There is a moment for every product when continuing feels easier than stopping. You can always add another feature. Change another setting. Run another test. Increase the version number and tell yourself that the product is moving forward.
Stopping is more difficult. Stopping forces you to ask a question that developers, founders, and probably most people do not like asking: Are we still improving the product, or are we only adding more things to it?
Traceveil 1.3.2 will remain the stable version of the Chrome extension. This does not mean that Traceveil failed. It means that the extension took us as far as an extension can honestly take us. The next real version of Traceveil should not be another extension update. It should be a browser.
But it is not the product we are building next. Before we move deeper into the browser, we are starting work on Roamer ID: a local-first identity root controlled by the individual.
What Traceveil 1.3.2 Accomplished
When we started working on Traceveil, the objective was simple to describe and much harder to achieve. I wanted to make browser fingerprinting useless. Not slightly less effective. Not better on one test and worse on another. I wanted a browser that could not be silently recognized every time it visited a website. You want like as ummary descriThe extension improved many of the signals used for fingerprinting. It normalized the screen profile and timezone. It interfered with Canvas, WebGL, audio, Client Hints, fonts, and other browser surfaces. It reduced common tracking signals and made several identifying characteristics less precise or less stable.
With version 1.3.2, we also hardened the way Traceveil interacts with native browser APIs. Pages should not be able to break its protections simply by modifying JavaScript invocation methods. We added regression tests, tested the behaviour in Chromium, and confirmed that Canvas perturbation remained active after the changes.
It is the best version of Traceveil we have built.
But is it perfect? No.
Could another extension update make it perfect? I no longer believe so.
When More Protection Creates Another Fingerprint
Browser fingerprinting is an uncomfortable problem because protection can itself become a fingerprint.
If you change too little, the real computer remains visible. If you change too much, the browser becomes unusual in a different way.
Imagine that a website sees a common screen resolution but an uncommon graphics configuration. It sees one timezone through one API and slightly different behaviour through another. Canvas produces modified results, but the browser handles an error differently from a native implementation.
Each individual protection may work. Together, they may describe a browser that exists nowhere else. That browser becomes identifiable precisely because it is protected.
We encountered a version of this problem when experimenting beyond 1.3.2. The later experimental branch tried to push WebGL protection further, but its Balanced-mode changes exposed native GPU information. The experiment did not become the stable release.
This was useful because it clarified something for me. There is a difference between passing more privacy tests and building a more private browser. They are not always the same thing.
An Extension Is Still a Guest
Traceveil runs inside Chrome.
Chrome decides when extension code executes. Chrome decides which APIs are available. Chrome controls the rendering engine, browser processes, storage behaviour, permissions, networking, and the relationship between the page and extension environments.
Traceveil can wrap parts of that environment. It cannot own it.
It is like trying to renovate an apartment while the owner decides where the walls are, when the electricity works, and which rooms you may enter. You can still make the apartment better. You can make it more private and more comfortable. But you cannot rebuild the foundation.
We could continue adding more wrappers, more exceptions, more fallbacks, and more compatibility code. Some changes might improve particular results. Others might break websites or introduce inconsistencies elsewhere.
At what point would we be protecting the user?
At what point would we only be protecting the illusion that development must never stop?
Why Version 1.3.2 Is the Right Place to Stop
Version 1.3.2 is stable. It includes the most important fixes and hardening work we completed. It provides useful protection today, without asking anyone to abandon Chrome or change the way they browse. That matters.
A privacy product that requires everyone else to adopt a new standard before it becomes useful is not yet a useful product.
Traceveil works immediately. Install it, and it starts reducing tracking and fingerprinting signals. No account is required. Websites do not need to support it. Advertisers do not need to approve it.
I do not want to damage that useful product by endlessly pushing it beyond the limits of its architecture. We will still address serious security issues, browser compatibility problems, or major regressions if they appear.
What we will not do is release version 1.3.3 merely because 1.3.3 is the number after 1.3.2. A new version should represent meaningful progress. The next meaningful progress requires control at a deeper level.
The Next Traceveil Will Be a Browser
A Traceveil browser could make privacy decisions before websites begin executing their scripts. It could coordinate screen characteristics, graphics behaviour, timezone, fonts, storage, networking, permissions, and browsing identities as parts of one coherent environment. Instead of changing isolated answers, it could control the system producing those answers.
That is the difference.
An extension tries to hide or modify what the browser reveals. A browser decides what exists to be revealed.
The browser will be open source. Privacy decisions should be visible, testable, and open to criticism. Nobody should have to trust a promise that cannot be inspected.
But a browser is not a weekend project. It needs security updates, automated builds, platform support, upstream maintenance, compatibility testing, release processes, and people prepared to maintain it for years.
Starting a browser is easy. Maintaining a browser people can trust is the real work.
The Traceveil browser is coming, but we should build it when we are ready to take responsibility for it. We are not going to rush it merely because it is the obvious next technical challenge.

So What Do We Build Now?
We begin Roamer ID.
Why identity? Because the internet currently has a strange relationship with us.
It is very good at identifying us when we do not want to be identified.
It is much worse at allowing us to prove something about ourselves without surrendering control to somebody else.
Google can recognize you. Facebook can recognize you. Your bank, employer, mobile provider, and government can recognize you.
But what identity do you actually own?
What remains if one of those accounts is closed?
What can you carry from one service to another?
How do you prove that you wrote something, controlled an identity, or maintained a pseudonym without asking a platform to confirm it for you?
Most of us do not have an identity on the internet. We have accounts.
The company owns the account system. The company defines the rules. The company can suspend access, change the conditions, or disappear.
Roamer ID begins from a different place. Your identity should begin with you.
What Roamer ID Means to Me
I do not want to start by creating another large identity platform. I do not want people to register for a Roamer account simply so that Roamer can tell them they control their own identity. That would repeat the same problem under a different name.
Roamer ID should begin locally.
The first version will focus on a cryptographic identity root controlled through passkeys, with support for multiple pseudonymous profiles. You may have one identity for professional work, another for writing, another for a community, and another that you deliberately keep separate from the rest.
Why should all of them be permanently connected?
Why should one identifier follow you through every part of your life?
A person is not one username. Roamer ID should allow identities to remain separate until the person controlling them chooses otherwise.
No mandatory central account.
No need to publish a legal name.
No assumption that privacy means having no identity.
Privacy should mean deciding when and how you are known.
Traceveil and Roamer ID Solve Opposite Problems
Traceveil tries to prevent involuntary recognition.
Roamer ID will enable voluntary recognition.
Little bit of a paradox, innit?
Traceveil says: You should not identify me merely because my browser visited your website.
Roamer ID says: I choose to prove that this identity, signature, document, or action belongs to me.
These ideas are not in conflict. They need each other. An internet where nobody can prove anything would not create freedom. It would create fraud, impersonation, and confusion. An internet where everybody must reveal everything would not create trust. It would create surveillance.
The better system lies between them.
Do not identify me without my permission. Allow me to prove what I choose when I decide it is necessary. Reveal no more than the situation requires.
This is the way.
What Comes After Roamer ID?
Once an individual has an identity root, we can build Roamer Proof.
- A writer could sign a draft and prove that they possessed it at a particular time.
- A creator could publish work with a verifiable signature.
- A person could prove continuity behind a pseudonym without revealing their legal identity.
- Documents could be verified without trusting screenshots, copied metadata, or the word of a platform.
Later, the Traceveil browser could bring these pieces together. It could create stronger separation between browsing identities. It could reduce accidental correlation. It could allow a person to move between private browsing, persistent pseudonyms, and verified actions without one context silently contaminating another.
But Roamer ID should not need the browser to become useful. The browser should not need Roamer ID to provide privacy. Each part must stand on its own.
Knowing When to Stop
I used to think that stopping development meant losing momentum. Now I think momentum can also be lost by refusing to stop.
You keep working on the same layer because it is familiar. You know the code. You know the problems. There is always another improvement waiting. Meanwhile, the work that should come next never begins.
Traceveil 1.3.2 is not perfect. It is useful, stable, tested, and honest about what it can do. That is enough for this stage. The open-source browser will come. When it does, it should not be a larger collection of fingerprinting tricks. It should be a coherent privacy environment built at the correct architectural level.
For now, we move to Roamer ID.
Traceveil protects the boundary.
Roamer ID will create the root.
Sometimes progress means building the next version.
Sometimes it means understanding that the next version should be something else.