Browser fingerprinting / Panopticlick: <https://ssd.eff.org/module/what-fingerprinting> <https://panopticlick.org/>
On-device identifiers --- Google AdID (GAID), Apple IDFA, etc.: <https://developer.transmitsecurity.com/guides/risk/secure_de...> <https://geraguard.com/blog/how-device-fingerprinting-works-m...> <https://alejandrocordon.com/blog/2025/01/18/unique-identifie...>.
And BYW, browser headers can even be a violation if it's determined that you are using them for tracking users in a way that violates ePrivacy demands.
It's still a cookies thing.
Browser fingerprinting / Panopticlick: <https://ssd.eff.org/module/what-fingerprinting> <https://panopticlick.org/>
On-device identifiers --- Google AdID (GAID), Apple IDFA, etc.: <https://developer.transmitsecurity.com/guides/risk/secure_de...> <https://geraguard.com/blog/how-device-fingerprinting-works-m...> <https://alejandrocordon.com/blog/2025/01/18/unique-identifie...>.