Behavioural biometrics: how sites profile you by the way you move, not just your device
Most people who look into browser fingerprinting stop at the device layer: canvas hashes, fonts, WebGL renderer strings, timezone mismatches. That’s the layer anti-detect browsers are built to address. But there’s a second layer running underneath it that has nothing to do with your device and everything to do with you. It’s called behavioural biometrics, and it’s a bigger part of modern fraud and multi-accounting detection than most people testing these tools realize.
I run proxy infrastructure and test anti-detect browsers against real platforms for multi-accounting work. The device-fingerprint conversation is well covered elsewhere. This article is about the layer that gets ignored: how a site learns to recognize how you interact, independent of what browser profile you’re sitting behind.
What behavioural biometrics actually measures
Device fingerprinting asks “what is this machine.” Behavioural biometrics asks “what is this person doing right now, and does it look like the last thousand people who did the same thing.” It’s a continuous signal, collected passively while you use a page, not a one-time snapshot taken at page load.
The common signals a site can collect through nothing more than JavaScript event listeners:
- Mouse movement. Path curvature, acceleration and deceleration between clicks, the small jitter every human hand produces, and how you approach a target (overshoot and correct, versus a dead-straight line).
- Keystroke dynamics. Dwell time (how long a key is held) and flight time (the gap between releasing one key and pressing the next). This is stable enough per person that it’s used as a standalone authentication factor in some banking and enterprise login systems.
- Scroll behaviour. Scroll speed, whether you scroll in bursts or a steady drift, and how often you scroll back up to re-read something.
- Touch and gesture data on mobile. Pressure, contact area, swipe velocity, and the angle of a finger touch, all reported through the Pointer Events and Touch Events APIs.
- Device motion. Accelerometer and gyroscope readings on phones, which pick up the tiny involuntary movements of a hand holding a device versus a device sitting flat on a rig.
- Timing patterns across a whole session. How long you dwell on a product page before adding to cart, whether your click-to-scroll ratio looks like reading or like a script executing a checklist.
None of this requires special permissions. It’s collected with standard mousemove, keydown, touchstart, and devicemotion listeners, often bundled into a script the site loads from a third-party fraud vendor or session-replay tool.
Who’s actually running this, and why
Session-replay tools like FullStory and Hotjar were built for UX research, but the same event stream they capture for “watch how users navigate the checkout page” is exactly what a fraud model needs to build a behavioural fingerprint. Dedicated fraud and bot-management vendors, names like DataDome, Forter, Sift, and BioCatch, sell products specifically built around this signal, usually layered on top of device fingerprinting and IP reputation rather than replacing it.
The reason platforms want this layer isn’t abstract. Device fingerprints can be reset. A new browser profile, a cleaned cache, a different canvas noise seed, and the device-level signal starts over. But the person operating the mouse doesn’t get reset along with it. If the same behavioural pattern shows up across twenty “different” accounts that all supposedly belong to different people, that’s a much stronger signal than any single device fingerprint, because it’s expensive to fake and it doesn’t change when you rotate hardware identifiers.
This is also why platforms increasingly correlate signals rather than trust one in isolation: a clean device fingerprint sitting on top of a behavioural pattern that repeats across accounts is itself a flag.
Why fingerprint spoofing doesn’t reach this layer
This is the part that gets misunderstood constantly, including by people selling anti-detect tools as more comprehensive than they are. Multilogin, GoLogin, Kameleo, AdsPower, and Dolphin Anty all work by intercepting and modifying the browser APIs a site queries to build a device fingerprint: canvas rendering output, WebGL parameters, installed fonts, navigator.hardwareConcurrency, screen resolution, timezone, and so on. That’s real engineering and it does change what a fingerprinting script reads back.
None of that touches how your mouse moves. The pointer event stream a site receives is generated by the actual input hardware and the actual person moving it, not by anything the browser profile layer can rewrite. A spoofed canvas hash and a real human hand produce two completely separate signals, and only one of them is under the anti-detect browser’s control.
This matters most for anyone running multiple profiles through automation. Scripted mouse movement tends to have a signature: paths that are too geometrically direct, uniform velocity where a human hand naturally accelerates and decelerates, click timing that’s suspiciously consistent down to the millisecond, or, in cruder RPA setups, movement that jumps straight to a coordinate with no path captured at all. A behavioural biometrics model doesn’t need to know anything about your browser fingerprint to flag that pattern. It just needs to see the same statistically unusual mouse signature repeating across accounts that a device-fingerprint check already passed as “distinct.”
I’m not going to walk through how to defeat any specific vendor’s model here. Setting that aside as out of scope, the honest technical point stands regardless: no anti-detect browser I’ve tested advertises behavioural biometrics evasion as part of its product, and none of them can, because the signal originates outside the browser process entirely.
What actually changes the picture, and what doesn’t
The closest thing to a mitigating factor is also the least exciting one: a real, different human operating each profile, at a normal pace, without scripted interaction. That’s not a feature of any tool, it’s just what happens when a person genuinely uses a browser instead of a script driving it. It doesn’t make an account undetectable and it doesn’t override a platform’s other signals, it just means the behavioural layer isn’t handing the platform a second, independent reason to link accounts that the device layer already tried to separate.
What doesn’t help, no matter what a sales page claims: “human-like” mouse movement libraries bolted onto automation frameworks. Some of these interpolate a Bezier curve between two points and call it done. Real human movement has irregular micro-corrections, varies session to session, and correlates with what’s actually on screen, not just start and end coordinates. A modeled curve is still a model, and behavioural biometrics vendors train specifically against synthetic movement because it’s the most common thing they see.
It’s also worth being clear about what these tools are for and aren’t for. Anti-detect browsers exist to manage separate, legitimate identities and business use cases across a device fingerprint layer, things like agencies running client ad accounts, or store operators managing storefronts across marketplaces. None of this is a workaround for account restrictions tied to fraud, stolen payment methods, or identity misuse, and behavioural biometrics is one of the tools platforms specifically built to catch exactly that kind of abuse. Nothing in this article, and no product in this category, changes that.
The honest summary
Behavioural biometrics is a passive, continuous layer that profiles the person, not the device. It sits alongside, not underneath, the fingerprinting layer that anti-detect browsers were built to manage. Spoofing canvas output, WebGL strings, or font lists changes nothing about how your mouse moves or how your fingers hit the keys, because that data never passes through the code an anti-detect browser controls. Any product claiming to solve both layers in one tool is overselling. Testing the fingerprint layer honestly still matters, but it’s only half the picture.
If you want the rest of what I’ve actually tested on the fingerprinting side, hands-on, no affiliate spin, start here.
Get new guides and videos first — join the Telegram channel.