<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Client Hints</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Client_Hints"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Client_Hints rootpage-Client_Hints skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Client Hints</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p class="mw-empty-elt">
</p>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */
.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}
/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><caption class="infobox-title summary">Client Hints</caption><tbody><tr><th scope="row" class="infobox-label">International standard</th><td class="infobox-data">
<ul><li><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */
.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}
/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a> <a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc8942">8942</a></li>
<li><a rel="nofollow" class="external text" href="https://wicg.github.io/ua-client-hints/">User-Agent Client Hints</a> - Draft Community Report</li></ul>
</td></tr><tr><th scope="row" class="infobox-label">Developed by</th><td class="infobox-data"><a href="Google" title="Google">Google</a>, <a href="W3C" class="mw-redirect" title="W3C">W3C</a></td></tr><tr><th scope="row" class="infobox-label">Website</th><td class="infobox-data url"><a rel="nofollow" class="external free" href="https://wicg.github.io/ua-client-hints/">https://wicg.github.io/ua-client-hints/</a></td></tr></tbody></table>
<p><b>Client Hints</b> is an extension to the <a href="HTTP" title="HTTP">HTTP</a> protocol that allows servers to ask the client (usually a <a href="Web_browser" title="Web browser">web browser</a>) for information about its configuration. This helps the server tailor its responses to the client; for example, a server can choose to send a smaller image if a client advertises that they have a very small screen. The client can choose to respond to this request by advertising the requested information about itself by sending the data using a specific part of the HTTP protocol called <a href="List_of_HTTP_header_fields" title="List of HTTP header fields">HTTP header fields</a> or by exposing the same information to the <a href="JavaScript" title="JavaScript">JavaScript</a> code being executed on a web page.
</p><p>Proposed by <a href="Google" title="Google">Google</a> engineers in 2013, Client Hints was designed as a <a href="Internet_privacy" title="Internet privacy">privacy</a>-focused alternative to <a href="User-Agent_header" title="User-Agent header">user-agent headers</a>. This was done as part of an initiative by Google called <a href="Privacy_Sandbox" title="Privacy Sandbox">Privacy Sandbox</a>. User-agent headers are code snippets sent by a client to identify itself to a server. While initially intended for statistical purposes, these headers had increasingly become a tool for tracking users across websites. Client Hints aimed to address this issue by providing a more controlled way to share the same information. Despite the focus on privacy, the initial design of Client Hints faced criticism from other browsers. One of the primary concerns that was brought up was that the protocol could enable new forms of <a href="Web_tracking" title="Web tracking">tracking</a> by third-party domains. Third-party domains are web servers not owned by the website that load resources like images and script files. Despite these concerns, Chrome implemented support for Client Hints in August 2020. By 2024, over 75% of web users had browsers that supported Client Hints.
</p><p>Privacy researchers have since raised concerns that Client Hints is primarily being used by JavaScript code which <a href="Web_tracking" title="Web tracking">tracks</a> users. In 2023, a study from <a href="KU_Leuven" title="KU Leuven">KU Leuven</a> and <a href="Radboud_University_Nijmegen" title="Radboud University Nijmegen">Radboud University</a> found that when examining the top 100,000 websites on the internet, most accesses of Client Hints came from JavaScript code used for tracking and <a href="Advertising" title="Advertising">advertising</a> purposes.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Background">Background</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */
.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}
/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Main article: <a href="User-Agent_header" title="User-Agent header">User-Agent header</a></div>
<p>In 1992, an extension to the <a href="HTTP" title="HTTP">HTTP</a> protocol was introduced adding a <code>User-Agent</code> <a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP Header</a> which was sent from the client to the server and contained a simple string identifying the name of the client and its version. The header was meant purely for statistical purposes and for tracking down clients that violated the protocol. Since then, User-Agent headers have become increasingly more complex, and has started containing significant uniquely identifiable information about the user. Often, this information is used to perform <a href="Device_fingerprint" title="Device fingerprint">browser fingerprinting</a>, allowing sites to track users across sites passively without having to load any <a href="JavaScript" title="JavaScript">JavaScript</a> for the user.<sup id="cite_ref-FOOTNOTESenolAcar202391_1-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202391-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>The original draft for the Client Hint specification was proposed in 2013 by engineers at <a href="Google" title="Google">Google</a>. The specifications became an <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">Internet Engineering Task Force</a> (IETF) draft in November 2015. In 2021, the specification was upgraded to the status of an experimental <a href="Request_for_comment" class="mw-redirect" title="Request for comment">request for comment</a> (RFC).<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-0" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> This designation indicated that the IETF had accepted the Client Hints specification as an <a href="Internet_Standard" title="Internet Standard">internet standard</a>, but it either still had unresolved questions or had not yet gained widespread adoption in the internet.<sup id="cite_ref-FOOTNOTEHoffmanHarris2006_3-0" class="reference"><a href="#cite_note-FOOTNOTEHoffmanHarris2006-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Around the same time, the specifications for how web browser would be handling HTTP Client Hints on the web was published as a draft in a <a href="World_Wide_Web_Consortium" title="World Wide Web Consortium">W3C</a> Community Group Report.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-1" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>In 2020, Google announced their intention to deprecate <a href="User-Agent_header" title="User-Agent header">user-agent</a> (UA) declaration by the browser.<sup id="cite_ref-FOOTNOTECimpanu2020_4-0" class="reference"><a href="#cite_note-FOOTNOTECimpanu2020-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> This deprecation was part of a broader initiative by Google to make changes to the web that allow <a href="Website" title="Website">websites</a> to access user information without compromising <a href="Privacy" title="Privacy">privacy</a> called <a href="Privacy_Sandbox" title="Privacy Sandbox">Privacy Sandbox</a>. They cited Client Hints as a privacy-preserving alternative to user-agent headers since they allowed for a more controlled way of sharing the same information.<sup id="cite_ref-FOOTNOTESenolAcar202392,_93_5-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202392,_93-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> The initial Client Hints proposal, however, was met with pushback from other <a href="Browser_engine" title="Browser engine">browsers</a> due to privacy concerns. In 2019, <a href="Brave_(web_browser)" title="Brave (web browser)">Brave</a> raised concerns about the initial proposal, citing ways in which it could be used to track users on the internet.<sup id="cite_ref-FOOTNOTECimpanu2019_6-0" class="reference"><a href="#cite_note-FOOTNOTECimpanu2019-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> <a href="Mozilla" title="Mozilla">Mozilla</a>, the company that makes <a href="Firefox" title="Firefox">Firefox</a>, initially classified the proposal as harmful, and <a href="Apple_Inc." title="Apple Inc.">Apple</a>, the company that makes <a href="Safari_(web_browser)" title="Safari (web browser)">Safari</a> also took a negative stance against the proposal.<sup id="cite_ref-FOOTNOTESenolAcar202396_7-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202396-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Despite these concerns, <a href="Chromium_(web_browser)" title="Chromium (web browser)">Chrome</a> implemented support for HTTP Client Hints in August 2020. While the deprecation of the UA strings was delayed due to the <a href="COVID-19_pandemic" title="COVID-19 pandemic">COVID-19 pandemic</a>, this process was completed in February 2023.<sup id="cite_ref-FOOTNOTESenolAcar202393_8-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202393-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p><p>Since their initial opposition, Mozilla has updated their stance to neutral<sup id="cite_ref-FOOTNOTESenolAcar202396_7-1" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202396-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> and Brave has synchronized its implementation of Client Hints with that of Chrome.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-2" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> As of 2024, over 75% of all web users use browsers that support Client Hints.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-3" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Mechanism">Mechanism</h2></div>
<p>The Client Hints protocol defines two entities: a <a href="User_agent" title="User agent">user agent</a> (UA) (typically a <a href="Web_browser" title="Web browser">browser</a>) and a <a href="Server_(computing)" title="Server (computing)">server</a>. These two entities communicate with each other to negotiate what kind of content should be served to the user.<sup id="cite_ref-FOOTNOTEGrigorikWeiss2021_9-0" class="reference"><a href="#cite_note-FOOTNOTEGrigorikWeiss2021-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> The process involves the server sending the UA a response with an <code>Accept-CH</code> <a href="HTTP_header" class="mw-redirect" title="HTTP header">HTTP Header</a>, containing a list of Client Hint HTTP headers that it requires.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-4" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Subsequently, the UA is expected to return the requested client hints with each subsequent response, provided it supports those hints. These headers are then used by the server to make decisions on what kind of content to serve the UA.<sup id="cite_ref-FOOTNOTEGrigorikWeiss2021_9-1" class="reference"><a href="#cite_note-FOOTNOTEGrigorikWeiss2021-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> If the UA does not understand or support a particular client hint then the UA is instructed to ignore the particular client hint. In cases where a specific Client Hint cannot be <a href="Cache_(computing)" title="Cache (computing)">cached</a>, the server must specify the applicable client hints headers in a separate <code>Vary</code> header sent to the UA. This ensures that caching mechanisms understand that responses can vary based on different client hint values.<sup id="cite_ref-FOOTNOTEGrigorikWeiss2021_9-2" class="reference"><a href="#cite_note-FOOTNOTEGrigorikWeiss2021-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> For client hints that specifically identify a browser, additional random browser identifiers are included as <a href="Grease_(networking)" class="mw-redirect" title="Grease (networking)">grease</a> in order to prevent users of the protocol from relying on browser specific idiosyncratic behaviours.<sup id="cite_ref-FOOTNOTETaylorWeiss2024_10-0" class="reference"><a href="#cite_note-FOOTNOTETaylorWeiss2024-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-FOOTNOTESenolAcar202395_11-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202395-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p><p>For UAs that allow <a href="JavaScript" title="JavaScript">JavaScript</a>, an additional option is available through the <code>navigator.userAgentData</code> JavaScript <a href="API" title="API">API</a>. This API enables JavaScript to retrieve the same information as provided by the Client Hints headers.<sup id="cite_ref-FOOTNOTESenolAcar202395_11-1" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202395-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> The API separates the data it provides into two types: low-<a href="Entropy_(information_theory)" title="Entropy (information theory)">entropy</a> data and high-entropy data. Low-entropy data corresponds to information that is likely to be similar across a large group of users, such as the platform on which the browser is running and the brand of the browser. In contrast, high-entropy data may vary significantly between users, including details like the exact version number of the browser and the model of the user's device. Low entropy data is included in the API as object parameters whereas high entropy data which can uniquely identify the user needs to be explicitly fetched by the client by calling the <code>getHighEntropyValues()</code> function in the API which allows the browser to ask for user permission or to perform additional checks.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Example">Example</h2></div><p>
To initiate a <a href="Content_negotiation" title="Content negotiation">content negotiation</a>, a HTTP server appends the <code>Accept-CH</code> header to the response of a HTTP request:</p><div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="kr">HTTP</span><span class="o">/</span><span class="m">1.1</span> <span class="m">200</span> <span class="ne">OK</span>
<span class="err">...</span>
Accept-CH: Viewport-Width
...
</pre></div><p>If the user-agent supports the viewport width client hint, the user-agent will append the <code>Viewport-Width</code> header in every subsequent request.</p><div class="mw-highlight mw-highlight-lang-http mw-content-ltr" dir="ltr"><pre><span class="nf">GET</span> <span class="nn">/gallery</span> <span class="kr">HTTP</span><span class="o">/</span><span class="m">1.1</span>
<span class="err">...</span>
Viewport-Width: 1920
...
</pre></div><p>The server can then use the information in the <code>Viewport-Width</code> header to make a decision about the kind of content to serve the client. For example, if the server has a particular image that is extremely large, the server can be configured to return a smaller image if the image does not fit the <a href="Viewport" title="Viewport">viewport</a>.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p><div class="mw-heading mw-heading2"><h2 id="Privacy_concerns">Privacy concerns</h2></div>
<p>When the Client Hints proposal was originally published, it was met with significant privacy concerns. Browser vendors like <a href="Brave_(web_browser)" title="Brave (web browser)">Brave</a> and <a href="Mozilla" title="Mozilla">Mozilla</a> pointed out that a particular provision in the initial draft of the proposal allowed websites to instruct the browser to provide Client Hint data to third-party domains. Third-party domains are domains that do not execute any JavaScript code, but rather load resources like images and script files.<sup id="cite_ref-FOOTNOTECimpanu2019_6-1" class="reference"><a href="#cite_note-FOOTNOTECimpanu2019-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> The provision in the initial draft would allow these third-party domains like <a href="Content_delivery_network" title="Content delivery network">content delivery networks</a> (CDNs) and <a href="Cloud_service_provider" class="mw-redirect" title="Cloud service provider">cloud service providers</a>. CDNs distribute website content across a <a href="Computer_network" title="Computer network">network</a> of geographically dispersed group of servers to improve the speed and reliability of the website. Cloud providers like <a href="Cloudflare" title="Cloudflare">Cloudflare</a> and <a href="Google_Cloud" class="mw-redirect" title="Google Cloud">Google Cloud</a> offer services like data storage, computing power, and infrastructure for websites and applications. These entities could track users across the web by instructing the browser to send Client Hint information to their servers alongside the original website.<sup id="cite_ref-FOOTNOTECimpanu2019_6-2" class="reference"><a href="#cite_note-FOOTNOTECimpanu2019-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-:4_14-0" class="reference"><a href="#cite_note-:4-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> Concerns were also raised that the Client-Hint proposal was too permissive and explicitly allowed for new privacy compromising information that could not be obtained by simply reading <a href="HTTP_headers" class="mw-redirect" title="HTTP headers">HTTP Headers</a> to be leaked to servers.<sup id="cite_ref-:4_14-1" class="reference"><a href="#cite_note-:4-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> Additionally, extensions that aim to preserve a user's privacy like the <a href="NoScript" title="NoScript">NoScript extension</a> also opposed the proposal on the grounds that it would make it significantly harder to prevent sites from <a href="https://en.wiktionary.org/wiki/exfiltrate" class="extiw external" title="wikt:exfiltrate">exfiltrating</a> privacy-compromising information about users.<sup id="cite_ref-FOOTNOTECimpanu2019_6-3" class="reference"><a href="#cite_note-FOOTNOTECimpanu2019-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>Since the adoption of Client Hints by major browsers like <a href="Google_Chrome" title="Google Chrome">Google Chrome</a> and <a href="Microsoft_Edge" title="Microsoft Edge">Microsoft Edge</a>, privacy researchers have raised concerns over their real-world use for tracking.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono202411_15-0" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono202411-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> A 2023 study by researchers from <a href="KU_Leuven" title="KU Leuven">KU Leuven</a> and <a href="Radboud_University_Nijmegen" title="Radboud University Nijmegen">Radboud University</a> found that out of the top 100,000 websites, 60% of JavaScript files loaded by web pages accessed the Client Hints <a href="JavaScript" title="JavaScript">JavaScript</a> APIs, with most being tracking and <a href="Advertising" title="Advertising">advertising</a> scripts, many of which came from <a href="Google" title="Google">Google</a>. Over 90% of these script files exfiltrated the obtained data to tracking domains.<sup id="cite_ref-FOOTNOTESenolAcar202399–100,_102_16-0" class="reference"><a href="#cite_note-FOOTNOTESenolAcar202399–100,_102-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> A subsequent study in May 2024 by researchers from the <a href="Hochschule_Bonn-Rhein-Sieg_University_of_Applied_Sciences" title="Hochschule Bonn-Rhein-Sieg University of Applied Sciences">Hochschule Bonn-Rhein-Sieg University of Applied Sciences</a> noted that while overall adoption of Client Hints amongst websites on the internet was low, a significant number of third-party domains known for tracking accessed HTTP Client Hints data.<sup id="cite_ref-FOOTNOTEWieflingHönscheidIacono202410_17-0" class="reference"><a href="#cite_note-FOOTNOTEWieflingHönscheidIacono202410-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Browser_sniffing" title="Browser sniffing">Browser sniffing</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Citations">Citations</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */
.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}
/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-FOOTNOTESenolAcar202391-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESenolAcar202391_1-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, p. 91.</span>
</li>
<li id="cite_note-FOOTNOTEWieflingHönscheidIacono20243-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-3"><sup><i><b>d</b></i></sup></a> <a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono20243_2-4"><sup><i><b>e</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFWieflingHönscheidIacono2024">Wiefling, Hönscheid & Iacono 2024</a>, p. 3.</span>
</li>
<li id="cite_note-FOOTNOTEHoffmanHarris2006-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEHoffmanHarris2006_3-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFHoffmanHarris2006">Hoffman & Harris 2006</a>.</span>
</li>
<li id="cite_note-FOOTNOTECimpanu2020-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTECimpanu2020_4-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFCimpanu2020">Cimpanu 2020</a>.</span>
</li>
<li id="cite_note-FOOTNOTESenolAcar202392,_93-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESenolAcar202392,_93_5-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, pp. 92, 93.</span>
</li>
<li id="cite_note-FOOTNOTECimpanu2019-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTECimpanu2019_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTECimpanu2019_6-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTECimpanu2019_6-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-FOOTNOTECimpanu2019_6-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFCimpanu2019">Cimpanu 2019</a>.</span>
</li>
<li id="cite_note-FOOTNOTESenolAcar202396-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTESenolAcar202396_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTESenolAcar202396_7-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, p. 96.</span>
</li>
<li id="cite_note-FOOTNOTESenolAcar202393-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESenolAcar202393_8-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, p. 93.</span>
</li>
<li id="cite_note-FOOTNOTEGrigorikWeiss2021-9"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTEGrigorikWeiss2021_9-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTEGrigorikWeiss2021_9-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-FOOTNOTEGrigorikWeiss2021_9-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFGrigorikWeiss2021">Grigorik & Weiss 2021</a>.</span>
</li>
<li id="cite_note-FOOTNOTETaylorWeiss2024-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTETaylorWeiss2024_10-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFTaylorWeiss2024">Taylor & Weiss 2024</a>.</span>
</li>
<li id="cite_note-FOOTNOTESenolAcar202395-11"><span class="mw-cite-backlink">^ <a href="#cite_ref-FOOTNOTESenolAcar202395_11-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-FOOTNOTESenolAcar202395_11-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, p. 95.</span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://developer.mozilla.org/en-US/docs/Web/API/NavigatorUAData/getHighEntropyValues">"NavigatorUAData: getHighEntropyValues() method - Web APIs"</a>. <i><a href="Mozilla_Developer_Network" class="mw-redirect" title="Mozilla Developer Network">Mozilla Developer Network</a></i>. 2024-07-26<span class="reference-accessdate">. Retrieved <span class="nowrap">2024-09-21</span></span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://developer.chrome.com/docs/privacy-security/user-agent-client-hints">"Improving user privacy and developer experience with User-Agent Client Hints"</a>. Privacy & Security. <i>Chrome for Developers</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240602071702/https://developer.chrome.com/docs/privacy-security/user-agent-client-hints">Archived</a> from the original on 2024-06-02<span class="reference-accessdate">. Retrieved <span class="nowrap">2024-06-02</span></span>.</cite></span>
</li>
<li id="cite_note-:4-14"><span class="mw-cite-backlink">^ <a href="#cite_ref-:4_14-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-:4_14-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://brave.com/web-standards-at-brave/1-client-hints/">"Brave's Concerns with the Client-Hints Proposal"</a>. <i>Brave</i>. 2019-05-09. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240626230134/https://brave.com/web-standards-at-brave/1-client-hints/">Archived</a> from the original on 2024-06-26<span class="reference-accessdate">. Retrieved <span class="nowrap">2024-06-02</span></span>.</cite></span>
</li>
<li id="cite_note-FOOTNOTEWieflingHönscheidIacono202411-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono202411_15-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFWieflingHönscheidIacono2024">Wiefling, Hönscheid & Iacono 2024</a>, p. 11.</span>
</li>
<li id="cite_note-FOOTNOTESenolAcar202399–100,_102-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTESenolAcar202399–100,_102_16-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFSenolAcar2023">Senol & Acar 2023</a>, pp. 99–100, 102.</span>
</li>
<li id="cite_note-FOOTNOTEWieflingHönscheidIacono202410-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-FOOTNOTEWieflingHönscheidIacono202410_17-0">^</a></b></span> <span class="reference-text"><a href="#CITEREFWieflingHönscheidIacono2024">Wiefling, Hönscheid & Iacono 2024</a>, p. 10.</span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading3"><h3 id="Sources">Sources</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1239549316">
/* start https://en.wikipedia.org/ */
.mw-parser-output .refbegin{margin-bottom:0.5em}.mw-parser-output .refbegin-hanging-indents>ul{margin-left:0}.mw-parser-output .refbegin-hanging-indents>ul>li{margin-left:0;padding-left:3.2em;text-indent:-3.2em}.mw-parser-output .refbegin-hanging-indents ul,.mw-parser-output .refbegin-hanging-indents ul li{list-style:none}@media(max-width:720px){.mw-parser-output .refbegin-hanging-indents>ul>li{padding-left:1.6em;text-indent:-1.6em}}.mw-parser-output .refbegin-columns{margin-top:0.3em}.mw-parser-output .refbegin-columns ul{margin-top:0}.mw-parser-output .refbegin-columns li{page-break-inside:avoid;break-inside:avoid-column}@media screen{.mw-parser-output .refbegin{font-size:90%}}
/* end https://en.wikipedia.org/ */
</style><div class="refbegin" style="">
<ul><li><cite id="CITEREFSenolAcar2023" class="citation book cs1">Senol, Asuman; Acar, Gunes (26 November 2023). <a rel="nofollow" class="external text" href="https://dl.acm.org/doi/10.1145/3603216.3624965">"Unveiling the Impact of User-Agent Reduction and Client Hints: A Measurement Study"</a>. <a rel="nofollow" class="external text" href="https://repository.ubn.ru.nl/handle/2066/298872"><i>Proceedings of the 22nd Workshop on Privacy in the Electronic Society</i></a>. ACM. pp. <span class="nowrap">91–</span>106. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1145%2F3603216.3624965">10.1145/3603216.3624965</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a> <bdi>979-8-4007-0235-8</bdi>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240626230404/https://repository.ubn.ru.nl/handle/2066/298872">Archived</a> from the original on 26 June 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">25 June</span> 2024</span>.</cite></li>
<li><cite id="CITEREFHoffmanHarris2006" class="citation report cs1">Hoffman, Paul E.; Harris, Susan R. (1 September 2006). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/rfc4677/">The Tao of IETF - A Novice's Guide to the Internet Engineering Task Force</a> (Report). Internet Engineering Task Force.</cite></li>
<li><cite id="CITEREFGrigorikWeiss2021" class="citation cs1">Grigorik, I.; Weiss, Y. (February 2021). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc8942"><i>HTTP Client Hints</i></a>. <a href="Internet_Engineering_Task_Force" title="Internet Engineering Task Force">IETF</a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC8942">10.17487/RFC8942</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc8942">8942</a><span class="reference-accessdate">. Retrieved <span class="nowrap">11 February</span> 2021</span>.</cite></li>
<li><cite id="CITEREFTaylorWeiss2024" class="citation web cs1">Taylor, Mike; Weiss, Yoav, eds. (1 April 2024). <a rel="nofollow" class="external text" href="https://wicg.github.io/ua-client-hints/#grease">"User-Agent Client Hints § 6.2. GREASE-like UA Brand Lists"</a>. <i><a href="WICG" class="mw-redirect" title="WICG">WICG</a></i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20240618024808/https://wicg.github.io/ua-client-hints/#grease">Archived</a> from the original on 18 June 2024<span class="reference-accessdate">. Retrieved <span class="nowrap">26 June</span> 2024</span>.</cite></li>
<li><cite id="CITEREFCimpanu2019" class="citation web cs1">Cimpanu, Catalin (16 May 2019). <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/privacy-concerns-raised-about-upcoming-client-hints-web-standard/">"Privacy concerns raised about upcoming Client-Hints web standard"</a>. <i>ZDNET</i>. <a rel="nofollow" class="external text" href="https://web.archive.org/web/20231201065434/https://www.zdnet.com/article/privacy-concerns-raised-about-upcoming-client-hints-web-standard/">Archived</a> from the original on 1 December 2023<span class="reference-accessdate">. Retrieved <span class="nowrap">2 June</span> 2024</span>.</cite></li>
<li><cite id="CITEREFWieflingHönscheidIacono2024" class="citation arxiv cs2">Wiefling, Stephan; Hönscheid, Marian; Iacono, Luigi Lo (22 May 2024), "A Privacy Measure Turned Upside Down? Investigating the Use of HTTP Client Hints on the Web", <a href="ArXiv_(identifier)" class="mw-redirect" title="ArXiv (identifier)">arXiv</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://arxiv.org/abs/2405.13744">2405.13744</a></span> [<a rel="nofollow" class="external text" href="https://arxiv.org/archive/cs">cs</a>]</cite></li>
<li><cite id="CITEREFCimpanu2020" class="citation web cs1">Cimpanu, Catalin (14 January 2020). <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/google-to-phase-out-user-agent-strings-in-chrome/">"Google to phase out user-agent strings in Chrome"</a>. <i>ZDNET</i><span class="reference-accessdate">. Retrieved <span class="nowrap">6 December</span> 2024</span>.</cite></li></ul>
</div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://wicg.github.io/ua-client-hints/">User-Agent Client Hints – Draft Community Group Report, 9 February 2021</a></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-06-06" href="https://en.wikipedia.org/wiki/?title=Client_Hints&oldid=1294196229">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>