Privacy defaults are making device intelligence harder. Good.

Browsers keep shipping changes that make our job harder. Most of them are right, and this category has been slow to say so.
What has actually changed
This is not a vague trend. It is a specific list.
Storage partitioning. Cookies and storage are increasingly scoped to the site you are on rather than shared across the web. Firefox ships this by default, Chrome has its own version, and the practical effect is that an identifier set on one site is no longer visible on another.
Reduced entropy in headers. The User-Agent string used to describe a browser in enough detail to help distinguish one machine from another. It is being cut back deliberately, and the detail that remains has to be asked for rather than volunteered.
Tracking prevention on by default. Safari has been doing this for years. Others have followed. The default position of a modern browser is that cross-site identification is something to interfere with.
Every one of those changes removes signal that somebody in this category was relying on. Ours included.
The uncomfortable part
A lot of what has been sold as device intelligence was cross-site tracking with a security label attached.
That is a harsh way to put it and I think it is accurate. If a technique’s value depends on recognising the same browser across unrelated websites, it is an advertising technique being used for fraud prevention. It might work. It was always going to attract exactly the countermeasures it is now attracting, and complaining about that is complaining that the thing you built on was never yours.
The browsers are not attacking fraud teams. They are removing a capability that was mostly used for something else, and fraud prevention was a passenger.
What survives
The narrower version of the question, and it turns out to be the version that was always more useful.
Is this environment what it says it is, right now, for this one action?
That does not need a persistent identity spanning the web. It needs a reading, at a moment, on one site, about one session. Does the timezone agree with the network path. Does the device resemble anything this account has used before. Does the behaviour look like a person or like a script. Is the network path a rental.
None of that requires following anybody anywhere. It requires looking carefully at a single moment on your own property, which is a thing site operators have always been entitled to do.
I would go further. The privacy changes are pushing this category towards the version of itself that actually holds up. A technique that survives storage partitioning is a technique that was measuring the environment rather than tracking the person, and that is the technique that will still work in five years.
What it costs us, specifically
Coverage.
On a privacy-hardened browser, with tracking prevention on, storage partitioned and headers reduced, there is less to work with. Fewer attributes, less history, weaker corroboration. The reading gets thinner.
Thinner readings mean more cases where we should decline to answer. That is the correct response and it is also, commercially, the annoying one, because a vendor that returns fewer confident answers looks worse in a demo than a vendor that guesses.
We would rather return “unknown” than a confident answer we cannot stand behind. Your engine can route on unknown. It cannot route on a guess it does not know is a guess.
The test I would apply to anyone in this category
If a vendor tells you that browser privacy changes have not affected them, one of two things is true. Either they are not relying on anything the changes touched, in which case they should be able to say precisely what they use and why it is unaffected. Or the answer is not complete.
Ask what coverage looks like on a hardened browser specifically. Not the average across all traffic, where the hardened sessions get diluted by everything else. The hardened subset, on its own.
That number will be worse than the headline. It should be. What matters is whether the vendor knows it and will say it.
The honest limit
We do not do this job as well on a privacy-hardened browser as we do on an ordinary one. Nobody does. Anyone claiming otherwise is either measuring something else or not measuring at all.
If we cannot do the job under a browser configured for privacy, the right response is to say so and to improve, not to lobby against the browser. The user turning those settings on is not the adversary. They are the customer, and they are usually the most valuable one.
