Antidetect Browser Glossary: 40 Terms Every Multi-Account Operator Should Know
I was three months into running multi-account campaigns before I understood what "entropy" actually meant. Kept seeing it in fingerprint test results, nodding along like I got it. I didn't. Cost me accounts.
That's the problem with this space. The terminology is half computer science, half operational jargon, and nobody bothers writing it down. You pick it up through expensive mistakes and scattered forum posts written by people who definitely know more than me but explain things like everyone already has a PhD in browser internals.
So here's the glossary I wish existed when I started. Forty terms, explained for people who actually run accounts — not academics. If you're setting up your first antidetect browser or trying to figure out why your profiles keep getting flagged, start here.
Core Fingerprinting Terms
1. Browser Fingerprint
A unique identifier derived from your browser's characteristics — screen resolution, installed fonts, GPU renderer, timezone, language settings, and dozens more. Unlike cookies, you can't clear it. Unlike IP addresses, you can't change it with a VPN. The fingerprint is calculated from how your browser behaves, not from stored data.
Platforms combine 30-50+ signals to create fingerprints. Each signal alone isn't unique. Combined, they identify you with 95%+ accuracy.
2. Canvas Fingerprinting
A technique that draws invisible graphics using the HTML5 Canvas API, then hashes the result. Different GPUs, drivers, and font rendering engines produce slightly different pixel outputs — even for identical drawing instructions. Your canvas hash is consistent across sessions but different from most other users.
Canvas fingerprinting is the most commonly discussed technique, but honestly? It's overhyped. It's the easiest to spoof. Audio and WebGL are the ones that actually trip people up — and the ones nobody writes blog posts about because they're harder to explain.
3. WebGL Fingerprint
Similar to canvas, but for 3D graphics. WebGL fingerprinting extracts your GPU's renderer string ("ANGLE (Intel, Intel UHD Graphics 620...)") and renders 3D scenes to detect rendering variations. More entropy than canvas because GPU configurations vary more than 2D rendering. Our WebGL fingerprinting deep-dive covers the technical details.
4. Audio Fingerprinting
Uses the Web Audio API to process audio signals and measure how your browser handles oscillators, compressors, and analyzers. Different audio stacks produce different output values — even with identical input. Lower entropy than canvas or WebGL, but useful as a cross-validation signal. See the audio fingerprinting breakdown.
5. Font Fingerprinting
Detects which fonts your system has installed by measuring text rendering width and height. Different font sets produce different lists. A machine with Adobe Creative Suite has fonts a stock Windows install doesn't. The combination of installed fonts is often unique enough to identify users.
6. Entropy
A measure of how identifying a piece of information is. High entropy = distinctive. Low entropy = common.
Screen resolution of 1920x1080? Low entropy — millions of people. A weird resolution like 1847x923? High entropy — almost nobody. Detection systems combine multiple low-entropy signals to create high-entropy fingerprints. This is why randomizing one parameter doesn't help — the combination still identifies you. Took me embarrassingly long to internalize this.
7. Fingerprint Hash
A fixed-length string generated by hashing your fingerprint values. Sites don't store your raw fingerprint data — they store the hash. When you return, they hash your current fingerprint and compare. Match = same user.
8. Cross-Browser Tracking
Techniques that identify users across different browsers. Harder than same-browser fingerprinting, but possible through shared signals: screen resolution, timezone, IP address, installed plugins, and hardware characteristics that don't change between Chrome and Firefox.
Antidetect Browser Concepts
9. Browser Profile
An isolated browser environment with its own fingerprint, cookies, localStorage, and session state. Each profile appears as a different user. Proper antidetect browsers generate internally consistent fingerprints per profile — canvas, WebGL, fonts, and Client Hints all match.
10. Profile Isolation
Keeping browser profiles completely separate so platforms can't link them. Isolation covers fingerprint (each profile has unique values), storage (cookies and localStorage don't leak between profiles), and network (each profile uses a different proxy).
11. Native Engine
An antidetect browser that modifies browser source code (C++ for Chromium) rather than using JavaScript overrides or extensions. Native engines produce genuine fingerprint values at every layer — main thread, Web Workers, and internal APIs. Extension-based tools fail cross-validation tests because their overrides don't reach everywhere. JustBrowser uses a native Chromium engine for this reason.
12. Fingerprint Spoofing
Altering your browser's reported characteristics to appear as a different user. Can be done via JavaScript overrides (detectable), browser extensions (very detectable), or native engine modifications (harder to detect). Quality spoofing produces consistent, plausible values — not random noise.
13. Fingerprint Consistency
When all spoofed values align logically. A profile claiming Windows should have Windows fonts, Windows-style path separators, Windows screen dimensions, and Windows GPU naming conventions. Mismatches — Mac fonts on a Windows profile, for instance — flag you faster than using no spoofing at all.
This is the mistake I see most often. People spend hours perfecting their canvas spoof and completely ignore that their navigator says "MacIntel" while their fonts scream "Windows 11." I've done it myself. More than once.
14. Cookie Warm-up
Browsing popular sites to accumulate cookies before using a profile for important accounts. New profiles with zero cookies look like fresh installs or automation. Profiles with Google, Facebook, news site, and retail cookies look like real users. Most antidetect browsers include automated warm-up features.
15. Profile Aging
Simulating usage history over time — browsing sessions, varied sites, realistic timing patterns. A profile that was "created" six months ago but has activity consistent with that timeline looks more legitimate than a fresh profile with perfect fingerprints. Platforms track account age and behavior consistency.
Detection Methods
16. Bot Detection
Systems that identify automated or non-human traffic. Cloudflare, PerimeterX, Akamai, DataDome — these analyze fingerprints, behavior patterns, and network signals to block bots. Multi-account operators get caught in bot detection because their profiles share detectable similarities.
17. Trust Score
A numerical rating of how legitimate your browser appears. CreepJS, FingerprintJS Pro, and platform-internal systems all calculate trust scores. Higher = more trustworthy. Scores tank when fingerprint inconsistencies, prototype tampering, or headless signals show up.
I hate trust scores, honestly. They're opaque, inconsistent between tools, and give you no actionable feedback. "Your trust score is 42%." Cool. Which of the 40 signals did I screw up? Nobody tells you.
18. Lies Detection
Techniques that identify spoofed fingerprint values. Cross-checking main thread values against Web Worker values. Measuring property access timing (native = fast, JavaScript override = slow). Examining prototype chains for tampering. If you're spoofing, lies detection catches how you're spoofing.
19. Headless Detection
Identifying browsers running without a graphical interface (headless mode). Headless browsers have telltale signals: missing plugins, absent window dimensions, specific automation flags. Platforms block headless traffic because it's almost always automated.
20. JA3/JA4 Fingerprinting
Fingerprinting based on TLS handshake characteristics — cipher suites, extensions, and their ordering. Even if your browser fingerprint is perfect, your TLS fingerprint can reveal that you're using an unusual configuration. JA4 is the newer standard with better collision resistance.
21. WebRTC Leak
WebRTC can expose your real IP address even when using a proxy or VPN. It was designed for peer-to-peer communication and sometimes bypasses proxy settings. Antidetect browsers disable or proxy WebRTC to prevent leaks.
22. DNS Leak
When DNS queries bypass your proxy and go directly to your ISP's DNS servers, revealing your real location. Similar to WebRTC leaks — the proxy handles HTTP traffic but DNS slips through a different path.
Network & Proxy Terms
23. Residential Proxy
A proxy IP assigned by a real ISP to a real home. Looks like normal consumer traffic. Higher trust than datacenter IPs. More expensive, but necessary for platforms that flag infrastructure IPs.
24. Datacenter Proxy
A proxy IP from a hosting provider (AWS, DigitalOcean, etc.). Cheap and fast, but flagged by most platforms because legitimate users don't browse from data centers. Useful for scraping; risky for account management.
25. Mobile Proxy
A proxy IP from a mobile carrier. High trust because mobile IPs are shared via carrier-grade NAT — thousands of legitimate users share each IP. Platforms rarely block mobile IPs.
Most expensive proxy type by a lot. Worth it for high-value accounts. Probably overkill for most operations, but people swear by them.
26. Sticky Session
A proxy configuration that maintains the same IP for extended periods (hours or days) rather than rotating per request. Important for account logins — if your IP changes mid-session, platforms flag it as suspicious.
27. Rotating Proxy
A proxy that changes IP with each request or at fixed intervals. Good for scraping where you don't need session continuity. Bad for account management where session consistency matters.
28. Geo-Matching
Aligning your proxy location with your account's expected location. A US account accessed from a German IP gets flagged. Proper geo-matching means your proxy's country, state, and sometimes city match the account's registration or billing location.
Automation & API Terms
29. CDP (Chrome DevTools Protocol)
The protocol Chromium uses for remote debugging and automation. Tools like Playwright and Puppeteer communicate with the browser via CDP. Antidetect browsers with CDP support let you automate fingerprint-protected profiles programmatically. JustBrowser exposes CDP through its REST API.
30. Headless Launch
Running a browser without a visible window. Faster for automation, but triggers headless detection. Antidetect browsers that support headless mode normalize the headless-specific signals to avoid detection.
31. REST API
An interface for controlling browser profiles via HTTP requests — create profiles, configure fingerprints, launch sessions, manage cookies. Engineering teams use REST APIs to integrate antidetect browsers into automation pipelines. Essential for scraping at scale.
32. Playwright/Puppeteer Stealth
Libraries and plugins that modify Playwright and Puppeteer to avoid automation detection. They hide the navigator.webdriver flag, normalize permission states, and remove other automation signals. Work best when combined with an antidetect browser. See the Playwright stealth tutorial.
Advanced Detection Signals
33. Client Hints (UA-CH)
HTTP headers that replaced the user-agent string for conveying browser and device information. Sec-CH-UA, Sec-CH-UA-Platform, Sec-CH-UA-Mobile, etc. Sites request specific hints and cross-check them against other fingerprint values. Inconsistent Client Hints are a strong spoofing signal. The Client Hints fingerprinting guide covers the details.
34. Navigator Object
The JavaScript object containing browser identification properties — navigator.userAgent, navigator.platform, navigator.language, etc. Spoofing the navigator is table stakes. The challenge is spoofing it consistently across main thread, Web Workers, and iframes.
35. Screen Fingerprint
Properties like screen.width, screen.height, screen.colorDepth, and window.devicePixelRatio. Common resolutions have low entropy, but unusual combinations are identifying. Running in a VM with a weird resolution is a red flag.
36. Timezone Fingerprint
Your browser's reported timezone offset and Intl.DateTimeFormat output. Should match your proxy's geographic location. A profile claiming Tokyo timezone while using a New York proxy is immediately suspicious.
37. WebGL Renderer String
The GPU identification string exposed via WebGL: manufacturer, model, and driver info. High entropy because GPU configurations vary widely. Spoofing requires matching the renderer string to plausible canvas and WebGL rendering behavior.
38. Hardware Concurrency
The navigator.hardwareConcurrency property reporting CPU core count. Modern phones have 8 cores; servers have 64+. A "mobile" profile with 32 cores is obviously wrong.
39. Device Memory
The navigator.deviceMemory property reporting approximate RAM in gigabytes. Combined with hardware concurrency, it reveals device class. Mismatches between device memory and other hardware signals flag spoofing.
40. Prototype Tampering
Modifying JavaScript built-in objects to hide automation signals or spoof values. Detection systems examine whether property descriptors, prototype chains, and function toString() outputs match native implementations. Tampering leaves traces. Native engine modifications don't have this problem because they're not tampering — they're generating genuine values at the source.
Honorable Mentions
Supercookies: Tracking methods that persist across cookie clears — HSTS state, favicons, cached resources. Proper profile isolation wipes these along with regular storage.
Behavioral Fingerprinting: Tracking mouse movements, scroll patterns, typing cadence. Harder to spoof because it requires realistic human-like input generation. Most antidetect browsers don't address this — it's a different layer of the stack. And frankly, I'm not convinced anyone has solved it well yet.
EME/CDM Fingerprinting: Using encrypted media extensions to detect device types. Mostly relevant for streaming services. Low priority for typical multi-account use cases.
Quick Verdict
If you remember one thing from this glossary: consistency beats randomization. Every time. A profile with matching, plausible values across all 40+ parameters beats a profile with random values that contradict each other. I learned this the expensive way.
The operators who survive long-term understand what they're actually spoofing. They know why their canvas hash matters, what their Client Hints reveal, and how proxy geo-matching affects detection. Now you have the vocabulary.
For click fraud protection on your ad accounts, ClickzProtect handles the traffic quality layer. For privacy-first analytics without adding fingerprinting signals, JustAnalytics works. For the email layer when running multi-account outreach, JustEmails isolates domains properly.
But the browser is where it starts. Get the terminology right, and the technical decisions start making sense.
Frequently Asked Questions
What's the difference between fingerprinting and tracking?
Tracking uses identifiers you can delete — cookies, localStorage, session IDs. Fingerprinting identifies your browser through its characteristics: how it renders graphics, which fonts it has, how its audio stack behaves. You can clear cookies. You can't change your GPU's rendering signature without specialized tools.
Why do I need an antidetect browser if I already use proxies?
Proxies change your IP address. Antidetect browsers change your browser fingerprint. Platforms track you at both layers — network (IP) and browser (fingerprint). Using proxies without fingerprint isolation means all your accounts share the same canvas hash, WebGL signature, and font list. Platforms link them instantly.
What does entropy mean in fingerprinting?
Entropy measures how identifying a piece of information is. High entropy means few people share that value — it's distinctive. Low entropy means lots of people share it — it's common. A rare GPU has high entropy (easy to track). A common screen resolution has low entropy (hard to track). Detection systems combine low-entropy signals to create high-entropy fingerprints.
Are antidetect browsers legal?
The browser itself is legal — it's modified Chromium. Legality depends on what you do with it. Running multiple business accounts within a platform's ToS is generally fine. Account fraud, identity theft, or bypassing security controls for malicious purposes isn't. Check the specific platform's terms and your jurisdiction's laws.
Try JustBrowser
Native Chromium antidetect browser — not extension-based. Real C++ engine patches at the canvas / WebGL / audio / font / screen layer, so 40+ identity parameters are genuine, not faked. REST API for Playwright, Puppeteer, Selenium. $9.99/month or $99.99/year. 7-day free trial, card required — cancel any time in the seven days and you are not charged. Unlimited profiles.
Get started → · How it differs from Multilogin / GoLogin / AdsPower
Related Posts
Ready to manage multiple accounts?
Seven days free, then $9.99/month — one plan, everything included.