Device identification — also called Device ID, device authentication, or device fingerprinting — builds a "fingerprint" of the computer or device a user is on, to track activity and spot links between seemingly unrelated accounts.
What to evaluate
- Solutions should draw on multiple variables, not one or two, to build a reliable fingerprint
- Exact matches are easy; the real value is in the ability to work partial matches too
- Best used to catch repeat fraudsters, habitual friendly-fraud actors, and fraud rings
- An excellent complement to account login authentication
- Whether the vendor shares device intelligence across other companies
- It needs to work alongside other checks — not replace them
- Remember that legitimate consumers genuinely use multiple devices
How it works
Most collection is passive, gathered from ordinary site interactions. Some solutions use active identification requiring the user to accept tracking code — though a fraudster who notices it can simply remove it.
Where it's most useful
Cataloging device-to-account and account-to-device velocity, blacklisting devices tied to fraud, and blocking their future transactions. It's especially effective for digital products: stolen identity data can sail through standard checks, but using it from an unfamiliar device is exactly the kind of pattern this catches.