Private browsing

Private browsing, privacy mode or incognito mode is a privacy feature in some web browsers to disable browsing history and the web cache. This allows a person to browse the Web without storing local data that could be retrieved at a later date. Privacy mode will also disable the storage of data in cookies and Flash cookies. This privacy protection is only within the browser application as it may leave traces on the hard drive and memory of the device,[1] or via websites by associating the IP address at the web server.[2]

History

The earliest reference to private browsing was in May 2005, and was used to discuss the privacy features in the Safari browser bundled with Mac OS X Tiger.[3] The feature has since been adopted in other browsers, and led to popularization of the term in 2008 by mainstream news outlets and computing websites when discussing beta versions of Internet Explorer 8.[4][5][6] However, privacy modes operate as shields because browsers typically do not remove all data from the cache after the session. Plug-ins, like Silverlight, are able to set cookies that will not be removed after the session. Internet Explorer 8 also contains a feature called InPrivate Subscriptions, an RSS web feed with sites approved for use with InPrivate browsing.[7]

The common web browser plugin Adobe Flash Player began supporting privacy mode in Chrome, Firefox, Internet Explorer, and Safari with the release of version 10.1 in June 2010.[8]. Some browsers (like Internet Explorer 8) allow users to select the privacy mode for single tabs, whereas others create a more isolated environment protected by password and cryptography.

Uses

Private browsing has multiple uses, including:[9][10][11]

  • Reducing history, including autofill, browsing, and personal information.
  • Performing "pure searches" that are not influenced by prior browsing history or networks or friends' recommendations, which may weight and more highly rank certain results than others.
  • Preventing accidental saving of login credentials to accounts.
  • Signing into multiple accounts simultaneously, via multiple tabs.
  • Testing websites.
  • Preventing other users of the computer from finding one's search history.
  • Viewing explicit material without outside knowledge.

The Mozilla Foundation performed a study about the user behavior when the feature is switched on and how long the session lasts. The results were that most sessions last only about 10 minutes, though there are periods where activation increases; usually around 11 a.m. to 2 p.m., 5 p.m., between 9 p.m. and 10 p.m., and a minor peak about an hour or two after midnight.[12]

Private browsing is known by different names in different browsers.

Date Browser Synonym
April 29, 2005 Safari 2.0 Private Browsing
December 11, 2008 Google Chrome 1.0 Incognito
March 19, 2009[13] Internet Explorer 8 InPrivate Browsing
June 30, 2009 Mozilla Firefox 3.5[14] Private Browsing
March 2, 2010 Opera 10.50[15] Private Tab / Private Window
November 18, 2014 Amazon Silk[16] Private Browsing
July 29, 2015 Microsoft Edge InPrivate Browsing

Security

In 2012, Brazilian researchers published the results of a research project[17] where they applied forensic techniques (namely the Foremost data carving tool and Strings program) to extract information about the users browsing activities on Internet Explorer and Firefox browsers with their private mode enabled. They were able to collect enough data to identify pages visited and even partially reconstruct them.

This research was later extended[18] to include Chrome and Safari browsers. The gathered data proved that browsers' private mode implementations are not able to fully hide users' browsing activities and that browsers in private mode leave traces of activities in caching structures and files related to the paging process of the operating system.

Another independent security analysis, performed by a group of researchers at Newcastle University in 2014, shows a range of security vulnerabilities in the implementation of the private mode across four major browsers (IE, Firefox, Chrome and Safari).[19] The results are summarized below.

  1. Browser extensions are potential threats to the user privacy. By design, existing browsers (e.g., Firefox, Safari) commonly choose to enable extensions in the private mode by default. This however allows an installed extension to secretly record the visited websites without the user's awareness. Newer versions of Chrome disable extensions in the private mode by default, but allow the private and the normal modes to run in parallel. This makes it possible for an installed extension in the normal mode to learn the user activities in the private mode by measuring the usage of shared computing resources.
  2. Data erasure by the browser alone is found to be insufficient. For example, the records of visited websites during the private session can be retained in memory for a long time even after the private session is closed. In addition, the visited website records are usually kept by the operating system in the local DNS cache. Furthermore, the modified timestamps of certain profile files saved on the disk may reveal if the private mode was previously turned on and when it was turned on.
  3. Software bugs present in some browsers are found to seriously degrade the security of the private mode. For example, in some earlier versions of Safari, the browser retained private browsing history records if the browser program was not closed normally (e.g., as a result of program crash), or if the user acted to add a bookmark within the private mode.
  4. Depending on whether the session is in the private or the normal mode, web browsers typically exhibit different user interfaces and traffic characteristics. This allows a remote website to tell if the user is currently in the private mode, for example, by checking the color of the hyperlinks or measuring the time of writing cookies. (The fact that the user is using the private mode should be considered protected information as well.)

In 2010, professors at Stanford University found that while Firefox won't record your history during a private browsing session, it still records the sites on which you've installed SSL certificates (which enable secure, encrypted information exchange indicated by the "https" in front of the URL) and allows specific permissions. If you download an SSL certificate from a website or told that site specifically to stop displaying pop-ups and downloading cookies, all of that information is still stored on Firefox.

In 2015, researchers from Pennsylvania State University found that a considerable amount of extensions on Firefox violated the private browsing policy based on an investigation of the top 2,000 extensions.[20] Many extensions maintain their own profile folders on the local machine, and most of them will not wipe the browsing data after the private browsing session ends. This violation even happens on some most popular extensions with millions of users on Firefox.

References

  1. Verger, Rob (26 February 2018). "Your private browsing isn't as incognito as you want it to be". Retrieved 15 September 2018.
  2. "HTG Explains: How Private Browsing Works and Why It Doesn't Offer Complete Privacy". How-To Geek.
  3. Trapani, Gina (May 4, 2005). "Safari's private (porn) browsing mode". Lifehacker. Retrieved 2010-04-11.
  4. Foley, Mary Jo. "Microsoft to roll out more granular 'porn mode' with IE 8". ZDNet. Retrieved 2008-10-04.
  5. Sadighi, Lalee. "Microsoft's Internet Explorer 8 Goes 'Porn Mode'". Red Herring. Archived from the original on 2008-09-12. Retrieved 2008-10-04.
  6. Kidman, Angus. "Microsoft releases IE8 beta 2: MS porn mode included". APC. Retrieved 2008-10-04.
  7. "IE8 and Privacy". Microsoft Developer Network. Microsoft. 2008-08-25. Retrieved 2009-07-06.
  8. Xu, Jimson; Nguyen, Tom (30 June 2010). "Private browsing in Flash Player 10.1". Adobe Systems. Retrieved 14 January 2011.
  9. Fiol, Taryn (23 October 2012). "7 Great Uses for Your Browser's Private Browsing Mode". Apartment Therapy.
  10. Obaiza, Osas. "5 Great Reasons Why You Should Use Private Browsing Online". Null Byte.
  11. Pash, Adam (25 August 2010). "Nine Great Uses for Private Browsing that Don't Involve Porn". Lifehacker.
  12. Ulmer, Hamilton (23 August 2010). "Understanding Private Browsing". Blog of Metrics. Mozilla Foundation. Retrieved 24 August 2010.
  13. "Microsoft Announces Availability of Internet Explorer 8" (Press release). Microsoft. 19 March 2009. Archived from the original on 22 March 2009. Retrieved 16 December 2011.
  14. "Mozilla Cross-Reference mozilla1.9.1". Mozilla Foundation. Retrieved 2009-05-26.
  15. Mateu, Roberto. "Opera 10.5 pre-alpha for Labs". Opera Software. Archived from the original on 2011-08-26. Retrieved 2009-12-22.
  16. "Private Browsing for Amazon Silk". Amazon Inc. Archived from the original on 2014-12-22. Retrieved 2014-11-18.
  17. R. Ruiz, F. P. Amatte, K. J. B. Park, Tornando Pública a Navegação “In Private”. Proceedings of the Seventh International Conference on Forensic Computer Science – ICoFCS 2012, Available online Sep 2012.
  18. R. Ruiz, F. P. Amatte, K. J. B. Park, Opening the “Private Browsing” Data – Acquiring Evidence of Browsing Activities. Proceedings of the International Conference on Information Security and Cyber Forensics (InfoSec2014), Available online Oct 2014.
  19. K. Satvat, M. Forshaw, F. Hao, E. Toreini, On the privacy of private browsing – A forensic approach. Journal of Information Security and Applications, In Press, Available online 3 April 2014.
  20. B. Zhao, P. Liu, Private Browsing Mode Not Really That Private: Dealing with Privacy Breaches Caused by Browser Extensions. In Proceedings of the 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2015), Rio de Janeiro, Brazil, Available online June 2015.
  • "How to Turn On Private or Incognito Browsing". Wikihow. Retrieved Jul 31, 2018.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.