BLOG
DOC · ARTICLE

Why Changing IP Still Gets You Detected as the Same Machine? The TCP/IP Fingerprint Deception

Simply changing your IP address is insufficient for true anonymity because modern anti-fraud systems delve deeper into your TCP/IP stack's 'fingerprint,' such as system clock skew and other packet characteristics, to identify the originating device, even with a new IP.

Simply changing your IP address is insufficient for true anonymity because modern anti-fraud systems delve deeper into your TCP/IP stack's 'fingerprint,' such as system clock skew and other packet characteristics, to identify the originating device, even with a new IP. This is the primary reason why many users still get detected when using basic proxy routing routers or rotating proxies while running multiple accounts on the same physical device.

Why is Changing Just the IP Address Not Enough for True Anonymity?

Changing only the IP address is akin to changing a car's license plate while keeping the same vehicle with all its scratches, scent, and other identifying features. The IP is just one of many layers of identification used by anti-fraud systems. Even if you use a SOCKS5 proxy or HTTP proxy to change your public IP address, your device still emits a host of other identifying signals at lower layers of the OSI model, particularly the Network Layer and Transport Layer. These signals form a unique "fingerprint" that helps systems recognize you as the same entity, regardless of the IP.

TCP/IP Fingerprinting: How Clock Skew and p0f Work?

TCP/IP fingerprinting is one of the most powerful device identification techniques, operating at the transport layer. Every device has its own system clock, and when communicating over a network, it embeds a timestamp value into the TCP timestamp (TSval) field in each TCP packet. The issue is that no two system clocks run exactly alike; they always exhibit a certain drift, known as clock skew. This drift is unique to each physical device, depending on its hardware and operating system.

Detection systems can analyze the sequence of these TSval values to calculate the device's clock skew. Although TSval values change continuously, their rate of change (the skew) is a characteristic constant. When multiple connections from different IPs (due to proxy usage) exhibit the same characteristic clock skew, it's a strong signal indicating that all those connections originate from the same physical device. Tools like p0f are designed to analyze TCP/IP stack characteristics (such as TCP timestamp, initial sequence numbers, window sizes, TCP flags, initial TTL) to infer the operating system and even the type of source device without looking at the IP. This is effective even when using multiple IPs through a proxy router or a rotating 5G proxy service.

Beyond IP: Other Network Layer Identifiers

Beyond clock skew, numerous other factors at the network and transport layers are exploited by anti-fraud systems:

TLS Fingerprinting (JA3/JA4): When establishing an encrypted connection (HTTPS), the browser or application sends a set of technical parameters about how it wishes to encrypt (cipher suites, elliptic curves, extensions). This sequence of parameters forms a unique TLS "fingerprint," often referred to as JA3 (for TLS 1.2) or JA4 (for TLS 1.3). If multiple accounts use different IPs but share the same JA3/JA4 fingerprint, it's a clear indicator of using an identical device or software configuration. DNS Leaks and EDNS Client Subnet: Improper proxy configuration can lead to DNS leaks, meaning DNS requests still go directly from your real IP instead of through the proxy. Even if DNS is routed through the proxy, public DNS services like Google DNS often use EDNS Client Subnet to send a portion of your IP address to the destination server, helping them optimize routing or content delivery, but inadvertently revealing approximate location information. Using DoH/DoT (DNS over HTTPS/TLS) can mitigate this but requires proper configuration to ensure coherence with the proxy IP. BSSID and WiFi Positioning System (WPS): If your device has a WiFi connection, it can scan and remember surrounding BSSIDs (MAC addresses of WiFi access points). Location services like Google Location Services or Apple Location Services collect this data and use it to determine your geographical location, often more accurately than IP alone. If you run multiple accounts on the same device, and it consistently sees the same set of BSSIDs, systems can easily link these accounts to the same physical location. MAC Address Entropy and Other Headers: MAC address randomization has become common, but it's not always perfectly implemented. Additionally, entropy in other packet header fields or default network stack values can reveal hardware type or operating system. Professional systems also check the ASN reputation of the IP and dMAP RTT (Round Trip Time) to assess latency and the suitability between the IP and the declared geographical location.

The Challenge of "Multi-WiFi Routers": Undeniable Colocation Signals

The model of using a single proxy routing router to broadcast multiple WiFi networks (each assigned a proxy) and run multiple accounts/devices simultaneously from one point is a common pitfall. While each connection might have a different IP, they all originate from the same physical device—the router itself. This generates a significant amount of undeniable colocation signals:

Unified Clock Skew: All TCP/IP streams passing through the router will carry the clock skew of the router itself or the end device connecting to it. If the router does not normalize the TCP timestamp for each proxy, all streams will exhibit the same clock drift, making them easily correlated by anti-fraud systems. Similar Network Stack Characteristics: The router might forward the network stack characteristics of the end device without altering them. Even if the router attempts to spoof, creating multiple completely independent and uncorrelated network stacks on the same hardware device is extremely complex. Physical WiFi Location: If a router broadcasts multiple SSIDs, all those SSIDs share the same physical location and will see the same set of surrounding BSSIDs. Anti-fraud systems can use WiFi Positioning System to determine that all accounts are operating from the same physical location, regardless of the IP. Airtime Contention: In a WiFi environment, all devices share the same wireless channel. If too many devices operate simultaneously on the same router/AP, airtime contention can occur, affecting performance and creating traffic patterns that can be detected by deep packet inspection (DPI) systems.

In essence, the model of a router broadcasting multiple WiFi networks and cramming multiple phones/computers into one spot to operate multiple accounts simultaneously is ineffective and unprofessional from a technical standpoint. It consistently leaves colocation signals and layer inconsistencies, making it highly susceptible to detection by anti-fraud systems.

How to Self-Check Your Device's "Fingerprint"?

You can self-check some aspects of your device's "fingerprint" using basic network tools. For example, running `ping` to a server from multiple devices or from the same device via different proxies and comparing the Round Trip Time (RTT), or using tools like `p0f` (if you have access to network traffic) to see how your operating system is identified. Additionally, anonymity checking websites like `browserleaks.com` or `ip-api.com` can reveal information about your DNS, WebRTC, and timezone, helping you assess your current level of identity concealment.

Comprehensive Solution from RouterSocks5.Net: Building Unique Digital Identities

At RouterSocks5.Net, we understand that merely changing the IP is not enough. Our solution focuses on building and maintaining a complete, isolated, and coherent digital identity for each task or account. Instead of cramming multiple identities onto a single physical device, we follow a rotation model: each account/task is assigned an independent identity and used sequentially.

Our hardware routers are specifically designed to address these issues at the network and packet level:

TCP/IP Stack Normalization: Our custom firmware intervenes at the packet layer to normalize TCP/IP stack characteristics, including TCP timestamp and TCP flags, so they are consistent with a simulated OS and device, or to ensure they have appropriate entropy, eliminating the router's characteristic clock skew. Secure DNS Management: We implement DoH/DoT and ensure DNS requests are securely routed through the proxy, matching the proxy IP's geographical location, and blocking EDNS Client Subnet to prevent real location leaks. Virtualised WiFi Environment & BSSID: For scenarios requiring a WiFi environment, our routers can create virtual WiFi environments with spoofed BSSIDs that match the proxy's geographical location, while simultaneously blocking the scanning and transmission of real BSSIDs from the physical surroundings. This resolves the WiFi Positioning System colocation detection problem. Low-Level Leak Blocking: We block potential information leakage channels such as WebRTC, traceroute, and LAN scanning, ensuring no signals about the internal physical environment are exposed. * Advanced Anti-Detection Features: Combined with features like timezone spoofing, geo-information matching the IP, and randomized MAC addresses from millions of vendor codes, we create a credible digital identity profile. You can learn more about how we help with effective anti-fingerprinting.

When a task is completed, that identity is "stored" and can be "restored" intact later. This completely eliminates colocation signals and ensures each session is an independent entity. To experience this solution, explore our specialized proxy routers or learn about proxies for MMO.

Limitations and Things to Note

No solution is 100% absolute in the ever-evolving fight against fraud. Advanced systems can use User Behavior Analytics and Machine Learning to look for unusual behavioral patterns or correlations between accounts, even if technical fingerprints have been cleaned. For example, typing speed, mouse movement patterns, or repetitive actions can be identifying factors. Our solution focuses on eliminating hard technical traces at the network and transport layers but cannot fully control end-user behavior or browser-level fingerprinting (via JavaScript/Canvas) without the aid of specialized software on the end device.

Quick Summary

IP Change Insufficient: Anti-fraud systems identify devices via TCP/IP "fingerprints" and other network layer characteristics, not just the IP. Clock Skew is Key: System clock drift (TCP timestamp) is unique to each device, linking multiple different IP connections to a single source. Multiple Identifiers: TLS Fingerprinting (JA3/JA4), DNS leaks, BSSID/WPS, and MAC Address entropy also reveal true identities. "Multi-WiFi Router" Ineffective: This model generates strong colocation signals, easily detected due to shared clock skew, network stack characteristics, and physical WiFi location. * RouterSocks5.Net Solution: Provides specialized hardware routers to build and manage independent digital identities, normalize TCP/IP stacks, secure DNS management, and virtualize WiFi environments to eliminate deep identification signals.