IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Private browsing ‘not so private’

Private browsing does not offer complete protection from snoopers as data is leaked in various ways, a report has claimed.

browser

Private browsing does not offer complete security from determined attackers and more needs to be done to offer stronger protection, a report has suggested.

Looking at Safari, Firefox, Google Chrome and Internet Explorer, researchers from Stanford and Carnegie Mellon University found each browser leaked user data in differing ways during or after private sessions.

One problem is operating systems often store certain DNS data. An attacker with control over a user's system can look at the DNS cache post-browsing and learn if and when the user visited a specific website, the researchers explained.

"Thus, to properly implement private browsing, the browser will need to ensure that all DNS queries while in private mode do not affect the system's DNS cache," the report said.

"None of the mainstream browsers currently address this issue."

One experiment showed how URLs of visited websites had been stored on the computer's swap file, despite privacy being on, along with links in those pages and sometimes even text from a site.

"A full implementation of private browsing will need to prevent browser memory pages from being swapped out," the report read, again noting none of the mainstream browsers do this.

Researchers also showed how many popular browser extensions undermined the security of private browsing.

"Browser add-ons pose a privacy risk to private browsing because they can persist state to disk about a user's behavior in private mode," the report claimed.

"The developers of these add-ons may not have considered private browsing mode while designing their software, and their source code is not subject to the same rigorous scrutiny that browsers are subjected to."

The study paper, due to be delivered at the Usenix security conference next week, also found private browsing was used more frequently in services which used "subtle private browsing indicators."

"Safari and Firefox have subtle indicators and enforce a single mode across all windows; they had the highest rate of private browsing use."

Unsurprisingly, the report showed how private settings were used more often when searching porn sites than when looking for surprise gifts.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Chrome vs Firefox vs Microsoft Edge
web browser

Chrome vs Firefox vs Microsoft Edge

19 Jul 2022
Google adds new security vendor plugins for Chrome, improved Chrome OS policy controls for IT admins
operating systems

Google adds new security vendor plugins for Chrome, improved Chrome OS policy controls for IT admins

27 May 2022
Google Chrome branded the least effective browser for stopping phishing attacks
phishing

Google Chrome branded the least effective browser for stopping phishing attacks

26 May 2022
Google patches second Chrome browser zero-day of 2022
zero-day exploit

Google patches second Chrome browser zero-day of 2022

28 Mar 2022

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Microsoft successfully tests emission-free hydrogen fuel cell system for data centres
data centres

Microsoft successfully tests emission-free hydrogen fuel cell system for data centres

29 Jul 2022