Private Browsing 2.0
webkit.org
webkit.org
Yes I cannot agree more. Personally this shift in people's expectations of Private Browsing or Incognito Browsing came in a way that felt sudden. The recent lawsuit about Google tracking you in Incognito mode was absolutely dumbfounding to me: of course websites can still track you! If only people still remembered the origins of this feature in 2005 (or 2008 in Chrome's case). But even on HN the opinion was pretty split. It is indeed clear that it is now time to change what private browsing means.
However, I don't think this is going to stay this way for long. The word "private" when it comes to computing has many varied definitions and it all depends on who the information is made private to. In the extreme case, if your threat model is privacy from eavesdroppers on the network or the ISP, then a browser can easily claim any HTTPS connection is private enough; the majority of browsing is already private browsing. If it is privacy from others using the same machine, then this older private browsing already works. But I cannot help but feel that a few years down the road people are going to consciously or subconsciously substitute yet another definition of privacy.
I'm not entirely surprised they got this "wrong" given that the question was, "What should we call it?" Naming things (correctly, "future-proof"-ly) is hard.
Naming things may be hard, but in addition, this isn't even a bad name. The popular colloquial name at the time (porn hiding button, or maybe that was only because I was a student when it was introduced) could hardly be seriously used, of course it is called something related to not leaving traces on the computer you're using
Private browsing was so your gf wouldn’t find out about the engagement rings you were looking at!
https://www.osnews.com/story/140252/safari-already-contains-...
https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
Without fail, the knee bends. This also just got quietly enabled by default in Firefox 128, go check and turn it off if you are so inclined.
dom.private-attribution.submission.enabled1. They started using USB Type C.
2. They are the only major manufacturer that appears to actually take privacy seriously. Even their AI endeavours look the most privacy focused that exists.
I'm sure I could go buy some no-name brick and flash my own security focused OS and run my own relays and ... I don't want to do that. I want to buy something that everyone else uses and for it to respect me.
So as much hate as Apple gets, they have my trust in good faith, for now.
Apple's deceptive marketing has made me lose all trust in the company. It will take a lot more than USB-C for me to consider Apple for computing devices.
* These guys are truly working very hard at guaranteeing privacy;
* That will probably break some websites (I'm trying out the advanced tracking protection in normal mode, we'll see).
* It will also put them on collision with Google, which is essentially an advertising shop with a free browser frontend.
> Alongside the new suite of enhanced privacy protections in Private Browsing, Safari also brings a version of Web AdAttributionKit to Private Browsing.
This is worse for privacy. No other browser does this. No other browser even lets you opt in for this because it's so nonsensical.
That seems like an exaggeration? How could another solution possibly be worse for privacy than the open season it was previously...
The worst it could be is the same.
> No other browser even lets you opt in for this because it's so nonsensical.
That also does not seem true
Google has their topics API: https://developer.chrome.com/blog/new-in-chrome-115/#topics-...
and according to another poster here, Firefox added something similar.
Don't get me wrong, I hate that they had to make these concessions, but what was their choice? If they did not give something (while giving users the ability to opt out) we would have seen browsers being blocked (and no way Google was going to not do something given their entire business is ads, so they could just keep saying use Chrome).
Previously, there was no ad tracking at all in private mode.
> That also does not seem true
No other browser enables any such tracking in private mode or incognito mode. https://developers.google.com/privacy-sandbox/relevance/attr....
The Topics API you mentioned returns empty topics in incognito mode. https://clearcode.cc/blog/google-chrome-topics-explained/#:~....
> but what was their choice?
Do what other browsers do. Don't enable ad tracking in private mode.
The post is about ways that tracking was previously possible in private mode that have now been blocked.
Is this a cat and mouse game?
> Fingerprinting
Does this prevent Google's cookieless tracking technology?
In many ways it is. When I first started blocking using pac files. It was painfully obvious that samesite advertising is the harder thing to block. Luckily for the blockers most companies have been lazy about adverts and put them in known locations. Which works just as well for whole site blocking (known trackers). However, once the adverts are blended into the real data it becomes much harder. Such as what youtube is experimenting with (putting adverts right in the same data stream remuxed). As long as the adverts follow known patterns blocking works fairly easily. The next 'arms' race will be AI detection and block. It will only be a matter of time until someone comes up with a plugin that does exactly that.
> Does this prevent Google's cookieless tracking technology?
To a point. But you do not need much data to fingerprint. Think it is something like 12-13 bits plus your IP even with a VPN.
Is that legal under GDPR?
- Blocking requests to known trackers
- Remove utm_ and other such parameters from URLs
- Fingerprinting resistance
- Extension disabling
- Cap third-party cookie lifetimes
- Partitioning for sessionStorage and blob URLs
- Proxying encrypted-to-the-resolver DNS traffic
- Proxying HTTP, but only when it's unencrypted
With a subscription, you also get per-tab sessions and a VPN
---
The fingerprinting resistance is interesting as it claims to remove user behaviour characteristics like typing speed and how you move the cursor. Does it fire keyboard events with randomised delays and adds random offsets to mouse locations or how could this work? Games would be unplayable with mouse offsets and random input lag, but if that's not it, then the website gets the data so this has to be it right? For canvas specifically, they say there'll be small but probably visible artifacts from noise injections. So no web-based photo editing in private navigation? Curious how this'll work out in practice
Also cool is that they offer an open platform (Mastodon) as a place where you can respond to the author!
Incorrect. Safari does not remove utm_ parameters. See: https://lapcatsoftware.com/articles/2023/6/2.html
I don't know why you're loling. Do you expect me to paste the entire file contents into this comment thread?
If you're a Mac user, then you can easily see the file on your own Mac. My blog post was written for Mac users. And the WebKit blog post was written for Apple Safari users on Mac and iPhone.
In any case, you already said "I'll take your word for it that utm isn't on there specifically", so I don't know why this particular detail needs further debate.
> When we invented Private Browsing back in 2005, our aim was to provide users with an easy way to keep their browsing private from anyone who shared the same device.
I wonder if anyone actually involved 19 years ago was also involved in writing this piece, or if it just sounded reasonable to whoever drafted it up.
It's an interesting question to me because their tone is speaking from experience but is it the authors experience or Apple?
I care a lot more if it's the actual author, a human, over Apple, a brainless corporation.
I use and love StopTheMadness Pro. Do you know if it breaks the whole extension or only some parts of it? If so, which ones? (I don't use the copy URL shortcut for example).
Yes, I assume it's a bug.
> I use and love StopTheMadness Pro.
Thanks!
> Do you know if it breaks the whole extension or only some parts of it? If so, which ones?
Not the whole extension, no, only the parts that depend specifically on the URL query.
This is like a bad dream.
Really, just ... what if the software on my computer tried its best to do exactly what I asked it to do, and was not concerned with anyone else's problems?
Anyway, here are the AdAtributionKit docs:
- Technical / API: https://developer.apple.com/documentation/adattributionkit
- High-level: https://developer.apple.com/app-store/ad-attribution/
I think a reasonable answer is that you are using their website for your own purposes; that running a website has costs; and that many businesses choose to fund those costs by advertising. If you don't want to be advertised to, I would suggest paying a fee to use ad-free services.
Apple specifically gets mentions as a website data sharing partner in the privacy policies of my health insurance, my dental insurance, and my mortgage provider. I can assure you that none of those companies are lacking for funds to run basic websites and equally that none of them have ways to pay to "opt out".
Adtech gaslights everyone into accepting that just because it is technically possible to perfectly track and personalize ads in digital media, that they have some sort of moral right to do it.
What an oxymoron.
No thanks, Apple!
I trust my ISP more than you. Multi-hop wont matter if all nodes are managed by you.
Contrast this model with Tor where you have 3 hops that are selected in such a way that there is a lower probability that logs from the node operators will be combined. If two nodes, let's say node 1 and 3 are coorporating, then the best that they can do is a correlation attack or other probabalistic methods.
If two nodes (all of them) in WebKit are adverserial, then the content is linked back to your IP address with 100% probability.
I'm sure some of this info has been passed on and then parallel construction used to obfuscate the initial source of the data.
>Contrast this model with Tor where you have 3 hops that are selected in such a way that there is a lower probability that logs from the node operators will be combined
"selected in such a way" sounded like there is something in Tor that actively works against a situation where the hops are owned by the same operator, but AFAIK there isn't such a thing. Hence my request for confirmation that the only thing Tor does better than the Apple+Cloudflare situation here is that it has more than two hops so that it increases the number of colluders needed for correlation.
Another thing Tor does better is that it creates circuits with nodes spanning multiple jurisdictions, whereas Private Relay circuits are confined to one jurisdiction (and worse, to your current one).
> actively works against a situation where the hops are owned by the same operator, but AFAIK there isn't such a thing
Right, there is nothing Tor can do to guarantee this, but it does take some best-effort measures like maximizing diversity of AS providers (you won’t get a circuit of three nodes with the same AS number). Of course this is meaningless in a world where anyone can purchase servers from anywhere. There is a lot of research on this attack vector against Tor (and p2p networks in general) - the relevant search term is “Sybil resistance.”
Btw - just to add some detail to the discussion, this blog post from Cloudflare is a good introduction to Private Relay: https://blog.cloudflare.com/icloud-private-relay
What if your ISP is working with the local cops or US government directly?
Trusting local parties of US parties is not a strange thought, especially since I can influence their supervision with my vote. Also, it seems plausible that the US is headed into dictatorship or civil war in the near future. Nether scenario helps me trust the US jurisdiction.
If that is your threat model, you need something a lot stronger than Private Browsing, whose purpose begins and ends with "I do not want other people to know what porn sites I visit". Tor is a good start.
You mean like an ISP that isn't in (and doesn't unnecessarily route through) the USA?
A user's residential IP address is in many cases almost static, and doesn't change that often. If you use the same residential IP for other services from Apple, or sites that are protected by Cloudflare's MITM DDOS protection, the content of the HTTP site can be linked back to you with a high probability through your IP address, and possibly in combination with other metadata such as the user-agent, or other headers.
Of course, you may think differently regarding your ISP, but that's for each one of us to decide about our own service providers.
The sites that already are MITM'd by Cloudflare are a different story. Cloudflare is going to know what IP address visited them at what time, and if you login with your personal email address, or if your personal phone number is shown in your account settings, then your identity is linked with some probability to that IP address+time.
If you then browse a non-CF HTTP site, using Apple's proposed proxy, there would be the risk that your identity+IP address that CF knows become associated with using the HTTP site as well.
If you don't use Apple's proxy at all, you connecting to a non-CF HTTP site would only be known by your ISP.
There’s no need for this ridiculous game of charades with private relay. Why on earth would Apple bother spending so much money setting up this infrastructure to spy on a browser they own, running on an OS they also own. It would be like arguing that your bank is secretly in cahoots with shops to spy on your transaction history, because of some reason they can’t do the obvious thing of just spying on your transaction history, which they already have by virtue of being your bank.
Your claim is ridiculous and doesn’t stand up to even a modicum of scrutiny. Unless you know of reason for believing that Apple is secretly spy on their customers, but only doing in the most convoluted way possible?
Even if it doesn't happen today, there is a realistic, technical possibility that the data flow could be exploited tomorrow. If the infrastructure is already there, and future incentives are found, what prevents the infrastructure from being exploited in the backend?
It is an easely exploitable system, and that's worth discussing and be conserned about.
But still, you bring up a good point. This is relatively convoluted to other ways Apple could harvest data if they wanted to. In fact, they already are harvesting much more data than unencrypted HTTP content by pushing iCloud onto its users.
Even if this was an attampt by Apple to gain good will, it has serious flaws, and Apple isn't generally a trustworthy company, and the jurestiction it operates under is not trustworthy either.
This feature is being sold as a strong privacy tool, and it's beneficial to discuss its flaws in isolation.
Could you provide some evidence for this claim, beyond the fact that all companies are profit motivated, and thus can only be trusted to protect their bottom line.
> This feature is being sold as a strong privacy tool, and it's beneficial to discuss its flaws in isolation.
Not really, all security and privacy is relative. You can discuss any security or privacy tool in isolation and find fault. But that’s not actually useful, because the only conclusion you could possibly derive from such an approach is that only truly secure and private way to exist is inside a small box disconnected from the rest of the world.
> Even if it doesn't happen today, there is a realistic, technical possibility that the data flow could be exploited tomorrow. If the infrastructure is already there, and future incentives are found, what prevents the infrastructure from being exploited in the backend?
That’s a rather silly question. It only makes sense to worry about this hypothetical if you already have strong argument for why Apple et.al. wouldn’t just compromise the browser or OS instead. The more parties needed to assemble a complete data flow, the more people that are needed, and more likely some will leak the fact this activity occurring. That the whole point of making a big song and dance about both Apple and 3rd parties being involved in Private Relay. Both parties have to be compromised to get valuable data, that’s much harder than compromising a single organisation.
Talking about all this silly hypotheticals deliberately ignores the simple fact that people will always choose the simplest, easier route to solving a problem. Putting forward the argument that a nation state or a private organisation is gonna bother attacking Private Relay, but not your ISP and unencrypted HTTP connections (which we know are already tapped at major internet exchanges) is ridiculous, bordering on paranoid.
Every request goes via an Apple node first, then is sent to a 3rd party node for final routing. That way neither Apple nor the 3rd party have a complete picture of where a request came from, or where it went.
Not entirely sure why you would trust a random ISP, and everyone else involved in routing that connection, more than Apple. Last I checked most ISP don’t have the tightest privacy policies, or even the best data handling practices. Apple stands to loose millions if they slip up on their privacy promises. Most ISP wouldn’t even bother telling you if they accidentally misplaced your personal details.
I’ve got one too, it’s taken me 25 years to find.
And no NAT!
And do I really need more bandwidth?
See also Mozilla turning on routing DNS traffic to Cloudflare by default because that's the level of trust this American organisation has in their ISPs, but after concerns raised in other countries they decided to turn it off by default at least where I'm from in western Europe (not sure about the rest of the world)
(I don't use iCloud Private Relay.)