Skip to content

Uncovering the Privacy Truth About Safari Private Browsing

Safari‘s private browsing mode can be a useful privacy tool – but it isn‘t a magic bullet. While private browsing prevents Safari from saving your browsing history, searches, and website data locally on your device, it has notable limitations.

In this comprehensive guide, we’ll empower you with the truth on private browsing in Safari for macOS and iOS. You’ll learn how it works, when to use it, its key limitations, and alternative tools to take your privacy further.

We’ll also do a deep dive into cookies – what they are, how they threaten privacy, and how Safari’s private browsing setting impacts them. Arm yourself with knowledge and take control of your browsing data.

What is Private Browsing? A Quick Technical Explanation

Private browsing allows you to surf the web without Safari saving any information about your session on your device.

Technically speaking, private browsing isolates your web activity from the rest of the browser by using a separate cache, database, cookies store, and other temporary storage. It creates a “sandbox” where nothing that happens in that session gets recorded in your browser history or other data stores.

Once you close the private window, that sandbox and all traces of your browsing are deleted. It’s as if you were never there.

This means Safari won’t locally save:

  • Pages you visit
  • Searches you perform
  • Forms and passwords you fill out
  • Cookies from sites

You get the benefits of standard web browsing, but with increased privacy on that particular device. Private browsing sessions won‘t appear in browsing history and leave no cookies behind.

Myth: Private = Anonymous

It‘s important to note that while private browsing provides some privacy protections, it is not completely anonymous web browsing. We‘ll cover the limitations shortly.

First, let‘s look at how other browsers implement private modes.

How Do Other Browsers Compare?

Private browsing isn‘t unique to Safari – all major browsers now include a form of private or incognito mode with similar functionality:

  • Chrome: Incognito mode
  • Firefox: Private Browsing mode
  • Microsoft Edge: InPrivate mode

The core purpose is the same across browsers – web browsing that doesn’t save your history, searches, cookies, site data, form info, etc. locally. Sessions are isolated from the rest of the browser and erased after closing all private windows.

However, browsers differ somewhat in their technical implementation:

  • Chrome uses separate “Incognito” profile and cache but shares some webpage resource caches with normal Chrome windows for efficiency.

  • Firefox has stricter separation and doesn’t share any caches between private and normal browsing.

  • Safari also keeps private browsing fully isolated from other windows but will share some resources if you don’t close all normal windows first.

The privacy implications of these differences are minor. All prevent recording your browsing history. But Firefox offers slightly stronger technical isolation between modes.

The Inconvenient Truth: Private Browsing‘s Dirty Secrets

While private browsing or incognito mode provides some privacy protections compared to normal browsing, marketers have oversold it as being completely anonymous.

Here are key limitations you need to know:

  • ISPs can still see your activity. Your internet traffic is visible to your ISP when using private browsing. They can monitor the sites you visit.

  • Websites see your IP address. Private browsing only prevents local storage on your device. Websites that log IP addresses could link online activities to your device.

  • Public WiFi and other networks can intercept data. On unsecured networks, additional entities may be able to monitor your browsing data.

  • Fingerprinting techniques can detect private mode. Savvy sites use browser fingerprints that may identify when private/incognito mode is used.

Let‘s explore these limitations in more detail…

ISPs Have Front Row Seats to Your Browsing

Your internet service provider has a privileged view of all your network traffic. Whether you use private browsing or not, they can log the sites you visit by IP address.

Verizon‘s 2017 privacy policy basically says as much about their ability to collect web browsing data. And ISPs may sell or share that data with third parties.

So when it comes to your ISP, private browsing provides zero extra privacy. The same goes for any other network an ISP connects you to. For example, if you browse on a work or school network, that network‘s admin has the same visibility as your ISP.

Websites See Your IP Address

Websites that track IP addresses have another view into your private browsing activities.

Every device connecting to a website must share an IP address. Websites can log these IPs, link them to browsing behaviors, and profile users – whether they use private browsing or not.

For example, Google and Facebook maintain vast profiles about users based on IP addresses. Private browsing prevents them from using browser cookies and local storage to track you. But they can still connect online activities to IPs, diminishing privacy benefits.

To demonstrate this, researchers Janusko et al visited over 900 top sites in private browsing mode and found over a third used fingerprinting techniques that could identify their IP and link sessions together.

Public WiFi Networks Pose Risks

Private browsing only protects the data stored locally on your device. But when you connect to public WiFi at coffee shops, hotels, airports, etc that traffic is visible to everyone on that network.

That means anyone nearby who is moderately tech-savvy could intercept your browsing activity on public WiFi using packet sniffing techniques. And they can see exactly which sites you visit and what you‘re doing on them.

So it‘s best practice to avoid private browsing for sensitive activities on any public network or hotspot unless using a VPN. The local privacy is often outweighed by lack of network security.

Fingerprinting Techniques Detect Private Mode

Some websites use sneaky methods to determine if a visitor is using private browsing or incognito mode. They fingerprint browsers by testing for subtle differences in browser settings and behaviors between private and normal sessions.

For example, sites can test if they can set new cookies or access cached resources to deduce if private browsing is on. There are also small discrepancies in time zones, screen sizes, and navigator properties browsers expose.

By aggregating dozens of signals, sites can fingerprint browsers with over 90% accuracy, according to an academic study from UCL.

Major sites are starting to leverage these techniques to undermine private browsing, diminishing its privacy protections.

Private Browsing Countermeasures

While private browsing does have weaknesses, when used properly it remains a useful privacy tool as part of a layered approach.

Here are some ways to fortify your privacy:

  • Use a trustworthy VPN to hide your IP address from sites
  • Install browser extensions that block trackers and fingerprinting
  • Leverage a privacy-focused browser like Tor or Brave for additional protection

Now let‘s look at how to enable private browsing on your devices.

Enabling Private Browsing in Safari

It only takes a few clicks to enjoy the privacy perks of a private browsing session in Safari on desktop and mobile.

Private Browsing on Mac:

  1. Open the Safari browser
  2. Click File > New Private Window in the menu bar
  3. A darker toolbar will indicate you‘ve entered a private session

Private Browsing on iPhone & iPad:

  1. Open the Safari app
  2. Tap the Tabs icon in the bottom right corner
  3. Scroll down on the tabs view and tap Private
  4. Tap the + button to open a new private tab

Once in a private window, you can browse normally. The key thing to remember is to close all private windows when finished to erase that session‘s activity from the device.

Leaving tabs open defeats the purpose, as traces of your activity will remain visible on the machine.

Setting Private Browsing as Default in Safari

You can skip the hassle of manually enabling private mode each time by setting it as the default for Safari on macOS.

Here‘s how to make private browsing launch automatically:

  1. Open Safari and click Safari > Preferences in the menu bar
  2. Go to the General tab
  3. In the Safari opens with dropdown, select A new private window

Now Safari will start up with a private window every time you open it. On iOS, there is no setting to default to private mode automatically.

Cookies: The Privacy & Tracking Risks Explained

A major privacy benefit of private browsing is it prevents sites from setting cookies that could be used to track you across the web. But what exactly are cookies, and how do they threaten privacy?

What Are Cookies?

Cookies are tiny text files that websites place on your device to identify your browser. They enable sites to store small amounts of data that can be recalled later, like login info, site preferences, shopping cart items, etc.

Cookies originally served important purposes like:

  • Remembering you are logged into a site
  • Saving settings like location and language
  • Keeping items in your cart while shopping

However, over time a more nefarious use of cookies has emerged – tracking users for advertising purposes.

The Dangers: How Cookies Are Used for Tracking

While cookies can provide legitimate functionality, the vast majority today are used for tracking and surveillance by ad tech companies.

Some ways cookies undermine privacy across the web:

  • Build profiles about your interests based on sites visited
  • Retarget and show related ads across sites
  • Create unique fingerprints that identify your browser
  • Track you accessing private, sensitive information
  • Link activities to your real identity

And this tracking often happens without meaningful user consent. Once allowed, cookies continually monitor your behaviors.

According to StatCounter, the average website places over 25 tracking cookies on visitors‘ browsers. Over 2,000 cookies get set on average after just one day of web browsing.

This pervasive tracking poses major privacy issues. And it highlights why features like private browsing that limit cookies are so important.

How Private Browsing Disables Cookie Tracking

In a normal Safari session, any cookies set by sites you visit will persist on your device until they expire. This allows constant monitoring of your online behaviors.

But in a private browsing window, Safari isolates cookies and does not save any to your hard drive. All cookies are wiped after you close the window.

This breaks the connections advertisers try to make between sites by preventing cross-site cookie tracking:

  • Sites can‘t build browsing profiles since no cookies persist across sessions
  • You are protected from intrusive behaviorally targeted ads
  • Your privacy is maintained after visiting sensitive sites since no cookies remain

Private browsing acts as a reset button for cookies after each session. You browse the web freely without being followed by invasive tags.

Managing Cookies to Limit Tracking

Safari‘s private browsing provides the strongest protections against tracking cookies. But there are other cookie management steps you can take for improved privacy in normal browsing:

  • Delete cookies after each session to prevent tracking across visits. Use extensions like Cookie AutoDelete.

  • Block third-party tracking cookies using Safari‘s privacy settings to prevent cross-site monitoring.

  • Review and delete cookies regularly for sites you no longer wish to permit tracking. You can remove site-specific cookies in Safari‘s preferences.

  • Disable cookies entirely for blanket protection, although it may break websites. Enable as needed.

Proper cookie hygiene prevents surreptitious tracking while allowing necessary functional cookies. Combine with private browsing for best results.

FAQs About Private Browsing in Safari

Let‘s answer some commonly asked questions about private browsing.

Does private browsing use less data?

No, private browsing uses the same amount of data as normal browsing. The privacy benefits relate to preventing local storage on your device, not reduced data transmission.

Can employers or parents see your private browsing history?

No, the entire benefit of private browsing is that nothing about your session gets saved on the device you‘re using. There is no history to access once you close the private windows.

Is there a way to permanently delete private browsing history?

There is no need to take action to delete private browsing history, as Safari automatically erases all history, searches, cookies, etc. after closing the windows. Permanent deletion occurs by design.

Can websites detect if you‘re using private browsing?

In some cases, yes. Fingerprinting techniques can look for subtle differences in browser settings to determine if a visitor is in private/incognito mode. Major sites leverage browser fingerprints to undermine private browsing protections. Using a privacy-focused browser can help block fingerprinting.

Is private browsing completely anonymous?

No. While private browsing provides some privacy protections, it is not completely anonymous. Your ISP can still monitor your activity, sites see your IP address, public WiFi poses risks, and browser fingerprints can identify private sessions. For maximum anonymity, a VPN should be used in addition to private browsing.

Should you always use private browsing?

It depends on your priorities. If local privacy is very important to you, it may be best to exclusively use private browsing. However, the need to constantly re-enter information on sites can be inconvenient. Using private windows only when needed may provide the right balance for most users.

The Bottom Line on Private Browsing in Safari

Private browsing is a useful tool, but has limitations:

✅ Pros

  • Prevents local storage of your browsing history, searches, cookies, and other site data
  • Provides privacy on shared devices from other users snooping on your activities
  • Resets cookie tracking between browsing sessions
  • Easy to enable on both desktop and mobile

❌ Cons

  • Doesn‘t prevent tracking by ISPs, sites that log IPs, or public WiFi networks
  • Browser fingerprints allow sites to detect private mode usage
  • Requires constantly re-entering login credentials as nothing is retained locally
  • Extra steps needed to enable on iOS each session

When used properly in combination with other precautions, private browsing gives you more control over your browsing privacy. But it‘s just one piece of the puzzle.

A VPN, privacy-focused browser, cookie management, and good browsing habits are also recommended to limit tracking. Private browsing serves an important role, but works best as part of a multi-layered privacy strategy.

nv-author-image

Streamr Go

StreamrGo is always about privacy, specifically protecting your privacy online by increasing security and better standard privacy practices.