Deleting cookies isn’t enough to stop online tracking.
Phu Phung, associate professor of computer science at the University of Dayton, explains why.
Faculty Bio:
Dr. Phu Phung is an Associate Professor in the Department of Computer Science at the University of Dayton. He is the founder and director of the Intelligent Systems Security Lab, where his team developed MyWebGuard, a system for detecting and mitigating web-based privacy threats, including browser fingerprinting. He is also the University’s founding Point of Contact for the Cyber Defense program, designated an NSA National Center of Academic Excellence in Cyber Defense in 2022. His research addresses security across web, mobile, cyber-physical, and IoT systems, with recent work spanning AI and Machine Learning applications in cybersecurity. Dr. Phung has recently been promoted to Full Professor, effective August 2026.
Transcript:
Most people think clearing cookies protects their privacy online. It’s a reasonable assumption, but that’s only part of the story.
Websites can also track people using a technique called digital fingerprinting.
Instead of placing a file on your device, fingerprinting quietly collects small details about your browser and hardware, such as screen size, language settings, installed fonts, and other technical traits. Taken together, those details form a profile distinctive enough to identify you across the web.
Here’s what makes this kind of tracking so hard to stop: you can delete a cookie, but you cannot delete your screen resolution. You cannot erase the fact that your browser and device reveal certain traits every time you go online.
My research examines why so many privacy tools still miss this problem, and what better defenses might look like.
In our lab, we developed a system called MyWebGuard that tracks where web code originates and how it uses your data. We found this approach can catch privacy risks that some traditional blocking tools miss.
That distinction matters. Most current protections still rely on an all-or-nothing model — they either block a source entirely or allow it completely.
But today’s websites are more complicated than that.
A single webpage can carry useful features, harmless scripts, and invasive tracking code all at once. Blocking everything breaks the page. Allowing everything surrenders your privacy.
That is why my work explores a more precise approach.
Instead of shutting everything down, we can monitor sensitive browser actions in real time and restrict only the specific behaviors that enable hidden tracking without disrupting everything else.
The lesson is simple. If we want better online privacy, we need smarter protections — not just broader ones. In the modern web, fine-grained control may be our most effective defense.










