7 ms·
Brute Force Incognito Browsing
- danjc 8y agoI noticed a while back that Safari disallows HTML storage in private browsing more - dead giveaway. Chrome and FF allow it but probably clear storage when the session ends.
- ReverseCold 8y agoSafari private browsing is to the point where if you open a new tab you're not signed into the same websites as your other tabs. It's pretty annoying actually, but it's a good feature.
- saagarjha 8y agoI think they may have relaxed that requirement a bit recently, so that you remain logged in if you click a link that opens in a new tab.
- dewiz 8y agoThe annoying first-time experience can be disabled by putting some files in the new profile. i.e. instead of creating a new empty profile every time, clone one that is already initialized.
- jph 8y agoThese are great! Thank you for the writeup and code. Do you have a way to donate to you to thank you? Or do you have a favorite charity?
- gcb0 8y agotl;dr create a brand new, disposable profile. instead of the browser built-in private mode.
- factsaresacred 8y agoWhy not just use one browser for general stuff and another browser for stuff that you want private?
- Normal_gaussian 8y agoI do something very similar; there are two main differences * I make a copy of a special default profile instead of a fresh one - eliminating a bunch of annoying popups and preserving add-ons * I set it as my default browsing experience ('web') so that anything that tries to launch a browser window also gets contained
- buu700 8y agoThis sounds like pretty much the same argument that @eganist and I made to Google and Mozilla a little while back before demoing an HPKP supercookie (https://github.com/cyph/hpkp-supercookie https://github.com/cyph/hpkp-supercookie) at Black Hat and DEF CON. Our position was that doing just about anything less than what Chris did here was essentially lying to users about incognito mode's threat model, but if I recall correctly both teams viewed other security tradeoffs (such as carrying over HPKP and HSTS state) as worth considering infringing on incognito's stated purpose. In the end they did both follow our suggested mitigation for the HPKP issue (before Google turned around and deprecated HPKP out of nowhere ಠ_ಠ), but it isn't surprising to hear that similar issues may still exist.
- tialaramex 8y agoDo you really feel that deprecation of the HPKP self-ransoming foot gun came out of nowhere?
- buu700 8y agoWell, the timing wasn't 100% random since the newly supported Expect-CT header was HPKP's "replacement", but I do think three years is a ridiculously small turnaround time between initially adding support for the feature and killing it with low adoption as a stated reason. I'd also say the footgun aspects of HPKP are a weak excuse to kill it, given that nothing really new about them has been discovered that wasn't acknowledged as a consideration in the original spec. If anything, I think it would've made more sense to improve the UX for both end users and admins/devs to reduce the likelihood of deployment mistakes (better documentation and tooling) and the potential for damage when mistakes did happen (e.g. make HPKP error screens skippable like any other TLS errors).
- dagenix 8y ago> make HPKP error screens skippable like any other TLS errors That largely defeats the point. Almost no one knows what to make of those errors. And just training everyone to ignore them makes HPKP pointless. The problem with HPKP was that it could be used to attack any site on the internet with no way for websites to opt out. Basically, the same problem as with certificate authorities - but worse. Those issues we're know when the spec was written, true. But, it was still a dangerous and extremely difficult to deploy feature. Good riddance.
- Naa4 8y agoI use Firefox Focus on my mobile devices. It blocks trackers and you can easily delete your history and cookies. https://support.mozilla.org/en-US/kb/focus https://support.mozilla.org/en-US/kb/focus
- duckerude 8y agoNote: it's packaged on F-Droid as Firefox Klar, the German version, but the name is the only difference as far as I can tell. https://f-droid.org/en/packages/org.mozilla.klar/ https://f-droid.org/en/packages/org.mozilla.klar/
- crtasm 8y agoThe difference is that Mozilla's analytics are disabled by default in Klar to comply with German law.
- fouc 8y agoI'm disappointed (though not surprised) that extra measures are actually required for true incognito mode. Hopefully people can share other good ways to accomplish this.
- notriddle 8y agoTor Browser.
- probably_wrong 8y agoI have two use cases requiring private browsing, and dealing with both of them is very annoying. On one hand, I don't want to be tracked. Disabling cookies in this case is fine, because if I open my webmail then all I do afterwards is tracked, courtesy of analytics code. On the other hand, disallowing cookies leads to all the problems mentioned in the post. I wish there was a feature "keep multiple tabs, but cookies are not shared between them". Currently I manage with a combination of Firefox extensions and using two browsers at the time. But I wish it was easier.
- systoll 8y ago> "keep multiple tabs, but cookies are not shared between them" That's how Safari does it. It can be a little awkward, in that [eg] if you log into HN, then open a comments page in a new tab, you'll need to log in again -- but I think it's better than Chrome's approach. There's a middle ground that seems like it'd be the best of both worlds — sharing things between multiple private tabs, but not multiple private windows.
- sureaboutthis 8y agoExcept when one uses server push and that's not true anymore.
- mockingbirdy 8y agoThere's a third use case. A use case that most people use it for... Developing web apps and avoiding caching problems, obviously.
- scrollaway 8y agoAren't you just describing Firefox container tabs?
- abtom 8y agoWhat Firefox extensions are you using? Check out Multi Account Containers on Firefox if you haven't already. It fulfills all my privacy requirements when paired with uBlock Origin and Privacy Badger. https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ https://addons.mozilla.org/en-US/firefox/addon/multi-account...
- PeterStuer 8y agoMy main use case of private browsing is to avoid having to agree to the ubiquitous tracking websites demand, when they use every dark pattern in the book to make opting out hell. A private session can let me agree and shrug it off. I do wish Firefox especially, as it positions itself as the users champion, would make their 'private' or persistent containered mode standard, with an option to whitelist and opt out for selected trusted sites.
- mrintegrity 8y agoDoesn't that assume that the only way they track your data is with cookies? Perhaps by agreeing you are also allowing them to track you based on browser fingerprint / IP address so private browsing wouldn't be fullproof for this use case?
- PeterStuer 8y agoYou are right, and I have considered that, but what is the practical alternative? At least if they do they seem to have the decency to ask for reconfirmation each visit.
- crtasm 8y agoTor browser. I use it on desktop and mobile for my day to day browsing, the network is much faster than it was in the past.
- dewanee 8y agoI use a more general approach starting firefox and/or chrome within firejail (i.e. firejail --private google-chrome-stable) https://firejail.wordpress.com https://firejail.wordpress.com The same approach can be used also with other applications one wants to isolate from the network and/or home data.
- deleted 8y ago[deleted]
- samet 8y agoI went through the very same path and wrote almost the same Bash script, then packaged it as a MacOS app: http://github.com/samet/sessionless http://github.com/samet/sessionless When I need a true sessionless browsing experience, here is what I do: 1. cmd+space, open Sessionless 2. do whatever do you want with a true sessionless mode 3. cmd+q, quit with sweeping every trace 4. profit Besides, I can open more than one independent Sessionless windows; a feature which is not possible using Incognito mode.
- patagonia 8y agotldr: Why should I be made to feel dirty if I don’t want to be surveilled? If the new profile is sufficiently similar to your actual profile, the browser’s “fingerprint”, combined with network and machine information might still register. On a non technical note I have a problem with browser makers chosing “sleuth” or risqué masquerading looking icons to represent “private” browsers. I turn on private browsing and the browser makes me feel sneaky or shifty or shady or suspicious (I’m just now noticing how many of those words start with “s”, interesting). When I step out of my house and hope to not be tracked and surveilled I do not put on some Carmen Sandiego looking private eye get-up. (Unfortunately, I actually might have to in some cities, like London. And I’d def need to leave my digital devices at home.) We opt-in to “do not track” and the servers ignore. We choose “incognito” mode and that’s not quite enough, even though at this point we are feeling dirty and sneaky because of the UI. I add uBlock Origin and Disconnect and now I feel like a full blown activist. How do we flip the table so that the servers have to opt in to “Private Eye” mode? And if they’re still not getting enough info they have to enable “Five Eyes” mode. And if they’re still not getting what they need they can ask us to install the optional “surveillance state” module. Not having the largest social network and largest browser maker both be for profit corporations with business models based on harvesting user information would be a start.
- fulafel 8y agoThis is what the upcoming Containers feature of Firefox is supposed to do, right?