default, but in my use case, I haven’t seen many reasons why this would be the case, so I’m of the opinion that this feature could be slowly implemented into default fingerprinting protection.

For WebGl fingerprinting, I would love to see this implemented by default, but I understand that it may lead to site breakage. Especially for browser games and sites heavily reliant on WebGl, it’s hard to not break sites while maintaining privacy.

Overall, I’m happy with how they handled this, I’m a big fan of Brave’s goal of making users all have a similar fingerprint, so this inches us closer to that goal. Also I was happy with their blog post and their outlook on focusing resources towards a single option and having that as the default. The main result that I see coming from this is more privacy protections enabled by default, and more privacy options that can be toggled by users.

---

## Post 10 by @davidcollini — 2024-01-18T22:41:36Z

Brave is actually working on automating fixing filter lists that cause site breakage, so that should fix your issue :wink: This is still very early in development and they haven’t revealed anything yet.

Full thread for context:  
[https://nitter.1d4.us/BrendanEich/status/1747457098697556140#m](https://nitter.1d4.us/BrendanEich/status/1747457098697556140#m)

---

## Post 11 by @redoomed1 — 2024-01-18T23:21:59Z

> [@anon21666177](#):
>
> most people using strict mode

read: most people who configure Brave using the PG recommendations :grin:

---

## Post 12 by @anon21489307 — 2024-01-18T23:42:51Z

> [@xe3](#):
>
> 50 million users, meaning that 0.5% would still be _half a million users_

It’s around 250 thousands, or 1/4 of a million.

---

## Post 13 by @xe3 — 2024-01-18T23:51:31Z

> > 50 million users, meaning that 0.5% would still be half a million users
> 
> It’s around 250 thousands, or 1/4 of a million.

Oops that’s embarassing… :smiley: You’re right.

(I’d say ‘math is hard’ but in this case the math was dead simple and I still got it wrong :roll_eyes: )

---

## Post 14 by @PoorPocketsMcNewHold — 2024-01-19T14:25:11Z

Hence why they disable a feature first before such “replacement” enter production builds, or is mature enough ?

---

## Post 16 by @davidcollini — 2024-01-19T15:35:21Z

Are you referring to them removing aggressive fingerprinting or their Star++ software? The two are correlated, but not directly linked.

---

## Post 17 by @wojciechxtx — 2024-01-19T17:55:32Z

> [@davidcollini](#):
>
> The two are correlated, but not directly linked.

Dare to explain?

---

## Post 18 by @davidcollini — 2024-01-19T18:12:08Z

@wojciechxtx The whole purpose of their research into their project with the Star++ protocol is to fix site breakage with their filter lists, and a big reason they listed for removing strict fingerprinting was because of site breakage. So a lot of resources go into fixing site breakage, and this research could potentially lead to advancements in fingerprinting protection with easier ways to fix broken sites that result from this better protection.

---

## Post 19 by @sha123 — 2024-01-19T21:18:29Z

> [@davidcollini](#):
>
> a big reason they listed for removing strict fingerprinting was because of site breakage

Which site breakage? I have used strict fingerprinting protection for a long time and almost never had a site break because of it. I can’t believe that this is a big problem in practice, especially since most users using strict protection should be knowledgeable enough to try the other protection levels to fix the problem for a website.

---

## Post 20 by @FlipSid — 2024-01-19T22:05:52Z

Same here with strict mode. Seldom problems.  
But I’m thinking more in direction Google Manifest V3

---

## Post 21 by @xe3 — 2024-01-20T00:23:58Z

> [@sha123](#):
>
> Which site breakages, I have used strict fingerprinting protection for a long time and almost never had a site break because of it

This seems to be the consensus among _everyone who actually uses_ strict fingerprinting protection, at least here on Privacy Guides, and on the Techlore forum.

Maybe we just have a higher tolerance for what we consider “breakages”, or maybe we are less likely to visit the sort of website that would be broken by strict fingerprinting protection. _OR_ Brave is just exxagerating the point since they made the decision to discontinue it and need to justify that decision to users. My guess is that there is a little bit of truth to each of these reasons.

---

## Post 22 by @anon21489307 — 2024-01-20T02:11:06Z

IMO, I agree with the reason to better maintain and improve the standard fingerprint blocking mode in Brave, which is already stricter than other browsers, and **it’s on by default** , so an average Joe who downloads and uses the browser as-is would be protected.

For example, on [https://coveryourtracks.eff.org/](https://coveryourtracks.eff.org/),

- I tested with Brave 1.61.120 (standard fingerprinting block), my result: you have strong protection against Web tracking. I have a _randomized_ fingerprint.
- But with Firefox 121.0 (standard fingerprinting block), my result: you have some protection against Web tracking, but it has some gaps. I have a _unique_ fingerprint.

Whether anyone who uses strict fingerprinting protection mode in any of the browsers ever experienced any site breakage on their end, it’s hard to tell whether that’s the case for other users, as our usage differs from one another. And by combining everyone’s problems together, that _could_ lead to a ton of issues.

I have never experienced an issue with fingerprinting blocking _yet_, but I always use the standard mode (default), so I can’t tell.

Nevertheless, it’s the _fact_ that strict fingerprint blocking in browsers _could_ break some sites, according to _both_ Brave and Firefox, as shown in their settings.

---

## Post 23 by @sha123 — 2024-01-20T07:24:42Z

> [@anon21489307](#):
>
> For example, on [https://coveryourtracks.eff.org/](https://coveryourtracks.eff.org/),

That’s not a good way at all to evaluate strict vs standard mode.

---

## Post 24 by @anon21489307 — 2024-01-20T07:28:41Z

> [@sha123](#):
>
> strict vs standard mode.

I didn’t test strict vs standard mode. I compared OOTB standard mode between 2 browsers, in which Brave did better than Firefox.

---

## Post 25 by @sha123 — 2024-01-20T07:50:18Z

> [@anon21489307](#):
>
> I didn’t test strict vs standard mode. I compared OOTB standard mode between 2 browsers, in which Brave did better than Firefox.

I see. But tbh it doesn’t matter, because it’s a flawed approach in general, no matter which browsers or modes you compare.

---

## Post 26 by @anon21489307 — 2024-01-20T08:14:37Z

> [@sha123](#):
>
> it’s a flawed approach in general, no matter which browsers or modes you compare.

Could you elaborate? Or if it doesn’t matter regardless, what is the point you want to say in this thread?

Also, I _didn’t_ say that any approach is perfect. However, there’s one browser that’s _objectively better_ than another browser in this particular aspect of privacy. This is simply the _fact_ that you can’t deny until it’s proven otherwise.

---

## Post 27 by @sha123 — 2024-01-20T08:24:12Z

> [@anon21489307](#):
>
> Could you elaborate?

- uses only old and easy methods for fingerprinting. Nothing new or even remotely advanced. If you add more advanced methods you will get partially very different results.
- reported statistical values are meaningless because the dataset is extremely skewed
- the dataset is way too small to be meaningful
- the whole approach has been flawed from the beginning
- coveryourtracks has done more damage than good by displaying seemingly easy to understand results, without warning people about the massive shortcomings, which leads users to using this tool to tweak or select their browsers to get a better result, which might actually worsen their security or privacy and wastes many people’s time to explain this stuff again and again on forums

---

## Post 28 by @sha123 — 2024-01-20T08:28:22Z

> [@anon21489307](#):
>
> However, there’s one browser that’s _objectively better_ than another browser in this particular aspect of privacy. This is simply the _fact_ that you can’t deny until it’s proven otherwise.

I would be a bit more cautious with such bold claims.

---

## Post 29 by @anon21489307 — 2024-01-20T08:47:22Z

Thanks for the explanation! However,

> [@sha123](#):
>
> uses only old and easy methods for fingerprinting. Nothing new or even remotely advanced.

If the methods they use are basically outdated, then, why does Firefox fall behind the others in this outdated/non-advanced tested? It would be totally understandable if every browser has the same result due to the outdated testing methods that are also probably well-known flaws that should be fixed/patched already. Does this mean that Firefox is totally out of their mind to let those flaws loose/unfixed?

> [@sha123](#):
>
> the dataset is extremely skewed

Which data set is extremely skewed? And which one they should use instead?

> [@sha123](#):
>
> the whole approach has been flawed

Could you care to elaborate? You keep saying that the test is flawed, but what flaw actually?

> [@sha123](#):
>
> coveryourtracks has done more damage than good by displaying seemingly easy to understand results,

Why displaying the easy-to-understand results is a con?

> [@sha123](#):
>
> without warning people about the massive shortcomings, which leads users to using this tool to tweak or select their browsers to get a better result

What are their shortcomings? Or are you trying to say that having a randomized fingerprint is worse than having a unique fingerprint, for example?

> [@sha123](#):
>
> wastes many people’s time to explain this stuff again and again on forums

If you think it’s a waste of your time, you don’t need to participate. Or, at least, you can link to a related thread if you believe that the test’s flaws had been explained on this forum many times already.

> [@sha123](#):
>
> I would be a bit more cautious with such bold claims.

I just posted my test result, also with the link ([https://coveryourtracks.eff.org/](https://coveryourtracks.eff.org/)) that anyone can use it to test for themselves whether it’s true. In fact, I didn’t claim anything to date, since the reason I think Brave is OOTB _objectively better_ than Firefox in this aspect is not based on my opinion.

On the contrary, you have such many unexplained claims, mostly, not on my point or missing my point entirely.

---

## Post 30 by @sha123 — 2024-01-20T09:18:31Z

> [@anon21489307](#):
>
> If the methods they use are basically outdated, then, why does Firefox fall behind the others in this outdated/non-advanced tested?

You simply can’t deduce that based on this website.

> [@anon21489307](#):
>
> Which data set is extremely skewed?

Its own dataset and all statistical values coming from it. Evaluating fingerprinting is a statistical problem.

> [@anon21489307](#):
>
> Why displaying the easy-to-understand results is a con?

Because it is not easy. It’s only _seemingly_ easy.

> [@anon21489307](#):
>
> What are their shortcomings?

I already explained them to you. But you neither seem to understand how fingerprinting works in general, nor individual methods, nor the statistical nature. And you know what? I have no problem with that. But if you make strong claims about it, I have a problem with it.

> [@anon21489307](#):
>
> On the contrary, you have such many unexplained claims, mostly, not on my point or missing my point entirely.

Lol, whatever. No point in arguing with people who lack even basic knowledge about a topic. I explained more than enough which you could make you understand if you did your own research (and I mean actual research, not visiting a few test websites), but I can’t explain to you a complicated topic and starting from zero. I don’t have the time to do so. This will get you started: [GitHub - prescience-data/dark-knowledge: 😈📚 A curated library of research papers and presentations for counter-detection and web privacy enthusiasts. · GitHub](https://github.com/prescience-data/dark-knowledge) .

Have a nice day.

---

## Post 31 by @anon21489307 — 2024-01-20T09:38:04Z

> [@sha123](#):
>
> You simply can’t deduce that based on this website.

I _didn’t_ deduce my question based on anything on that website. I deduced the question because _you accused the website’s methods_ to be outdated and non-advanced.

Now, if the methods on the website are simply too old and non-advanced, why does Firefox still fail the test?

> [@sha123](#):
>
> Its own dataset and all statistical values coming from it. Evaluating fingerprinting is a statistical problem.

Then, what’s your recommended test that’s not based on statistic?

> [@sha123](#):
>
> I already explained them[the test’s shortcomings] to you.

You had never explained anything. You explained that to me just now, that it’s a statistical problem. But never mind. However, you still didn’t explain about why having a randomized fingerprint is worse than having a unique fingerprint. I believe this is not related to statistic issues, as it’s just a simple math value (randomized value vs 1 unique value).

> [@sha123](#):
>
> if you make strong claims about it, I have a problem with it.

I _didn’t_ make any claim, as explained before that it’s not coming from my opinion, but from the tool which _you claimed_ that it’s not advanced enough and outdated.

> [@sha123](#):
>
> No point in arguing with people who lack even basic knowledge about a topic.

Why does assuming my knowledge related to this topic in any way? I believe this against the forum rule, as it is a personal attack, not a topic attack.

---

## Post 32 by @Sprout3425 — 2024-01-20T10:10:24Z

Let’s all keep it respectful.

---

## Post 33 by @FlipSid — 2024-01-20T16:55:52Z

Something to reflect upon:

> **[Browser Tracking | Madaidan's Insecurities](https://madaidans-insecurities.github.io/browser-tracking.html)**

I found the articel quite usefull, especially for me to not drift off in my perfectionism

---

## Post 34 by @anon21489307 — 2024-01-20T17:11:01Z

Agreed, it’s a very good article. Here’s the key point I get from the article:

> The only real approach to preventing browser tracking/fingerprinting is by using a browser that is designed to prevent this **by default** and the users do not change it.

Which means the strict mode probably wouldn’t matter much, and it’s better for the browser vendors to improve on their default settings. At least, this will not make some of their users stand out from the crowd.

---

## Post 35 by @anon80779245 — 2024-01-22T03:12:34Z

Just here to say that strict fingerprinting do cause some breakages. Quite low-key but some websites only have fingerprint based captchas so you have to put in on medium settings. The good thing is that Brave will remember this so you end up having your own list of websites with less protection which means after a few weeks websites breakage is minimum.

The new change doesn’t affect the aggressive tracker blocker right ?

---

## Post 36 by @anon21489307 — 2024-01-22T03:33:40Z

> [@anon80779245](#):
>
> The new change doesn’t affect the aggressive tracker blocker right ?

The only way to know is to check in the nightly release. But since it’s nightly, there could be some changes when it actually lands on beta and stable channel.

According to the news, I would assume the change will make the standard mode stricter than ever before, while retaining the website’s compatibility intact.

---

## Post 37 by @deadorbit — 2024-01-23T05:55:57Z

To be fair - if Brave ever wants to be a contender for mainstream browser they need to reduce the ability for every day users to break things. This means removing the amount of things newbies can play with. They should just do what uBlock does and hide these features behind a warning screen. `¯\_(ツ)_/¯`

---

## Post 38 by @xe3 — 2024-01-23T07:05:16Z

> [@deadorbit](#):
>
> They should just do what uBlock does and hide these features behind a warning screen.

Warnings, and setting expectations properly are good, but to enable the setting a user would literally need to click on the option called: `Strict , may break sites` so users can/should be reasonably expected to understand there is some risk. (and considering that Brave claims only 0.5% of users, use the strict mode, it appears it is an effective deterrent)

I do very much agree with you that uBO strikes a good balance between advanced features being included and supported, but in such a way that inexperienced users would have to go out of their way to find/enable them and won’t just stumble upon them.

Firefox is another good example of this. There is tons of advanced functionality built into Firefox but not exposed in settings.

I wish Brave would take this approach as opposed to just entirely removing the option of strict fingerprinting protection.

---

## Post 39 by @sha123 — 2024-01-23T10:50:30Z

> [@anon80779245](#):
>
> The new change doesn’t affect the aggressive tracker blocker right ?

The announcement sounds like it only affects strict fingerprinting option, but not ads and tracker blocking.

If Brave wanted to seriously tackle more advanced fingerprinting, they would need to massively cut down on fingerprintable settings, because there are way too many, and also improve mitigations. At best with one or two easy security/privacy sliders like on Tor/Mullvad browser. But removing mitigations like by removing the strict option is not a good step.

---

## Post 40 by @pika — 2024-01-23T11:59:04Z

> 1. In order to block fingerprintable APIs, Strict mode frequently causes certain websites to function incorrectly or not at all. This website breakage means that Strict mode has limited utility for most Web users.

And disabling javascript in settings also breaks websites ,so now brave should remove javascript option as well right ? :confused:

> 1. Fewer than 0.5% of Brave users are using Strict fingerprinting protection mode, based on our privacy-preserving telemetry data.

Like really ? how do you get this statistics when you have an opt-out toggle even for daily usage pings . We all have followed PG’s privacy settings for brave , so does that mean there is still some telemetry i can’t opt-out ? Such a questionable statement i would say.

Atleast they should stick to the valid reasons only for supporting their decision instead of giving made up reasons.

I hope that what Brave claims and other users in this forum say about defualts becoming stronger and “extensive” turns out to be true in reality and not on just paper.  
Or else i may have to make major changes in my browser habits now unless i regain trust in Brave.  
Would be interesting to know what PG makes of this move as ?

---

## Post 41 by @redoomed1 — 2024-01-23T23:52:35Z

To add on to what @anon80779245 shared, I also recently encountered a breakage that was fixed by downgrading the Block Fingerprinting setting from ‘Strict’ to the default: Google Docs. The strict setting botches the text alignment and messes with how the cursor displays after clicking anywhere in a document.

* * *

EDIT  
I encountered another breakage: [FluffyChat](https://fluffychat.im/web) does not load properly under Strict Fingerprinting Blocking, and Brave prompts you to wait or kill the page. Fixed with the same method as the one I mentioned for Google Docs.

---

## Post 42 by @davidcollini — 2024-01-28T19:36:53Z

Here’s an update on the removal of Strict fingerprinting

[https://github.com/brave/brave-browser/issues/31229#issuecomment-1913689548](https://github.com/brave/brave-browser/issues/31229#issuecomment-1913689548)

---

## Post 43 by @sha123 — 2024-01-28T20:22:23Z

What a meme issue. They have a zillion unnecessary settings (some of which are detectable), but remove an actually useful privacy feature, with the justification that there are too many settings.

---

## Post 44 by @anon21666177 — 2024-01-28T20:48:50Z

Unfortunately, their business model relies on crypto you get for watching ads. They’d want to simplify the settings without making it too easy to disable all the crypto/web3 settings.

---

## Post 45 by @pika — 2024-01-29T05:56:36Z

They literally added a dedicated menu of “content filtering” in settings with countless toggles for ad filtering.

And still want us to believe that strict fingerprinting is being removed coz too many options will make users standout. What a joke !

---

## Post 46 by @dngray — 2024-01-29T07:49:21Z

> [@pika](#):
>
> too many options will make users standout

That is generally how it works. The more differences between browsers the easier it is to spot one in the crowd. Fingerprinting typically is the sum of all the measured metrics.
