Reading what a data broker script would make of you…
Open any site and it helps itself to almost everything listed further down this page, in the seconds before the page even appears. Nothing asks first, and there is no we value your privacy box to close on the way in.
Taken one at a time the readings are boring: a screen that is this wide, a processor with that many cores, a clock set to some time zone. None of them means anything on its own. Stack them up and you have a fingerprint in the literal sense, distinctive enough to pick your browser out of a crowd of millions and recognise it again on the next site, and the one after that, with no cookie to clear and no account to sign out of.
This is not an edge case that keeps researchers up at night, it is a large part of how the web pays for itself. Ad networks use the fingerprint to follow you between sites, data brokers stitch those trails together and sell the result to advertisers, insurers, campaigns and anyone else with a card on file, and a few retailers use it to decide you look comfortable enough to be quoted a higher price.
Most of the habits people rely on barely touch it. Clearing cookies does nothing, since no cookie is involved. A private window forgets your history, not your fingerprint. A VPN changes your IP address and your apparent city, which is genuinely worth doing, and leaves the other forty-odd signals exactly where they were.
There is even a cruel joke built in: pile on enough privacy extensions and flip enough settings and you become the only person on earth with that exact loadout, which is easier to spot, not harder. Fingerprinting rewards looking painfully average.
The word on offer for all of this is anonymous. Strictly true, in that your name is not stapled to the file, but a profile that reliably lands on one actual human does not need a name to choose your ads, set your price, or tell a background-check company what to make of you.
SNITCH does exactly one thing: it runs the same reads a tracker would run and shows you the results instead of shipping them somewhere. Nothing is uploaded, nothing is stored, and there is no analytics quietly watching you read about analytics. Consider it the itemised receipt every other site forgets to hand you on the way out.
Your browser is the fingerprint. Swapping it for one built to blend in beats every setting, extension and good intention further down this list.
Tor Browser is the gold standard: everyone running it is engineered to look identical, so you vanish into the crowd instead of standing in front of it. Rent paid: speed, the occasional site that treats Tor traffic like a masked stranger, and a window that will not maximise (that part is deliberate). torproject.org
Mullvad Browser is Tor Browser's anti-fingerprinting work without the onion network. Run it behind a VPN, or bare, when you want the disguise but not the latency. mullvad.net/browser
Brave is the gentle option: it randomises your canvas and audio readings per site by default and leaves your extensions, bookmarks and muscle memory intact. Less airtight than Tor, far ahead of stock Chrome.
Plain Firefox can be talked into it. Flip privacy.resistFingerprinting, or adopt the Arkenfox user.js, and it starts reporting a common screen size, a rounded clock and a fake canvas. Expect a letterboxed window and every site in light mode until you make peace with it.
What not to do: bolt three privacy extensions onto Chrome and call it a day. You become the one person online running Chrome with that exact stack, which is the opposite of hiding.
An ad blocker that only hides banners still lets the tracking script run. You want the one that stops the script from loading at all.
uBlock Origin, default settings, on every browser that still allows it. Free, light, and it blocks most trackers before they get a single read. That is the whole recommendation; the rest is footnotes.
Leave the filter lists roughly as shipped. Adding one or two (EasyPrivacy is already on; "Fanboy's Annoyances" is a reasonable extra) is fine. Enabling all of them mostly buys you broken pages.
Accept no substitutes: not uBlock Origin "Lite", not the app called "AdBlock", and definitely not Adblock Plus with "Acceptable Ads", which is a paid allowlist in a trenchcoat.
On iPhone, where Apple bans real extensions, a content blocker such as AdGuard is the runner-up prize.
WebRTC can hand a website your real local and public IP while your VPN sits there looking competent. Shut it: in Firefox set media.peerconnection.enabled to false; in uBlock Origin, tick Prevent WebRTC from leaking local IP; on Chrome or Brave, an extension like uBO does the same job.
Permissions: set location, camera, microphone and notifications to "ask" or "block" by default, and grant them per site when you actually mean to. A page that genuinely needs your microphone can manage a prompt.
The obscure sensors (motion and orientation, ambient light, the connected-gamepad list) are niche reads, but there is no reason to leave them on if your browser lets you say no.
A VPN rewrites your IP address and the city it points at. That is real and useful: it blinds your ISP, frustrates coarse geolocation, and covers you on hostile Wi-Fi.
It does nothing for your canvas hash, font list, screen geometry, GPU string or timezone. Those ride with the browser, not the connection, and they are most of what identifies you above.
Worse, a mismatched VPN is its own signal. "IP in Frankfurt, system clock in Toronto, language set to Canadian English" is a more memorable visitor than any one of those alone.
Pick a provider whose business model is your subscription, not your traffic logs. If it is free, the money is coming from somewhere, and it is you.
Fingerprinting rewards looking boring. Eleven privacy add-ons, a hand-picked font stack and a page of flipped flags combine into a setup exactly one human has, and now they can just watch for it.
Pick a lane. Either commit to a browser built for this (Tor, Mullvad) and inherit the crowd's disguise, or keep a mainstream browser close to stock with uBlock Origin on top. The worst spot is the miserable middle: a half-hardened Chrome with a user-agent spoofer and a canvas blocker reporting physically impossible values, which is the single most identifiable state on offer.
Spoofers that lie inconsistently (a phone user-agent on a 2560-pixel screen, a canvas that returns a fresh answer every call) get you filed under "actively evading", which is a sticky label of its own.
Run one browser (or a dedicated Firefox container or profile) for signed-in life such as bank, email and work, and a locked-down separate one for everything else.
The two get fingerprinted as two different people. The tracker that follows your idle browsing never gets to staple it to the profile with your real name on it.
Firefox Multi-Account Containers, or just separate browser profiles anywhere, take one click to set up and break most cross-site cookie joins at no further cost.
Locked-down mobile OSes mean few or no real browser extensions, so nothing on a phone quite matches desktop Firefox with uBlock Origin.
Android: Firefox supports uBlock Origin and a slice of about:config, which makes it the closest thing to a hardened phone browser. There is also a mobile Tor Browser for the committed.
iPhone: every browser is Safari underneath. The realistic ceiling is a content blocker (AdGuard, 1Blocker) plus Safari's own "Prevent Cross-Site Tracking" left on.
Apps are a separate and larger problem. This page only speaks for the browser.
This page is built for education, authorized testing, and CTF/research; aiming it at a system you don't own or don't have explicit permission to test could be illegal. Use it accordingly.
No backend also means no data collection, no storage, no transmission, not because of a policy somewhere promising it, but because the infrastructure to do any of that just doesn't exist.