You finally did it. You cleared your cookies, switched to incognito, and felt a tiny surge of privacy victory. Then Chrome quietly rolled out a feature that makes all of that pointless.
Google just announced what they’re calling the best protection yet against account takeovers. It uses your device’s TPM (Trusted Platform Module) — a dedicated hardware chip — to cryptographically bind your login to your specific machine. Even if a hacker steals your password, they can’t log in without your physical device. It’s brilliant. It’s secure. And it’s the most dangerous privacy tool ever deployed at scale.
Here’s the part nobody in the press is talking about: the same hardware that protects your accounts also brands your browser with a permanent, unspoofable fingerprint. Clearing cookies? Useless. Incognito mode? Doesn’t help. This identifier lives in the silicon of your machine, and websites can request it without your knowledge.
Let’s be clear about what’s happening. The TPM-backed authentication creates a deterministic, static identifier that is tied to your hardware. That means every website you visit can — with a simple browser API call — know it’s the same person, even if you’ve never given them your email, never logged in, never accepted a cookie. Chrome is building a global surveillance network, and it’s handing the keys to every advertiser and data broker on the planet.
I’ve seen this pattern before. Every time a company says ‘this is purely for security,’ they’re laying the groundwork for a tracking system that makes cookies look like a privacy paradise. The difference here is that you can’t opt out. You can’t clear it. You can’t spoof it. This isn’t a feature — it’s a hardware-level jail that Google is building for your digital identity.
Some will argue that it’s no different from a TPM-backed passkey. They’re wrong. Passkeys are opt-in and tied to specific services. This is a blanket identifier that any site can try to read. Others will say the security benefits are worth it. But that’s a false choice. We can have strong account protection without creating the most invasive fingerprinting tool in history. Google just chose not to separate the two.
So what do you do? You can’t uninstall it. You can’t disable it. The only real option is to stop using Chrome entirely, or to accept that every move you make online will be tracked by a mechanism that even the most paranoid privacy practices can’t evade. The question isn’t whether you’re being tracked. The question is whether you’ll notice before it’s too late.
FAQ
Q: Isn't this just like a passkey? Why is it more dangerous?
A: Passkeys are tied to specific services you opt into. This feature creates a device-level identifier that any website can access via browser APIs, making it a universal tracker with no user consent required.
Q: What's the practical implication for me as a Chrome user?
A: Your online activity can now be linked to your specific hardware permanently, even in incognito mode. Advertisers and data brokers can build exhaustive profiles of you that you cannot erase by clearing cookies or using privacy tools.
Q: Isn't the security benefit worth the privacy cost?
A: That's a false binary. Google could have implemented TPM-backed security without exposing a hardware identifier to third parties. They chose not to, which suggests the tracking capability is a feature, not a bug.