Private browsing modes in four biggest browsers often fail


Recommended Posts

Features in the four major browsers designed to cloak users' browser history often don't work as billed, according to a research paper that warns that users may get a false sense of security when using the built-in privacy settings.

The private-browsing modes are supposed to allow users to visit a website without leaving any trace on their computers, and yet Internet Explorer, Firefox, Chrome, and Safari frequently leave tracks, according to the research, which is scheduled to be presented at next week's Usenix Security Symposium in Washington DC. The makers of those browsers ? Microsoft, Mozilla, Google, and Apple respectively ? often hail the offerings as a way to enhance privacy when using shared computers.

One failure that affects IE, Firefox, and Safari happens when users save SSL, or secure sockets layer, client certificates while browsing in private mode. The browsers store a record of those actions in a file that allows anyone who has physical access to know exactly what site the user was visiting at the time. Similarly, when IE and Safari encounter a self-signed certificate, it is stored in a certificate vault that is preserved even after the private session ends.

Similarly, Firefox users who make security certificate settings while in private mode will have a partial copy of their browsing history stored in a file called cert8.db, the researchers said.

?We discovered that all these browsers retain the generated key pair even after private browsing ends,? the researchers wrote. ?Again, if the user visits a site that generates an SSL client key pair, the resulting keys will leak the site's identity to the local attacker.?

The study (PDF here) showed each browser failing in specific settings.

The privacy mode in Firefox, for instance, is undermined when a user sets site-specific preferences or uses a variety of Mozilla-sanctioned plug-ins. The open-source browser also stores websites visited that dole out custom protocol handlers based on the HTML5 standard.

For its part, IE's InPrivate mode can be undermined when websites make SMB queries, since the Microsoft browser shares large chunks of code with Windows Explorer.

The researchers also devised a way for webmasters to detect when someone visiting their sites is using the privacy mode. It involves placing an iframe with a unique web address and then ?using JavaScript to check whether a link to that URL was displayed as purple (visited) or blue (unvisited).?

The researchers said that to the best of their knowledge they are the first to demonstrate a way to detect private browsing mode ? but that may not really matter for much longer. The technique appears to use the decade-old browser history attack, which was recently fixed in Safari and will soon be fixed in Firefox. It's only a matter of time before Microsoft and Google follow suit.

Using the technique, they confirmed what we all suspected: the feature is mainly used when surfing to porn sites. Gift and news sites, not so much. ?

http://www.theregister.co.uk/2010/08/06/private_browsing_mode_failure/

I think people put too much trust in these modes, but at the same time I think the browser makers hype it up a bit.

That being said, these would be flaws that should be fixed.

...

The technique appears to use the decade-old browser history attack, which was recently fixed in Safari and will soon be fixed in Firefox.

...

Uh, Mozilla came up and implemented it first, Apple was second.

Well, porn is a multi-billion-dollar business for a reason. But even so, people can't afford to lose the jobs they have over it. Thus, "porn mode" was born.

Porn mode was born because porn is a really booming internet business...and people cannot control their urges. If people feel the need to wack it all the time, they have problems. Friend of mine, her EX had porn on every laptop and mobile device he had....and thats not even the half of it.

But anyway, at work I dont even bother trying to mask where I am going to because I respect the rules.

I've never bothered to use those modes tbh, I guess a better private browsing mode would be running a browser normally in a sandbox, then deleting the sandbox when you close the browser.

You do know that there's a market for VMware vulnerabilities too. I can only imagine that VirtualBox, Virtual PC and the OSX ones are would be similar.

But I agree - I never use these modes since I've never really believed that they can self contain whatever happens. I wonder if these modes lead people to believe that they're protected from malware, tbh.

1195970568513ij6.jpg

That's because you never bothered to upgrade from IE6.

I dont need to, I dont use private browsing anyway.

You do know that there's a market for VMware vulnerabilities too. I can only imagine that VirtualBox, Virtual PC and the OSX ones are would be similar.

I meant something like sandboxie, but I guess there are vulnerabilities there too.

Probably they don't think Opera is a major browser. Hope not. :(

In terms of how much they've innovated and contributed to the browsing community in the past no their not, in terms of market share yes their tiny.

You can't count Chrome or Safari as major browsers if Opera is not. It's been in development far longer and has plenty of commercial ties especially in embedded devices, and was "innovating" far longer than than any other. It uses it's own engine and isn't simply a front-end and has a sizable market share when you consider how many browsers are in use, total. 10's of millions of people at least... 'bout the only thing they don't do a lot of is marketing and bundling which is practically the only way anyone else got their browser in use, 'cept for Firefox...

Most people go by market share to determine what is a major browser. Unfortunate Opera market share is tiny.

Exactly, but so is Safari and Chrome's. It's rare to ever come across someone in the general public that actually uses these as their primary browser. So to include Safari and Chrome is to expand the definition of major browser to including anyone with a single digit of market share, which Opera should be included. The only reason anyone might think Safari and Chrome are otherwise major browsers are because the image their parent company has to the media..

Porn mode was born because porn is a really booming internet business...and people cannot control their urges. If people feel the need to wack it all the time, they have problems. Friend of mine, her EX had porn on every laptop and mobile device he had....and thats not even the half of it.

Well, I don't see the point of having X rated material on mobile devices. Pointless.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Now 8GB of ram looks even worse in the Neo. I'm so happy I purchased 128GB of DDR 4 when I did.... paid $174. Upgraded my parents laptop to 32GB around the same time for $48. Luckily I have a TON of spare laptops. So i'm good on laptops for a while. I also have a lot of desktops too that I could use if i had to. Lets just hope nothing happens to my main 4 monitor couch workstation.
    • I will keep my current devices for several years... no planning in upgrading until these devices stop working. Too pricey.
    • Apple raises MacBook and iPad prices as memory costs surge by Karthik Mudaliar Apple has raised the U.S. prices of several MacBook and iPad models, including the MacBook Neo, which it launched for $599 less than four months ago. The company’s cheapest laptop now starts at $699, while some MacBook Pro configurations have increased by $300. The changes affect the MacBook Neo, MacBook Air, MacBook Pro, iPad Air, and iPad Pro. Apple has not changed the hardware or storage included with these models, so customers are simply paying more for the same configurations. Here is how the new US pricing compares with the previous starting prices: Product Previous price New price Increase MacBook Neo $599 $699 $100 13-inch MacBook Air, 512GB $1,099 $1,299 $200 14-inch MacBook Pro, 1TB $1,699 $1,999 $300 16-inch MacBook Pro $2,699 $2,999 $300 11-inch iPad Air, 128GB $599 $749 $150 13-inch iPad Air, 128GB $799 $949 $150 11-inch iPad Pro, 256GB $999 $1,199 $200 13-inch iPad Pro, 256GB $1,299 $1,499 $200 The updated prices are already appearing on Apple’s U.S. online store. The MacBook Neo increase will probably attract the most attention. Apple introduced the laptop in March for $599, pitching it as a more affordable Mac for students and buyers considering Windows laptops or Chromebooks. It uses an A18 Pro processor and originally undercut Dell’s new $699 XPS 13 by $100. Following the increase, the two laptops now have the same starting price. The M5 MacBook Air has also lost the price Apple promoted when it launched in March. The 13-inch model arrived with 512GB of storage for $1,099, while Apple’s store now lists the MacBook Air range as starting at $1,299. The 14-inch MacBook Pro with an M5 chip and 1TB of storage has gone from $1,699 to $1,999. Apple has made similar changes to its iPads. The recently released M4 iPad Air, which launched at the same $599 starting price as its predecessor, now starts at $749 for the 11-inch version. The 13-inch version has risen from $799 to $949. The iPad Pro increases are larger in dollar terms. Apple’s 11-inch M5 iPad Pro now starts at $1,199, up from $999, while the 13-inch version has moved from $1,299 to $1,499. Both base models still include 256GB of storage. Apple blamed the increases on the rapidly rising cost of DRAM and NAND flash, which provide system memory and device storage. The company told Reuters that it had tried to shield customers from the increases but could no longer absorb them. “We have never seen a component price increase this much, this quickly,” Apple said. Tim Cook had already warned that price increases were coming. Cook said Apple’s existing component inventory had softened the immediate impact, but that higher memory costs would increasingly affect the company after the June quarter. Much of the pressure comes from the construction of AI data centers. Memory manufacturers are directing more production toward high-margin server products, leaving PC, tablet, and smartphone makers competing for the remaining supply. Apple has not said whether the new prices are temporary or whether further increases are planned. For now, the changes show that even Apple’s purchasing power has not been enough to keep the AI-driven memory shortage away from consumer devices.
    • Ventoy 1.1.16 is out.
    • This is a none story - these low volume Chinese models will always get new experimental features first because Apple and Samsung can't produce them in huge volume to meet demand.
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      462
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      135
    4. 4
      Michael Scrip
      77
    5. 5
      Xenon
      77
  • Tell a friend

    Love Neowin? Tell a friend!