{"id":15879,"date":"2019-07-23T09:22:10","date_gmt":"2019-07-23T17:22:10","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/07\/23\/news-9624\/"},"modified":"2019-07-23T09:22:10","modified_gmt":"2019-07-23T17:22:10","slug":"news-9624","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/07\/23\/news-9624\/","title":{"rendered":"Chrome 76 blocks websites from detecting incognito mode"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/sophosnews.files.wordpress.com\/2019\/07\/shutterstock_279059117-compressor.jpg\"\/><\/p>\n<p><strong>Credit to Author: John E Dunn| Date: Mon, 22 Jul 2019 13:24:56 +0000<\/strong><\/p>\n<div class=\"entry-content\">\n<div class=\"entry-prefix\">\n<div class=\"entry-author\"> \t\t\t\t \t \t\t\t\t\t<span class=\"by\">by<\/span> \t\t\t<a href=\"https:\/\/nakedsecurity.sophos.com\/author\/john-e-dunn\/\" title=\"Posts by John E Dunn\" class=\"author url fn\" rel=\"author\">John E Dunn<\/a>\t\t \t \t\t\t\t<\/div>\n<div class=\"entry-sharing\">\n<ul class=\"block social share\">\n<li class=\"facebook\"><a href=\"https:\/\/www.facebook.com\/share.php?u=https%3A%2F%2Fnakedsecurity.sophos.com%2F2019%2F07%2F22%2Fchrome-76-blocks-websites-from-detecting-incognito-mode%2F&#038;title=Chrome+76+blocks+websites+from+detecting+incognito+mode\" data-title=\"Chrome 76 blocks websites from detecting incognito mode\" title=\"Share on Facebook\"><svg style=\"height: 20px;\" viewbox=\"0 0 100 100\" class=\"icon facebook\"><use xlink:href=\"#facebook\"><\/use><\/svg><\/a><\/li>\n<li class=\"twitter\"><a href=\"https:\/\/twitter.com\/home?status=Chrome+76+blocks+websites+from+detecting+incognito+mode+https%3A%2F%2Fwp.me%2Fp120rT-1T6Q\" data-title=\"Chrome 76 blocks websites from detecting incognito mode\" title=\"Share on Twitter\"><svg style=\"height: 20px;\" viewbox=\"0 0 100 100\" class=\"icon twitter\"><use xlink:href=\"#twitter\"><\/use><\/svg><\/a><\/li>\n<li class=\"linkedin\"><a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Fwp.me%2Fp120rT-1T6Q&#038;title=Chrome+76+blocks+websites+from+detecting+incognito+mode\" data-title=\"Chrome 76 blocks websites from detecting incognito mode\" title=\"Share on LinkedIn\"><svg style=\"height: 20px;\"  viewbox=\"0 0 100 100\" class=\"icon linkedin\"><use xlink:href=\"#linkedin\"><\/use><\/svg><\/a><\/li>\n<li class=\"reddit\"><a href=\"https:\/\/reddit.com\/submit\/?url=https%3A%2F%2Fwp.me%2Fp120rT-1T6Q&#038;title=Chrome+76+blocks+websites+from+detecting+incognito+mode\" title=\"Share on Reddit\"><svg style=\"height: 20px;\"  viewbox=\"0 0 100 100\" class=\"icon reddit\"><use xlink:href=\"#reddit\"><\/use><\/svg><\/a><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<p>Have you ever bypassed a website paywall using a browser\u2019s privacy mode?<\/p>\n<p>It used to be a simple hack to read an article without registering, paying, or logging in to the publisher&#8217;s website. But subscription-based websites caught on.<\/p>\n<p>Now, for example, visit any article on The Washington Post news site while in Google Chrome\u2019s Incognito mode, and you\u2019ll get the following message:<\/p>\n<blockquote>\n<p>We noticed you\u2019re browsing in private mode. Private browsing is permitted exclusively for our subscribers. Turn off private browsing to keep reading this story, or subscribe to use this feature, plus get unlimited digital access.<\/p>\n<\/blockquote>\n<p>This is annoying, not because it means the visitor can\u2019t access the story (the publisher is, of course, within its rights) but because it seems to be imposing restrictions on the whole idea of private browsing.<\/p>\n<p>If it\u2019s up to publishers to decide when a visitor is allowed to remain private, is that mode really private?<\/p>\n<h2>Plans to remedy the loophole<\/h2>\n<p>As <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/02\/20\/googles-working-on-stopping-sites-from-blocking-incognito-mode\/\">we reported earlier this year,<\/a> Google agrees and has <a href=\"https:\/\/www.blog.google\/outreach-initiatives\/google-news-initiative\/protecting-private-browsing-chrome\/\" rel=\"nofollow\">laid out its plans<\/a> to \u201cremedy the loophole\u201d websites have been using to detect visitors using Chrome\u2019s Incognito mode.<\/p>\n<p>The loophole in question is Chrome\u2019s FileSystem API, which is disengaged in Incognito mode to keep people\u2019s browsing activity private. Eventually, websites twigged that receiving an error message when checking whether this was accessible was a simple giveaway that visitors had gone Incognito.<\/p>\n<p>This doesn&#8217;t matter to sites that have \u2018hard\u2019 paywalls because a login is required regardless of browsing mode. The issue arises on sites that try to whet readers\u2019 appetites by offering two or three free articles, which means they need to plug ways of beating this limit.<\/p>\n<p><a href=\"https:\/\/www.blog.google\/outreach-initiatives\/google-news-initiative\/protecting-private-browsing-chrome\/\" rel=\"nofollow\">According to Google<\/a>, starting with Chrome version 76 on 30 July 2019, publishers will no longer be able to detect Incognito mode by checking the FileSystem API. And just in case publishers look for other methods &#8211; the FileSystem API being far from the only giveaway &#8211; Google warns:<\/p>\n<blockquote>\n<p>Chrome will likewise work to remedy any other current or future means of Incognito Mode detection.<\/p>\n<\/blockquote>\n<p>The company\u2019s advice to publishers is to adjust their settings to allow more or fewer free articles, or to ask users to log in &#8211; something that\u2019s likely to have paywall site owners muttering under their breath.<\/p>\n<aside id=\"sophos_ad-3\" class=\"widget sophos-inline-ad sophos_widget_ad\">\n<style><\/style>\n<div class=\"sophos_widget_ad\"><a href=\"https:\/\/secure2.sophos.com\/en-us\/security-news-trends\/whitepapers\/gated-wp\/sophos-best-practices-for-securing-the-cloud.aspx?cmp=34494\" class=\"s-ad-secure-cloud__link-wrapper\">    <\/p>\n<div class=\"s-ad-secure-cloud\">\n<div class=\"s-ad-secure-cloud__sophos-logo\">        <svg style=\"height:11px;\" viewbox=\"0 0 132 24\" class=\"block icon sophos\"><use xlink:href=\"#sophos\"><\/use><\/svg>      <\/div>\n<div class=\"s-ad-secure-cloud__title\">        How to secure workloads in AWS, Azure and GCP      <\/div>\n<div class=\"s-ad-secure-cloud__action\">        <span class=\"s-button s-button--small s-button--green\">          Download&nbsp;Guide        <\/span>      <\/div>\n<\/p><\/div>\n<p>  <\/a><\/div>\n<\/aside>\n<h2>Privacy illusion<\/h2>\n<p>Google is spot on with this move. Detecting when users of any browser are using Incognito mode goes against the spirit of privacy, even if it\u2019s not being done to directly track people as such, and any information that some browsers share and others don&#8217;t helps add to a browser&#8217;s <a href=\"https:\/\/nakedsecurity.sophos.com\/2014\/12\/01\/browser-fingerprints-the-invisible-cookies-you-cant-delete\/\">fingerprint<\/a>.<\/p>\n<p>Detecting Incognito mode is also a weak defence that&#8217;s easily bypassed by using different browsers in sequence, for instance Chrome followed by Firefox, Safari and\u00a0 Opera.<\/p>\n<p>Ironically, the real problem with private browsing or anonymity modes is they <em>don\u2019t actually do the job you think they do.<\/em> They block web history from being recorded on a device but not the numerous parties watching web activity, such as ISPs, advertisers, and website owners.<\/p>\n<h2>No, private browsing doesn&#8217;t hide porn site visits<\/h2>\n<p>Unfortunately, a lot of people take the misleadingly named anonymity offered by private browsing too literally, assuming it\u2019ll hide things like visits to porn sites.<\/p>\n<p>It won\u2019t, of course, as a <a href=\"https:\/\/arxiv.org\/pdf\/1907.06520.pdf\" rel=\"nofollow\">recent study<\/a> on the user tracking carried out by websites (including by companies such as Google and Facebook, no less), reminds us.<\/p>\n<p>Never forget that on the internet, everyone can see you click.<\/p>\n<\/p><\/div>\n<p><a href=\"http:\/\/feedproxy.google.com\/~r\/nakedsecurity\/~3\/7mBVTCcCHZk\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/NakedSecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/sophosnews.files.wordpress.com\/2019\/07\/shutterstock_279059117-compressor.jpg\"\/><\/p>\n<p><strong>Credit to Author: John E Dunn| Date: Mon, 22 Jul 2019 13:24:56 +0000<\/strong><\/p>\n<p>Ever bypassed a website paywall using a browser\u2019s privacy mode? It was once a simple hack, however, it no longer works for most websites.&lt;img src=&#8221;http:\/\/feeds.feedburner.com\/~r\/nakedsecurity\/~4\/7mBVTCcCHZk&#8221; height=&#8221;1&#8243; width=&#8221;1&#8243; alt=&#8221;&#8221;\/&gt;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[1670,11427,12152,22422,5897,10436,11114],"class_list":["post-15879","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-google","tag-google-chrome","tag-incognito-mode","tag-paywalls","tag-privacy","tag-private-browsing","tag-web-browsers"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15879"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15879\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}