You have seen the box. The little one that says "verify you're human" and makes you wait before a site lets you in. It turns out Cloudflare Turnstile, a common bot check, scans your device to decide. When one user's privacy browser refused to hand over that scan, the box locked them out.
Cloudflare sells Turnstile as privacy-friendly. Its own page says Turnstile "never harvests data for ad retargeting." So the message one user got in late May 2026 reads strangely.
Here is what Turnstile told them, word for word. "Turnstile uses browser fingerprinting to verify you're human. Privacy tools that block or randomize fingerprinting make your browser look like a bot trying to hide its identity. Temporarily allowing fingerprinting for this site will fix the issue."
A security tool is asking you to weaken your privacy protection so it can fingerprint your device. That's backwards.
hacktivis.me Cloudflare Turnstile Requiring Fingerprintable Webgl
What fingerprinting means
Browser fingerprinting recognizes your device without cookies. Instead of tagging you directly, a site measures small details about your setup, including graphics hardware, fonts, screen size, and browser math. Stack enough clues together and the device starts to look unique.
The signal here is WebGL, the part of your browser that draws 3D graphics. Ask the browser about WebGL and it may name the exact graphics card and driver underneath. That is highly identifying, which is why hardened browsers fake it or hide it. Basic stuff. Still sensitive.
hacktivis.me Cloudflare Turnstile Requiring Fingerprintable Webgl
Who gets locked out
The person who hit the wall was running WebKitGTK, a browser built on the same open-source engine as Safari. It masked the WebGL details Turnstile wanted, so the check never got its answer. The page stayed shut.
The blogger says WebKit has blocked this kind of fingerprinting for years, though that is disputed. Others point out WebGL fingerprinting still works on Safari, just with noise added. The blogger suspects Safari gets a quiet pass, but that is a guess.
Firefox is sneakier. It passes Turnstile by default, so most users never notice anything. The trouble starts only if you turn on resistFingerprinting, a setting that stays off even when Firefox tracking protection is set to "Strict." Turn it on and Turnstile may tag you with a "Canvas Randomization Detected" notice.
On Hacker News, some users with resistFingerprinting said Turnstile still worked, while others watched it fail on Android. So this mostly catches the most locked-down setups, which is exactly the wrong crowd for a bot filter to punish.
The part that stings
The contradiction is hard to miss. A product pitched as privacy-friendly is leaning on browser fingerprinting, one of the most identifying tricks on the web, then asking people to switch off their defenses to get in. Give me a break.
Cloudflare's defense, spelled out in its privacy terms, is that these signals catch bots, not people, and that it can't directly identify you from them. But "we don't sell it to advertisers" is not the same as "we don't fingerprint you." Same raw material. Different excuse!
What you can do
There are not many options if a site you need sits behind Turnstile. You can keep privacy settings high and accept that some pages may refuse you. You can loosen them for one site. Or you can ride Firefox's default setup and hope Cloudflare doesn't tighten the screws tomorrow. What choice is that?
The bigger worry is the precedent. When a gatekeeper this common treats a locked-down browser as suspicious, "verify you're human" starts drifting toward "show us your browser." Same box. Whole new deal.
hacktivis.me Cloudflare Turnstile Requiring Fingerprintable Webgl




