Deck Help Center

What no antidetect browser can change

An honest list of the signals a browser cannot fake — TLS handshakes, IP reputation, behaviour and account history — and what to do about each.

Updated · 5 min read

On this page

LoginDeck gives each profile its own consistent machine, its own storage and its own exit address. That covers a large part of what a site reads, and it is the part the browser is in a position to control. It is not everything, and any tool that tells you otherwise is selling something.

This page is the list of things to stop expecting from a browser.

🔐 The network handshake (TLS, JA3/JA4, HTTP/2)#

Before a single byte of a page loads, your browser negotiates TLS. The order of cipher suites, the extensions offered, the way the handshake is shaped — that is a recognisable signature, published as JA3 and JA4 hashes, and services such as Cloudflare and Akamai read it. The same applies to the HTTP/2 settings a connection opens with.

That signature comes from the browser's own network stack. LoginDeck does not rewrite it, and nor does any other antidetect browser. What matters in practice is that it does not contradict what the profile claims: a profile presenting Chrome really is running Chromium, and a profile presenting Firefox really is running Firefox. Trouble starts when a tool claims to be a browser it is not — and that is also why a scripted HTTP client pretending to be Chrome is caught immediately, while a real browser driven by automation is not caught this way.

Nothing for you to configure. Just do not expect to look like a different browser than the engine you picked.

🌐 IP reputation#

The address itself carries history you cannot change from the browser:

  • Which network owns it — a hosting company, a home ISP, a mobile carrier.
  • Whether the range is a known datacentre or commercial VPN range.
  • What other people have already done from that address.

A perfect fingerprint on an address a site distrusts is still an address the site distrusts. This is the one item on the page you fix with money and choice rather than settings: see Which proxy should I use?, and prefer a residential or mobile exit for accounts that matter. A phone you own is the cleanest exit available, because it is an ordinary carrier address: Use an Android phone as a mobile proxy.

🖱️ Behaviour#

How fast you type, how the mouse moves, how long you read before clicking, what time of day you work, how many accounts you touch in a row, how similar their actions are. Platforms weigh this heavily, and it is invisible to every fingerprint test.

  • Paste passwords and long text with Paste as human (right-click inside a profile), which types the clipboard out instead of filling the field in one frame.
  • Give a new profile some ordinary browsing before you ask anything of it: Warm up new profiles.
  • Automation is still automation. A Flow that logs into forty accounts in four minutes looks like exactly that, whatever the fingerprint says. Space runs out, and use schedules rather than one burst.

📜 Account history#

Account age, the phone number and email it was verified with, the payment methods used, the addresses shipped to, the people it talks to, the content it posts. When two accounts share any of these, a site does not need a fingerprint to connect them.

Keep one account per profile, keep the profile, and keep everything about the account — the email, the number, the card — as separate as the account needs to be. Good habits that keep accounts safe is the short version.

💻 Your own computer, still underneath#

Some values are read from the machine the browser is running on, and the best a profile can do is agree with them rather than contradict them:

  • Installed fonts. The font mask hides fonts; it cannot install ones you do not have. A profile claiming macOS on a Windows computer cannot render the fonts a Mac would.
  • Display scale and screen size. A claimed resolution has to be one that exists at your display's scale factor, which is why LoginDeck fits Windows profiles to the host at launch.
  • Touchscreens and other real hardware. Present or not present.
  • The graphics driver. Some of what WebGL reports comes from the driver itself, underneath the strings a profile presents.

The fingerprint check is where you see the result of this on your machine, per profile.

🧩 Two profiles, one computer#

If the masking rows on the Advanced tab are set to real — the default, and the right default — then every profile on this computer returns the same canvas, WebGL image and client-rect readings, because they are all drawn by the same hardware. That is a link a determined site can use.

The alternative, noise, makes those readings differ per profile but is itself detectable, and ad platforms treat a tampered readback far more harshly than a shared one. The trade is explained per setting in Fingerprint settings, explained. If unlinkable hardware really is your requirement, separate computers are the honest answer.

🧰 What depends on the engine#

Rows in the fingerprint check marked needs the engine are traits a stock Chrome physically cannot change. Stock Chrome honours the process-level half of a profile — user agent, languages, window size, proxy, WebRTC policy — and has no way to change the rest: canvas, WebGL, fonts, cores, memory and navigator.platform all come out of the browser's own code. Those rows turn green when the profile runs on LoginDeck's own engine. The report's Engine line tells you which one ran.

ℹ️ Good to know#

  • No browser makes an account unbannable. It removes one category of link between accounts; the rest is up to how the accounts are run.
  • Do not add anti-fingerprinting extensions on top. They contradict the engine's values and make a profile look tampered with.
  • If a site has already flagged an account, a fresh fingerprint on the same cookies, the same address and the same behaviour does not reset anything.
  • Sites also change. A profile that passed every check in the spring can meet a new signal in the autumn — which is why the check is a button you can press again, not a certificate.