Skip to content
All fingerprint checks
Render & GPU

drawing the same scene twice produces the same pixels

Pim· Clearcote Research 2 min readCheck id canvas-repeat-render-determinism

The same scene drawn several times into one context reads back byte-identical every time. Brave's stock farbling makes it differ and is declined rather than scored.

What a detector infers

Canvas noise is usually reasoned about as a trade: give up a stable hash, gain an unlinkable one. A deployed commercial collector shows why that trade can be a loss. Its canvas collector renders its text pass TWICE into the same context and compares the two readbacks; when they differ it discards the value entirely and reports the literal string 'unstable'.

So a build that reseeds its perturbation on every call does not hand that collector a new fingerprint — it hands it a much rarer one, because 'cannot draw the same thing twice' describes a far smaller population than any particular canvas hash does.

The other half of the argument is what the noise was bought for, and measurement on the same vendor's identity matcher answers it: changing BOTH canvas digests on an otherwise-unchanged device moved the confidence score from 0.99 to about 0.97 and did not mint a new visitor at all. A signal that costs a unique tell and buys 0.02 of confidence is not worth paying for.

This row is the temporal counterpart to canvas-subrect-consistency: that one renders once and compares a windowed read against the full read, which catches noise indexed by offset inside the returned buffer; this one renders repeatedly and catches noise that reseeds between calls. A build can pass either and fail the other, which is why they are separate.

How to resolve it

Seed canvas noise per session, not per call: the same input should give the same output for the lifetime of the page. Per-call reseeding does not produce a new identity on a real matcher, and it produces a tell that no ordinary browser produces.

What is canvas fingerprinting?

Nearby checks in Render & GPU

See all 46 checks in Render & GPU
Who builds this test

Clearcote is a browser built for fingerprint coherence

It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.

This audit takes no position on how Clearcote scores on Render & GPU checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.

See the other checks in Render & GPU — the family canvas-repeat-render-determinism belongs to.