Microsoft Edge branded as ‘worrisome’ for user privacy

Research claims the web browser sends telemetry data and URLs to back-end servers

Microsoft Edge is one of the least private web browsers, as it sends back device identifiers and web browsing telemetry to back-end servers, according to new research. 

An analysis of the browser, which comes bundled in Windows 10 by default, conducted by  Trinity College Dublin found that Edge sends “persistent identifiers” to back-end services, as well as the URLs typed into the browser’s pages. 

Related Resource

Don’t just collect data, innovate with it.

Removing the barriers to the experience economy

Download now

Professor Douglas Leith from the university’s School of Computer Science and Statistics looked at the behaviour of other browsers as well and concluded that Edge and fellow browser Yandex were lacking in privacy protections. 

“From a privacy perspective Microsoft Edge and Yandex are much more worrisome than the other browsers studied,” Leith explained. “Both send identifiers that are linked to the device hardware and so persist across fresh browser installs and can also be used to link different apps running on the same device. 

“Edge sends the hardware UUID of the device to Microsoft, a strong and enduring identifier than cannot be easily changed or deleted. Similarly, Yandex transmits a hash of the hardware serial number and MAC address to back end servers. 

“As far as we can tell this behaviour cannot be disabled by users. In addition to the search autocomplete functionality (which can be disabled by users) that shares details of web pages visited, both transmit web page information to servers that appear unrelated to search autocomplete.” 

It's worth noting that the collection of user data and browser telemetry isn’t a privacy issue in itself, as such data can facilitate smooth upgrades and feedback when testing new features. But Leith noted that it becomes a problem when such data can be tied to a specific user. 

“When the same identifier is used across multiple transmissions it allows these transmissions to be tied together across time,” Leith said. “While linking data to a browser instance does not explicitly reveal the user’s real-world identity, many studies have shown that location data linked over time can be used to de-anonymize.”

“A second way that issues can arise is when user browsing history is shared with backend servers. Previous studies have shown that it is relatively easy to de-anonymize browsing history, especially when combined with other data,” Leith added. 

Not having the ability to opt-out of such privacy-sapping measures flies in the face of other efforts Microsoft has made in recent times to make its data collection and privacy option in Windows 10 and other services more transparent. 

Conversely, Leith found that the Brave Browser was the most secure, followed by Google’s Chrome browser, Mozilla Firefox, and Apple’s Safari. 

While Microsoft has put in plenty of work to make Edge into an appealing browser, it appears to have more work to do if it wishes to compete with rivals on privacy.

Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Recommended

How to factory reset Windows 10
operating systems

How to factory reset Windows 10

30 Mar 2021
FBI shuts down web shells in hacked Exchange servers
cyber security

FBI shuts down web shells in hacked Exchange servers

14 Apr 2021
NSA uncovers new "critical" flaws in Microsoft Exchange Server
servers

NSA uncovers new "critical" flaws in Microsoft Exchange Server

14 Apr 2021
Microsoft Surface Laptop 4 official with AMD and Intel CPU options
Laptops

Microsoft Surface Laptop 4 official with AMD and Intel CPU options

13 Apr 2021

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget
Mobile Phones

Xiaomi Redmi Note 10 Pro review: Champagne tastes on a lemonade budget

13 Apr 2021
NSA uncovers new "critical" flaws in Microsoft Exchange Server
servers

NSA uncovers new "critical" flaws in Microsoft Exchange Server

14 Apr 2021