I think falsifying your user agent would be critical. Even with e.g. Mullvad how many requests will it take until one is deanonymized? Let's say I'm using a crowded VPN exit, still I can be profiled based on my user agent, the vpn IP and my requests. All it'd take them to connect the dots, would be me openning my apps/browser tabs on my phone/laptop/device without VPN for a second.
Not just user agent. Tons of other info is used for fingerprinting, from viewport and screen size to the list of installed fonts.
How would you go about them? So far I rely on Mullvad, privacy badger, ublock and random user agent.
The Tor browser employs a variety of anti-fingerprinting measures and there’s a project that’s upstreamed some of them back into vanilla Firefox.