Firefox resistFingerprinting announces itself when enabled
Check id firefox-resist-fingerprinting-identifiable
What an ordinary browser yields
Informational only, never scored. Reports whether resistFingerprinting is on.
What a detector infers
Firefox's privacy.resistFingerprinting substitutes CONSTANTS rather than randomness, and a constant is itself a fingerprint. Measured on Firefox 151: the WebGL renderer becomes the literal string "Mozilla" instead of a GPU, the timezone becomes Atlantic/Reykjavik (UTC+0 with no DST, so there is no seasonal tell), screen, avail and outer all collapse to the inner window size, hardwareConcurrency drops from 16 to 4, devicePixelRatio goes from 1 to 2, and plugins/mimeTypes/pdfViewerEnabled flip from 0/0/false to 5/2/true. RFP also fires around a dozen farbling rows in this audit because it genuinely perturbs canvas, WebGL readback and shader precision. Those rows stay scored - an anti-bot sees exactly what this audit sees, and telling a Tor Browser user they look coherent would be false. This row exists to supply the CAUSE, so a page of contradictions is not misread as evidence that something is deceiving the user when the honest answer is that they enabled a Mozilla privacy feature. It is keyed on the WebGL renderer string rather than the timezone, because Atlantic/Reykjavik at a zero offset is the genuine answer for anyone actually in Iceland. fingerprintingProtection, the modern ETP-strict default, is deliberately not matched: it was measured changing almost nothing and failing only two rows.
How to resolve it
Nothing to fix. If the farbling rows are failing and this row reports resistFingerprinting on, that setting is the cause rather than anything deceptive.
Other checks in Capability surfaces
- the device-API family is present or absent as a unit
device-api-family-coherenceWeb Bluetooth, WebUSB, WebSerial and WebHID are one family on Chromium desktop - the same secure-context gating, the same desktop platforms… - the CSS feature surface is identical in a fresh realm
css-surface-vs-realmWhich CSS properties, values and selectors an engine understands is decided when the browser is compiled. - device-level media features are identical in a fresh realm
media-surface-vs-realmMedia features are answered by the layout engine rather than by the JavaScript properties that describe the same machine, which is what… - the codec matrix is identical in a fresh realm
codec-surface-vs-realmcanPlayType answers come from the media stack compiled into the browser, and the shape of that matrix is genuinely informative: branded… - supported <input> types are identical in a fresh realm
input-surface-vs-realmAssigning an unrecognised type to an <input> element does not throw — the element silently falls back to reporting type "text". - emoji advance widths are identical in a fresh realm
emoji-surface-vs-realmEmoji do not render from the page's fonts but from a platform font supplied by the operating system — Segoe UI Emoji on Windows, Apple Color… - the Web Animations surface is identical in a fresh realm
animation-surface-vs-realmThe Web Animations API exposes a small, precisely specified surface: whether Element.animate exists, whether the timeline and KeyframeEffect… - the platform theme resolves the CSS system colours coherently
system-colors-vs-platformThe CSS system-colour keywords — Highlight, HighlightText, Canvas, CanvasText, ButtonFace, ButtonText, GrayText and their newer siblings…
Clearcote is a browser built for fingerprint coherence
It is a Chromium fork, maintained by the same people who wrote this reference. It ships as a compiled browser rather than as a stealth script injected into someone else's — which is a description of how it is built, and is not an argument about how it behaves on this check.
This audit takes no position on how Clearcote scores on Capability surfaces checks, on this one, or anywhere else. It has no baseline corpus of other people's fingerprints to rank you against and no vendor scoreboard — nearly every check is self-referential, asking one browser the same question through two independent APIs and reporting whether both answers can be true at once. It runs identically on any browser, including ours. Run it on yours and read the result yourself.
See the other checks in Capability surfaces — the family firefox-resist-fingerprinting-identifiable belongs to.