Deck Help Center

Fingerprint settings, explained

Every control on a profile's Advanced tab, what it changes, and whether it is worth touching (usually not).

Updated · 8 min read

On this page

The Advanced tab of the profile editor holds the fingerprint controls. Every one of them already has a sensible default, and for almost every account the right move is to leave them alone: the defaults are what a genuine browser answers, and "different from a real browser" is the thing you are trying to avoid.

Open them with the row ⋯ menu → Edit, then the Advanced tab.

A shortcut instead of ten decisions

On the Overview tab, Profile type sets this whole tab in one click: Google, Facebook and TikTok all pass real hardware through, and Crypto does the same plus turns WebRTC off. Pick the one that matches the account and don't come back here.

🎛️ Hardware masking#

The first five rows are the values a page reads back as raw pixels or samples. Each one has the same two honest positions, and the trade is real:

  • real — pass this machine's actual readback through. It is exactly what a genuine computer produces, so tamper checks see nothing wrong. Every profile on this computer shares that one hardware answer.
  • noise — change it slightly per profile. Your profiles stop matching each other, but the change is itself detectable: a solid fill whose pixels disagree, or silence that is not quite silent, is physically impossible on real hardware, and that is precisely what a tamper check looks for.

Ad platforms weigh tampering much more heavily than they weigh two accounts sharing a graphics card, so real is the default on four of the five rows. (In the app, the stored value "off" is shown as real.)

Canvas — noise / real / block (default: real)

A page draws text and shapes into a hidden canvas, reads the pixels back and hashes them. The result differs slightly between graphics drivers, so it identifies hardware.

  • real passes your real readback through. Recommended.
  • noise perturbs it per profile, deterministically — the same value all session and across launches, so real sites still work.
  • block refuses to produce a canvas at all. A page that cannot read any canvas is rarer in the wild than one that reads an unusual canvas, so this is almost never the right choice; it also breaks features that legitimately use canvas.

Leave it on real unless one specific site is linking profiles on this computer.

Client rects — noise / real (default: real)

getClientRects() returns the exact sub-pixel size of elements on the page. Those measurements vary with fonts and rendering, so they are another hardware hash. Same trade as canvas: real is consistent, noise is unlinkable but detectable. Leave it on real.

Audio context — scale / noise / real (default: scale)

The Web Audio API renders a short tone offline and the result is hashed. scale is the default and is the one exception to "pass the real hardware through": it applies a tiny per-profile gain to the finished render, which keeps silence silent and the waveform intact, so a physical-consistency check finds nothing wrong — while stopping every profile on one computer from sharing a single audio hash.

noise perturbs every sample, which is detectable. real passes the machine's own value through and links your profiles by it. Leave it on scale.

WebGL image — noise / real (default: real)

Same idea as canvas, but the image is rendered by the GPU through WebGL. real is the consistent answer; noise makes profiles differ from each other at the cost of looking tampered with. Leave it on real.

WebGL metadata — mask / real (default: mask)

This one is not a readback, it is the name of the graphics card: the WebGL vendor and renderer strings, and the adapter that navigator.gpu describes.

  • mask reports the card the profile claims (the one in Graphics card below). It sets the WebGL vendor, the renderer, the WebGPU adapter and the numeric WebGL limits together, so they cannot contradict each other, and so two profiles on your machine are not linkable by your real card.
  • real lets your actual card answer. Every profile on this computer then names the same GPU.

Leave it on mask. This is the one masking row where the default is not "real", because a card's name is metadata a browser can report honestly in any number of ways — unlike a pixel readback, there is nothing physically inconsistent about it.

🖼️ Graphics card#

Graphics card — which GPU the profile claims

A dropdown of cards that ship with the profile's operating system. Only those are offered on purpose: a Metal renderer under a Windows user agent is a contradiction no amount of noise hides.

You do not need to set this. The card is drawn with the rest of the machine and already matches the operating system, and every profile generated gets its own draw — so a deck of profiles does not all claim the same card. If you want a different one, New fingerprint on the Overview tab regenerates the whole machine consistently, which is the safer way to change it. The dropdown has no effect at all while WebGL metadata is set to real.

Windows profiles are offered two Intel entries, which look identical in the list because the long driver string is shortened to the model name. They are different cards.

🔤 Fonts#

Mask the font list (default: on)

Which fonts are installed is one of the strongest signals of which operating system you are really on, and one of the easiest ways to contradict your own user agent.

Masking narrows the fonts a page can detect down to the base set that ships with the profile's operating system. It is a filter over the fonts this computer really has: it hides, it never invents. The preview line under the switch shows what is left, for example "56 fonts — Arial, Arial Black, …".

Leave it on. If the profile claims an operating system whose signature fonts your computer does not have, the fingerprint check says so on the "Font set vs claimed OS" row.

🎥 Media devices#

Mask media devices (default: off) and the three counts

Sites can read how many cameras, microphones and speakers exist. Off means the real list is reported. Switch it on and the profile reports the counts you type in Video inputs, Audio inputs and Audio outputs (0–4 each; a new profile is generated with one of each, a phone profile with two cameras).

A browser reporting zero devices of every kind reads as headless, so do not set all three to zero to "hide". One of each is what an ordinary laptop reports. Some sites read the list deliberately — TikTok is one — and an empty list there is a tell.

🌐 WebRTC#

WebRTC — Based on proxy / Disabled / Real (default: Based on proxy)

WebRTC is the one leak that never touches your proxy. It sends a UDP packet to a STUN server; SOCKS proxies do not carry UDP, so your machine's own address can land in the connection candidates and a site reads it in a few lines of JavaScript.

  • Based on proxy blocks the UDP the proxy cannot carry, and then reports the candidate set a real Chrome behind a home router would — including the proxy's exit address, which the site already knows from the connection. "WebRTC present but completely silent" is itself unusual, so this is the coherent answer. With no proxy on the profile it behaves like Real, because your own address is the one the site sees anyway.
  • Disabled gathers nothing at all. This is what the Crypto profile type sets, on the argument that a leaked local address matters more there than looking ordinary.
  • Real reports whatever the machine says, including your home address. Only useful for testing.

Leave it on Based on proxy. More detail in WebRTC and IP leaks.

⚙️ The rest#

Send Do Not Track (default: off)

Sends the DNT: 1 header and sets navigator.doNotTrack. Most browsers do not send it, so switching it on makes the profile slightly more distinctive rather than more private. Leave it off unless you have a specific reason.

Start URL — Previously opened tabs / Blank page (default: Previously opened tabs)

What the browser opens when the profile launches. Previously opened tabs restores the tabs that were open when you last stopped it; Blank page starts clean every time. See Tabs, sessions and clearing a profile's cache.

Launch arguments — extra Chromium flags

Whitespace-separated command-line switches for the browser, for example --start-maximized. This is a power-user field and a synced one, so LoginDeck drops any switch that would quietly turn the profile into something else — anything that moves or removes the proxy, points the browser at a different data folder, opens a debugging port, loads code, disables the sandbox, or overrides the user agent, language or timezone. Dropped switches are ignored silently; the profile still opens.

Launch arguments are ignored entirely for Firefox profiles.

ℹ️ Good to know#

  • Changes here do not need a new fingerprint. Save the profile and the next launch uses them.
  • What the profile will present is summarised live in the Profile summary panel on the right of the editor.
  • Firefox profiles ignore the four readback rows (Canvas, Client rects, Audio context, WebGL image), the WebRTC setting and Launch arguments — the Firefox engine produces its own consistent values. The font mask and the GPU strings do apply.
  • To change many profiles' settings at once, edit one and use the row ⋯ menu on the others, or see Change many profiles at once. There is no bulk editor for masking values.
  • After changing anything here, re-run the fingerprint check to see what the browser actually reports.