Header illustration for Anti-detect browsers: what they are, what they're used for, and who legitimately needs one

Anti-detect browsers: what they are, what they're used for, and who legitimately needs one

Anti-detect browsers: what they are, what they're used for, and who legitimately needs one

Anti-detect browsers have a reputation problem. Search the term and you land in ad-farm and account-farming territory; ask a fraud analyst and they'll tell you the same software is a core threat vector. Both things are true – and neither tells you what the technology actually is. This piece covers the mechanics, the major products, the open-source alternatives, the legitimate use cases, and where the legal line sits in Australia.

This is general information, not legal advice.

What fingerprinting actually is

A browser fingerprint is a set of values your browser exposes to any site that runs JavaScript, combined into an identifier that can persist without cookies. The research basis is old and well established: the EFF's original Panopticlick study (Eckersley, 2010) showed most browsers were uniquely identifiable from configuration alone, and the AmIUnique project at INRIA replicated it at larger scale years later. The main signals:

Signal How it works What drives uniqueness
Canvas Render hidden text/graphics to a <canvas>, read back pixels. Sub-pixel rendering differs by GPU, driver, font stack, antialiasing. GPU + driver + OS + fonts
WebGL Read GPU vendor/renderer strings, or render 3D scenes and hash the output. Graphics hardware, driver
Fonts Detect which fonts are installed (measure text widths, or document.fonts). Installed font list – wildly variable
AudioContext Render audio through an offline context; output has hardware-level quirks. Audio stack
Screen/UA/locale/timezone navigator.userAgent, screen geometry, Intl defaults, Date timezone offset. Configuration, VPN mismatch
TLS/JA3 & JA4 Not JavaScript at all – the server fingerprints the handshake itself (cipher-suite order, extensions) before any page loads. JA3/JA4 hashes this into a stable ID. Browser/engine build – the hardest signal to fake

The killer detail is the timezone/locale mismatch: connect from a VPN exit in Frankfurt while your browser reports Australia/Sydney and a UTC+11 clock offset, and you've told every anti-fraud system that your IP is a proxy. This is exactly the class of leak anti-detect browsers exist to fix – they pin the timezone, locale, geolocation API, and font stack of each profile to match its proxy, not your machine.

The two philosophies: blend in vs. change shape

There are two defences against fingerprinting, and they're opposites.

Uniformity – make everyone look identical. This is Tor Browser's approach and, by extension, Mullvad Browser (Tor Browser's Firefox base with the Tor network removed, built in collaboration with the Tor Project). If every user reports the same window size, same font list, same everything, your fingerprint is one of a million. The cost: you must not customise anything, and you stand out precisely because everyone else isn't uniform.

Randomisation/spoofing – change your values per session or per profile. Brave's "farbling" injects per-site deterministic noise into canvas, WebGL, and audio outputs so the hash differs by site and session. Chromium forks like Cromite and ungoogled-chromium ship Bromite's anti-fingerprinting patches (font mitigations, client-rect noise) behind flags.

Anti-detect browsers are the industrial version of spoofing: many simultaneous, fully isolated profiles, each with a consistent, realistic fingerprint (OS, GPU, fonts, timezone, locale, WebRTC) bound to its own proxy. They're built on Chromium (most products) or Firefox (Multilogin pioneered a Firefox-based engine), with deep patches that ordinary extensions can't reach – including, for some products, TLS-level consistency so the JA3/JA4 handshake matches the spoofed browser.

The main products

Browser Engine Notable strengths Considerations Free tier
Multilogin Chromium + proprietary Firefox (Mimic/Stealthfox) Longest track record; deep, tested fingerprint consistency; "real device" fingerprint sources Priciest tier; aimed at teams No (trial)
GoLogin Chromium (Orbita) Cloud profiles accessible from any machine; generous free plan; broad proxy marketplace Less granular control than top-tier Yes
AdsPower Chromium (SunBrowser) + Firefox (FlowerBrowser) Strong automation/RPA tooling, bulk profile management; popular with e-commerce sellers Heavy feature set; smaller free tier Yes (limited profiles)
Kameleo Chromium + Firefox Mobile fingerprint emulation (Android/iOS UAs from desktop), fingerprints sourced from real hardware, well-documented API Premium pricing No (trial)
Dolphin Anty Chromium Favoured by affiliate marketers; good team/role management, profile tagging, automation Marketing-centric feature set Yes (10 profiles)
Incogniton Chromium Free tier and profile-data backup; synchroniser for bulk data import Younger product, smaller fingerprint database Yes (10 profiles)

Common denominators: per-profile proxies (HTTP/SOCKS5), cookie/session isolation, fingerprint storage and cloning, and Selenium/Puppeteer/Playwright automation APIs – which is exactly what QA teams and exactly what fraud rings both want.

Honest caveats that apply to all of them: you are running a closed-source binary that sees all your browsing, several of these companies serve a customer base that includes fraudsters, and detection vendors like Fingerprint ship layered anti-detect-browser detection precisely because the arms race never ends. A profile is only as consistent as its weakest signal – a perfect Chromium spoof behind a JA3 that belongs to Firefox build X is a flag, not a mask.

Open-source options (and when they beat the paid tools)

The trade-off is fundamental: open-source privacy browsers make one identity harder to track; anti-detect browsers construct many identities. Privacy research and personal defence use the former; multi-account workloads genuinely need the latter – or at least profile-separation tooling.

Legitimate use cases

The Australian angle

Are they legal in Australia? Yes. Anti-detect browsers are ordinary software; Australia has no law against owning or running one, and no licensing regime touches them. The law attaches to what you do:

The line is bright and worth stating plainly: the browser is legal; deception for gain, use of other people's identification information, and fraud are not. Everything else – QA, research, privacy, permitted multi-accounting – sits firmly on the lawful side.

Verdict

The technology is neutral, the arms race with detection vendors is permanent, and the law in Australia cares about what you do – not what you browse with.

Sources were live-verified at publication. Product features change frequently; check vendor docs before purchase.

← All posts