A device identifier is a unique hardware or software fingerprint because it lets platforms recognize you even when you switch networks, clear cookies, or turn on a VPN. This technical distinction explains a case that circulated some time ago: the precise identification of a user who believed himself anonymous, connected from a hotel with an active VPN, traced down to his specific session through signals that no private network touches.
The thesis that circulates in forums, videos, and manuals holds that masking the IP is enough to break the thread linking activity to identity. Adding a local account or running everything inside a virtual machine would supposedly complete the invisibility. That logic dominated popular anonymity advice for years, because the IP was, in fact, the central data point connecting location and person.
Masking the IP is still useful against basic geographic tracking, against what your provider observes, and against regional blocks. A virtual machine isolates certain traces from the host system. A local account keeps major platforms from tying your activity to a profile already linked to your name and email. Against an average advertiser, these measures work reasonably well. The problem is they stopped being sufficient, and almost no one updated the manual.
How is it possible for a device identifier to survive a VPN? It operates on a different layer of the machine. The VPN encrypts and reroutes network traffic, but the identifier resides in the operating system or in the hardware itself, and it travels inside every request regardless of the chosen route. On Android, the advertising identifier is generated through Google services, persists across apps, and can be manually reset, though its value for correlation remains high. On iOS, the IDFA has required explicit per-app consent since version 14.5, a change that reduced cross-tracking without eliminating it. Windows exposes hardware-bound identifiers that a lot of telemetry reads without the user ever noticing. Some software identifiers can be reset with effort. Those anchored to physical components are, for all practical purposes, immutable.
The hotel case is instructive. The user ended up identified not by his masked IP but by the combination of browser fingerprint, device identifier, screen resolution, installed fonts, the device's time zone, and temporal correlation between sessions sharing advertising development kits. This isn't cinematic surveillance: it's the logical consequence of a digital advertising infrastructure optimized over years to recognize the same user across phone, laptop, and tablet, even when each device presents a different IP and cookie. Tracking on hotel networks is a side effect of a design built for another purpose: advertising persistence.
What the guides rarely mention is that you're competing against structures built with large budgets and years of iteration, precisely to withstand the known countermeasures. I've seen this same pattern in other contexts, where the user believes they're trading privacy for use, but the technical architecture already decided that trade was illusory from the start. A parallel case shows up in how certain AI platforms demand identity verification with no legal mandate requiring it, or in the relaunch of services like Fable, which quietly built in identity validation.
What can be done when the hardware itself gives away your presence? Less than one would hope, and with more effort than short tutorials promise. Resetting the advertising identifier on Android or limiting app tracking on iOS reduces basic advertising tracking, but it doesn't stop browser fingerprinting or network correlations. A more realistic path involves browsers designed to resist fingerprinting, constant updates, and accepting that no single tool solves everything. Privacy today is built in layers, never with one app alone.
I still don't have a clear answer for how to fully resolve this tension between convenience and control. I keep exploring the subject because the complexity outpaces the quick fixes. In The Generosity in the Doorway I examine a similar pattern with AI infrastructure: whoever builds the identification system ends up managing its supposed remedies too. Las Piedras No Mienten, a work still in progress, looks into how to tell legitimate coordination apart from structural surveillance. The difference almost always comes down to one simple question: did someone ask for permission, or was permission just assumed the moment you used the device?
The counterintuitive fact worth holding onto is this: turning off the VPN doesn't always change how much you can be tracked, because the IP was never the main piece giving you away. The sense of anonymity it offers is closer to a well-marketed placebo. It protects against threats that stopped being the main ones, while the identifier that actually matters keeps operating inside the machine.
Who decided, and under what accountability, that devices should be born with permanent identifiers users cannot negotiate?