All posts

Privacy & fingerprinting

Does Incognito mode change your browser fingerprint?

Short answer: no. Incognito drops cookies, not your fingerprint. Exactly what it hides, what it leaves exposed, and what actually separates two identities.

By Mango TeamPublished 5 min read

Open an Incognito window, visit a fingerprint test, and compare the result with your normal window. The hash is the same. The GPU is the same, the fonts are the same, the screen, the timezone and the IP are the same. Incognito changes what your browser remembers; it does not change what your browser is. Here is the exact line between the two, and what that means if you use private windows to keep accounts apart.

What Incognito actually does

Chrome's own description is precise: a private window does not save your browsing history, cookies and site data, or information entered in forms, and it drops the cookies and site data it collected when you close the last private window. Extensions are off unless you allow them. Downloads and bookmarks are kept.

That is a statement about storage. Inside the private window the site can still set cookies and use local storage; they just live in a temporary jar that is emptied at the end. During the session a site sees a fresh visitor with no history. After the session, the jar is gone. Nothing in that list touches the signals a fingerprint is built from.

What it leaves exactly the same

SignalIn a normal windowIn IncognitoWhy
User-Agent and Client HintsChrome 152 on macOSChrome 152 on macOSSame binary, same OS
Screen, cores, memory2560×1440, 10, 8 GBSameSame hardware
Canvas and WebGLHash A, Apple M2Hash A, Apple M2Same GPU, driver and renderer
FontsYour installed setSameRead from the OS
Timezone and languageAsia/Shanghai, zh-CNSameRead from the OS
IP and WebRTCYour connectionSameSame network path
Cookies and storagePersistentTemporaryThe only difference

Every row except the last is identical. The Lab will give you the same fingerprint identifier in both windows, because the identifier is built from the rows that do not change.

The part that does change, and why it does not help

Incognito is not invisible. Sites have spent years finding ways to tell that a window is private, because publishers with metered paywalls wanted to stop readers from resetting their free-article counter. The techniques change (an early one based on the file-system API was closed in Chrome 76, and others based on storage quotas followed), but the pattern is stable: private windows behave slightly differently from normal ones in ways scripts can measure.

So the one thing Incognito does change is a flag that says "this person opened a private window". Combined with an unchanged fingerprint and an unchanged IP, that is not a new identity. It is the same identity, now marked as trying to look like a new one.

A fresh cookie jar is not a fresh visitor.

A site that keeps a fingerprint-based record recognises the private window as the same browser the moment it loads. The empty cookie jar tells it only that you cleared, or never kept, its cookie.

A two-minute experiment

  1. Open the Lab in a normal window and note the fingerprint identifier and the Canvas hash.
  2. Open a private window and load the Lab again.
  3. Compare. The identifier, the Canvas and WebGL rows, the fonts and the network rows will match.
  4. Now clear cookies in the normal window and reload. The identifier still matches, because none of its inputs were cookies.

See your fingerprint with and without Incognito

Run the Lab in both windows. The rows that match are the ones a site uses to recognise you regardless of cookies.

Open the Lab

So what does separate two identities?

Three things have to be different at the same time, and Incognito gives you one of them for the length of a session:

  1. Storage. Cookies, local storage, IndexedDB, cache and service workers. Incognito isolates these temporarily; a separate browser profile isolates them permanently.
  2. Fingerprint. User-Agent, Client Hints, screen, GPU, Canvas, fonts, timezone, language. Incognito changes none of them. A second identity needs a second, internally consistent set.
  3. Network. IP and WebRTC. Incognito changes neither. A second identity needs its own exit, with WebRTC agreeing with it.

Two accounts that share any of the three are linkable. Two accounts that share all three, with one of them in a private window, are the same account with a flag on it. The full checklist is in Browser profile isolation.

When Incognito is the right tool

It is a good tool for what it was built for: borrowing a computer, checking a price without personalisation, logging into a second account for five minutes on your own machine, or keeping a search out of your history. For those, the temporary jar is exactly what you want and the unchanged fingerprint does not matter.

It is the wrong tool for running accounts that must never be connected, for the simple reason above: every signal a risk system uses to connect them stays the same.

How Mango Browser handles this

Mango starts where Incognito stops. Every profile is a fully separate browser directory, so cookies, storage, cache and extensions never cross between profiles, and they persist between sessions instead of vanishing when you close a window. Each profile also carries its own fingerprint: a Canvas seed that is unique to the profile yet identical on every draw, a WebGL renderer from a pool of real GPUs for the profile's operating system, a font list from that OS, and User-Agent and Client Hints that describe one coherent browser.

Bind a proxy to the profile and the network story follows: the HTTP IP, the WebRTC candidate, the timezone and the language all describe the exit. Open the Lab inside two Mango profiles and you get two different identifiers, which is the result that Incognito can never give you.

Sources

  1. Google Chrome Help: How private browsing works in Chrome
  2. Google Chrome Help: Browse in private
  3. MDN: Canvas API

See what your browser reveals in the Fingerprint Lab

Keep reading