Anti-detect browsers: what they are, what they're used for, and who legitimately needs one
Anti-detect browsers: what they are, what they're used for, and who legitimately needs one
Anti-detect browsers have a reputation problem. Search the term and you land in ad-farm and account-farming territory; ask a fraud analyst and they'll tell you the same software is a core threat vector. Both things are true – and neither tells you what the technology actually is. This piece covers the mechanics, the major products, the open-source alternatives, the legitimate use cases, and where the legal line sits in Australia.
This is general information, not legal advice.
What fingerprinting actually is
A browser fingerprint is a set of values your browser exposes to any site that runs JavaScript, combined into an identifier that can persist without cookies. The research basis is old and well established: the EFF's original Panopticlick study (Eckersley, 2010) showed most browsers were uniquely identifiable from configuration alone, and the AmIUnique project at INRIA replicated it at larger scale years later. The main signals:
| Signal | How it works | What drives uniqueness |
|---|---|---|
| Canvas | Render hidden text/graphics to a <canvas>, read back pixels. Sub-pixel rendering differs by GPU, driver, font stack, antialiasing. |
GPU + driver + OS + fonts |
| WebGL | Read GPU vendor/renderer strings, or render 3D scenes and hash the output. | Graphics hardware, driver |
| Fonts | Detect which fonts are installed (measure text widths, or document.fonts). |
Installed font list – wildly variable |
| AudioContext | Render audio through an offline context; output has hardware-level quirks. | Audio stack |
| Screen/UA/locale/timezone | navigator.userAgent, screen geometry, Intl defaults, Date timezone offset. |
Configuration, VPN mismatch |
| TLS/JA3 & JA4 | Not JavaScript at all – the server fingerprints the handshake itself (cipher-suite order, extensions) before any page loads. JA3/JA4 hashes this into a stable ID. | Browser/engine build – the hardest signal to fake |
The killer detail is the timezone/locale mismatch: connect from a VPN exit in Frankfurt while your browser reports Australia/Sydney and a UTC+11 clock offset, and you've told every anti-fraud system that your IP is a proxy. This is exactly the class of leak anti-detect browsers exist to fix – they pin the timezone, locale, geolocation API, and font stack of each profile to match its proxy, not your machine.
The two philosophies: blend in vs. change shape
There are two defences against fingerprinting, and they're opposites.
Uniformity – make everyone look identical. This is Tor Browser's approach and, by extension, Mullvad Browser (Tor Browser's Firefox base with the Tor network removed, built in collaboration with the Tor Project). If every user reports the same window size, same font list, same everything, your fingerprint is one of a million. The cost: you must not customise anything, and you stand out precisely because everyone else isn't uniform.
Randomisation/spoofing – change your values per session or per profile. Brave's "farbling" injects per-site deterministic noise into canvas, WebGL, and audio outputs so the hash differs by site and session. Chromium forks like Cromite and ungoogled-chromium ship Bromite's anti-fingerprinting patches (font mitigations, client-rect noise) behind flags.
Anti-detect browsers are the industrial version of spoofing: many simultaneous, fully isolated profiles, each with a consistent, realistic fingerprint (OS, GPU, fonts, timezone, locale, WebRTC) bound to its own proxy. They're built on Chromium (most products) or Firefox (Multilogin pioneered a Firefox-based engine), with deep patches that ordinary extensions can't reach – including, for some products, TLS-level consistency so the JA3/JA4 handshake matches the spoofed browser.
The main products
| Browser | Engine | Notable strengths | Considerations | Free tier |
|---|---|---|---|---|
| Multilogin | Chromium + proprietary Firefox (Mimic/Stealthfox) | Longest track record; deep, tested fingerprint consistency; "real device" fingerprint sources | Priciest tier; aimed at teams | No (trial) |
| GoLogin | Chromium (Orbita) | Cloud profiles accessible from any machine; generous free plan; broad proxy marketplace | Less granular control than top-tier | Yes |
| AdsPower | Chromium (SunBrowser) + Firefox (FlowerBrowser) | Strong automation/RPA tooling, bulk profile management; popular with e-commerce sellers | Heavy feature set; smaller free tier | Yes (limited profiles) |
| Kameleo | Chromium + Firefox | Mobile fingerprint emulation (Android/iOS UAs from desktop), fingerprints sourced from real hardware, well-documented API | Premium pricing | No (trial) |
| Dolphin Anty | Chromium | Favoured by affiliate marketers; good team/role management, profile tagging, automation | Marketing-centric feature set | Yes (10 profiles) |
| Incogniton | Chromium | Free tier and profile-data backup; synchroniser for bulk data import | Younger product, smaller fingerprint database | Yes (10 profiles) |
Common denominators: per-profile proxies (HTTP/SOCKS5), cookie/session isolation, fingerprint storage and cloning, and Selenium/Puppeteer/Playwright automation APIs – which is exactly what QA teams and exactly what fraud rings both want.
Honest caveats that apply to all of them: you are running a closed-source binary that sees all your browsing, several of these companies serve a customer base that includes fraudsters, and detection vendors like Fingerprint ship layered anti-detect-browser detection precisely because the arms race never ends. A profile is only as consistent as its weakest signal – a perfect Chromium spoof behind a JA3 that belongs to Firefox build X is a flag, not a mask.
Open-source options (and when they beat the paid tools)
- Tor Browser – the strongest anonymity tool, full stop. But it's designed to make all users look the same, not to give you many distinct identities. Wrong tool for "ten consistent business personas".
- Mullvad Browser – Tor-grade uniformity without the Tor network's speed penalty. Best default for an individual who wants to reduce fingerprintability while keeping a VPN.
- Brave – per-site farbling randomisation while remaining a mainstream, usable browser. Good middle path; a randomised fingerprint is still a fingerprint.
- Cromite / ungoogled-chromium – community Chromium with Bromite-derived anti-fingerprinting patches. Powerful but you inherit maintenance, consistency and verification work yourself.
The trade-off is fundamental: open-source privacy browsers make one identity harder to track; anti-detect browsers construct many identities. Privacy research and personal defence use the former; multi-account workloads genuinely need the latter – or at least profile-separation tooling.
Legitimate use cases
- Ad-tech and site QA. Ad operations and affiliate managers need to verify how a campaign or page renders in dozens of geo/locale/device combinations. Multiple isolated profiles, each pinned to a country, is the honest way to do that without a device lab.
- Brand protection and anti-counterfeit. Investigators checking grey-market listings, impersonation accounts, and phishing pages must browse as ordinary users from the target's region – not from their corporate IP wearing their corporate browser.
- OSINT and security research. Threat-intel and investigative work requires visiting hostile infrastructure without exposing a real researcher fingerprint. This is standard practice in fraud investigation shops (see Group-IB's own material on the topic – they both investigate and educate).
- Privacy research. Academics studying fingerprinting – and defence engineers testing whether their own anti-bot stack detects spoofed clients – use the same tooling as the attackers.
- Managing multiple business accounts. The largest user base by volume: agencies and sellers running several client ad accounts, storefronts, or marketplace shops where the platform's terms allow the accounts but its risk systems punish them sharing one browser fingerprint (a logged-out session cookie and shared canvas hash look identical to collusion). Many platforms' ToS are stricter than the law here – that's a compliance question, not a criminal one.
The Australian angle
Are they legal in Australia? Yes. Anti-detect browsers are ordinary software; Australia has no law against owning or running one, and no licensing regime touches them. The law attaches to what you do:
- Identity crime and fraud. The Commonwealth Criminal Code, Part 9.5 criminalises dealing in identification information and identity fraud (up to 5 years for dealing offences), and Commonwealth/State fraud offences (e.g. s 192E Crimes Act 1900 (NSW), max 10 years) apply to deception-for-benefit – as does any use of stolen cards or hijacked accounts, which is the signature anti-detect-browser-enabled fraud pattern flagged by vendors like SpyCloud.
- Impersonation. Pretending to be a real person or business to obtain benefit, harass, or deceive implicates fraud provisions and (for specific contexts) offences around passing off and misrepresentation. Note Australia's 2024 criminalisation of doxxing covers releasing others' identifying data, not browsing anonymously.
- Account ToS vs. criminal law. Circumventing a platform's multi-account rules is at most a contract/termination issue. Buying stolen accounts, running card-not-present fraud, or phishing is criminal, with or without the browser.
- Legitimate AU users. Ad agencies running multi-client Meta/Google accounts, e-commerce sellers on marketplaces, financial-crime and brand-protection teams (banks and telcos use detection and red-team versions of this tech), journalists and researchers, and privacy-conscious individuals – all lawfully.
The line is bright and worth stating plainly: the browser is legal; deception for gain, use of other people's identification information, and fraud are not. Everything else – QA, research, privacy, permitted multi-accounting – sits firmly on the lawful side.
Verdict
- Individual wanting less tracking: Mullvad Browser or Brave. You don't need an anti-detect product.
- Strong anonymity: Tor Browser. Nothing else comes close.
- Multi-account business workloads, QA, or brand protection: a paid anti-detect browser is the fit-for-purpose tool – Multilogin or Kameleo if budget allows, GoLogin/AdsPower/Dolphin Anty/Incogniton for smaller teams; plus one paid proxy per profile, or you've leaked your timezone/IP pair anyway.
- Everyone else: don't buy one. A spoofing browser that's worse at blending in than Tor and worse at honesty than Brave is the worst of both.
The technology is neutral, the arms race with detection vendors is permanent, and the law in Australia cares about what you do – not what you browse with.
Sources were live-verified at publication. Product features change frequently; check vendor docs before purchase.