All posts

Multi-account

Browser profile isolation: what it separates and what it doesn’t

Chrome profiles keep cookies apart but share one fingerprint and one IP. The full isolation checklist for accounts that must never be linked.

By Mango TeamPublished 5 min read

"Isolated" is a word that gets used for very different amounts of separation. A second Chrome profile is isolated. A Firefox container is isolated. A private window is isolated for an hour. A separate computer on a separate connection is isolated. Only the last one is isolated in every way a website can measure, and it is the one nobody wants to pay for. This guide lays out the three layers a site uses to recognise a browser, shows which tools separate which layer, and ends with the checklist for accounts that must never be linked.

The three layers of a browser identity

LayerWhat is in itHow a site reads itSurvives clearing cookies?
StorageCookies, local storage, IndexedDB, cache, service workers, saved loginsSent back on every request, read by scriptsNo, that is what clearing does
FingerprintUser-Agent, Client Hints, screen, cores, GPU, Canvas, fonts, audio, timezone, languageRead by scripts on the first page loadYes
NetworkHTTP IP, WebRTC candidates, IP-derived locationSeen by the server, gathered by scriptsYes

A site does not need all three to connect two accounts. Two accounts with different cookies, on the same fingerprint, from the same IP, are one person with two logins. The layers are cross-checked against each other too: a fingerprint that says macOS with a font list from Windows, or a timezone that does not fit the IP, is a modified browser rather than a second one.

What browser profiles separate

Chrome profiles (and the equivalent in other Chromium browsers) each get their own user data directory. That means separate cookies, storage, history, extensions, saved passwords and settings. For the storage layer, that is complete isolation, and it is permanent rather than per-session.

What they share is everything that comes from the machine and the program. Two profiles run the same binary on the same OS with the same GPU, the same fonts, the same screen, the same clock and the same network connection. Their fingerprints are identical, and so are their IPs. To a site, they are one browser with two cookie jars.

Firefox Multi-Account Containers work the same way at a finer grain: each container has its own cookies and storage inside one Firefox profile, so you can be logged into two accounts in two tabs. Fingerprint and network are shared across all containers, by design; containers were built to separate sites from each other, not to make one person look like two.

What proxies and VPNs separate

A proxy changes the network layer for the traffic that goes through it. Bound to one profile, it gives that profile its own exit. A VPN changes the network layer for the whole machine, which means every profile gets the same new exit, so it separates you from your home IP but not the profiles from each other.

Neither touches the fingerprint layer. And the network layer has its own consistency rule: the WebRTC candidate has to agree with the HTTP IP, and the timezone and language have to agree with both. The WebRTC guide covers the most common way that goes wrong.

What an antidetect browser separates

An antidetect browser separates all three layers per profile, and does one more thing that the other tools cannot: it makes each fingerprint internally consistent. A profile that claims Windows gets Windows fonts, a Windows GPU string and Windows Client Hints; a profile bound to a Singapore proxy gets a Singapore timezone and language. The separation is only useful if every profile also looks like a real, single browser, because an inconsistent fingerprint is flagged before it is ever compared to another one.

Different is not enough. Different and consistent is the target.

Two profiles need two fingerprints, and each fingerprint needs to describe one plausible machine. Randomising values on every page load gives you neither: the profile looks like a different device each visit, and a different device that is impossible.

The isolation checklist

For accounts that must never be linked, every item applies to every profile:

  1. Storage is separate and persistent. Own cookies, storage and cache, kept between sessions so the account looks like a returning user rather than a new device every day.
  2. The fingerprint is distinct. Canvas, WebGL, audio, fonts and hardware values differ from every other profile you run.
  3. The fingerprint is consistent. OS, fonts, GPU, Client Hints, navigator.platform and screen all describe the same kind of machine, and the browser version is current.
  4. The network is its own. One proxy per profile, WebRTC reporting the proxy's exit, IPv6 not leaking around it.
  5. Location signals agree. Timezone, language and geolocation match the exit IP.
  6. Behaviour stays inside the profile. Never log into account B from profile A "just once", never reuse a phone number, payment method or recovery email across profiles, and do not open both profiles on the same site at the same second from the same machine if the site checks for it.
  7. Extensions do not give it away. The same unusual extension set across profiles is a fingerprint of its own. Keep the list per profile and small.

How to test isolation

Open the Lab in each profile. Compare the fingerprint identifier, the Canvas and WebGL rows, the IP and WebRTC rows, and the timezone row. Every profile should get a different identifier, the same-machine rows should not be the same across profiles, and inside each profile the location rows should agree with each other. A pair of profiles that share any measured row share a link a site can use.

Compare two of your profiles

Run the Lab in each profile you use. Rows that match across profiles are links; rows that disagree inside one profile are flags.

Open the Lab

How Mango Browser handles isolation

Every Mango profile is a fully separate browser directory, so cookies, storage, cache and extensions never cross, and each profile keeps its data between sessions. Each profile has its own fingerprint built to be consistent with itself: Chrome/Chromium or Firefox on Windows or macOS, with the User-Agent, Client Hints, fonts, GPU renderer and platform following the chosen OS. Canvas, audio and client-rect noise are seeded per profile, so the values are unique across profiles and identical on every draw.

Network isolation is per profile too. Bind an HTTP, SOCKS5 or residential proxy to the profile; WebRTC reports the proxy's exit by default, and timezone, language and geolocation can follow it. Templates and batch creation apply the same consistency to many profiles at once, and team roles keep each person inside the profiles they are meant to use.

Sources

  1. Google Chrome Help: Share Chrome with others
  2. Mozilla Support: Multi-Account Containers
  3. MDN: Storage quotas and eviction criteria

See what your browser reveals in the Fingerprint Lab

Keep reading