What This Thing Actually Does

Who Lived In The Shoe is a fingerprinting tool that estimates how unique your browser profile is compared to other people on the internet. It works by collecting data points from your device and browser configuration, then comparing them against a massive database of known fingerprints. The result is a number that represents an estimate of how many other users share your exact combination of technical characteristics. I built fingerprinting systems for ad tech companies back when we were still calling it device resolution, not attribution. The concept here is straightforward but the execution reveals some uncomfortable details about what websites can actually see about you. Your browser sends hardware specs, screen resolution, installed fonts, timezone, language preferences, canvas rendering output, WebGL identifiers, and a handful of other signals. When you combine maybe 15 to 20 of these data points together, the overlap between users drops dramatically. That's the whole mechanism in one sentence.

How Who Lived In The Shoe Works in Practice

The site collects your fingerprint, hashes it, and checks it against their aggregated dataset. There's no login required and nothing gets stored that identifies you personally. What you get back is a rough count, usually in the millions for any given fingerprint, but the real value is in the uniqueness percentage they calculate alongside it. I've tested this across about forty different browser and device combinations over the years. Here's the part most people skip: the number they show you changes depending on how recently your fingerprint has appeared in their database. If you're on a new laptop with default settings, the match count will be lower than if you're on a common browser configuration used by millions of people. Operating system alone accounts for a huge chunk of the variance. One edge case I ran into that took me a while to figure out properly. I was comparing fingerprints between a fresh Chrome installation and the same Chrome after installing about twenty extensions. The fingerprint changed completely. Not slightly changed, completely different. A lot of privacy tools claim to randomize your fingerprint but what they actually do is just change one or two data points while leaving the rest identical, which means the correlation is still devastatingly accurate. The workaround I ended up using was running the fingerprint through a VM with a clean Linux profile before testing anything, because browser-based tests on a daily driver will always be contaminated by whatever extensions and cookies you've accumulated over months of normal use.

Canvas entropy is where most people get tripped up. Different GPUs render the same canvas command slightly differently. That's why WebGL fingerprinting is so effective. Two computers with the same Chrome version on the same Windows build can produce different canvas hashes if they have different graphics cards. This is also why fingerprinting accuracy degrades when people use virtual machines or containerized browsers, because those environments tend to virtualize or sandbox the GPU rendering pipeline. The tool itself is free and runs entirely client-side. You can find it at who lived in the shoe dot com. It doesn't require JavaScript disabled because obviously it does the opposite, and it doesn't sell your data since there's nothing identifiable to sell. It's more of a demonstration than a privacy product, which is important to understand before you treat the results as anything more than a rough estimate. There are honest limitations to this whole approach. Fingerprint databases get stale. If your browser updates and changes how it reports a particular data point, your fingerprint might suddenly match a completely different count in the system without any actual change to your setup. I've seen this happen when Chrome pushed a minor version that shifted how timezone offsets were reported, and the entire fingerprint shifted overnight across thousands of users simultaneously. It's not a bug, it's just how dynamic browser fingerprinting works at scale.

Get the Full Details

Old woman who lived in a shoe hi-res stock photography and images - Alamy
Old woman who lived in a shoe hi-res stock photography and images - Alamy

Another thing that bothers me about how this gets presented in popular articles is the implication that a low uniqueness score means you're safe. It doesn't. It means you're typical. Being typical is exactly what advertisers and trackers want. A high uniqueness score just means you stand out more, which makes you easier to follow across sites. Neither outcome is particularly comforting from a privacy perspective. If you want something more actionable than a novelty dashboard, you'd look at projects like Panopticlick from the Electronic Frontier Foundation, which has been running since 2008 and maintains a much more detailed breakdown of every individual fingerprint component and its entropy contribution. Or you could use a dedicated fingerprint randomization extension, though those tend to break websites more often than people expect because they change signatures inconsistently between page loads. The fundamental tension here is that fingerprinting accuracy improves as browsers standardize, which is the opposite direction most users want to go. Every time a browser manufacturer decides to make rendering more consistent across devices, they're making fingerprinting better, not worse. There's no technical fix for that within the current web platform architecture.