Real-time communication
GET /api/fingerprint/webrtcWebRTC fingerprinting exploits the Real-Time Communication API to gather network information, including local IP addresses, network interfaces, media capabilities, and connection characteristics that uniquely identify devices and network configurations. WebRTC's RTCPeerConnection creates peer-to-peer connections for audio/video communication, but in doing so, necessarily exposes network details. The technique creates RTCPeerConnection objects, uses createOffer() to generate Session Description Protocol (SDP) offers, and parses the resulting SDP strings to extract ICE (Interactive Connectivity Establishment) candidates containing local IP addresses, including IPv4 and IPv6 addresses for all network interfaces (WiFi, Ethernet, VPN, virtual adapters). Even behind NAT and firewalls, WebRTC reveals internal private network addresses (192.168.x.x, 10.x.x.x) that provide fingerprinting entropy. The technique also enumerates media devices, codecs, and capabilities through RTCRtpSender.getCapabilities() and RTCRtpReceiver.getCapabilities(), revealing supported video codecs (H.264, VP8, VP9, AV1), audio codecs (Opus, G.711, iSAC), RTP header extensions, and RTCP feedback mechanisms. Different browsers, browser versions, and operating systems support different codec configurations, profile levels, and extension parameters. Hardware acceleration capabilities affect codec support: devices with hardware H.265 decoding report different capabilities than software-only systems. Additional fingerprinting comes from STUN/TURN server connectivity tests, mDNS hostname leakage, and timing characteristics of connection establishment. VPN users attempting to hide their real IP address often fail because WebRTC bypasses VPN tunnels and reveals the actual local network configuration. Modern browsers implement privacy protections like mDNS masking and ICE candidate filtering, but these protections themselves become fingerprinting signals. Privacy-conscious users disable WebRTC entirely, but WebRTC unavailability is a strong signal distinguishing privacy-focused users from mainstream users.
Move from this collector to the CreepJS signal index, live checker, API docs, and other high-value fingerprinting explainers.