.::browser::.

updated 2026-07 · 14 min read · index

you are followed two ways at once. by trackers loaded into the pages you visit (scripts, pixels, third-party cookies), and by your browser's own fingerprint, the near-unique combination of user agent, screen, fonts, hardware and settings that identifies you with no cookie at all. a good setup fights the first hard, and is careful not to make the second worse. these two goals sometimes pull in opposite directions, which is the whole subtlety of this page.

the browser choice is a tradeoff, stated plainly

first, the objection any honest guide has to concede is that there is no browser that simply wins, only trades between three axes. content blocking, killing trackers and ads before they load. security architecture, surviving a malicious page that attacks the browser itself. fingerprint resistance, not standing out from the crowd. every browser leads on one axis by giving ground on another, so the pick follows your threat model, not a leaderboard.

on the content-blocking axis, one technical fact does settle things. full ublock origin depends on the blocking webRequest api that chrome's manifest v3 removed. it stopped working on stable chrome with chrome 138 (july 2025), and the web store purges the remaining manifest v2 extensions through 2026, while firefox has committed to keeping manifest v2. chrome's replacement api caps filter rules and forbids the dynamic blocking that makes a content blocker effective against fast-rotating tracking infrastructure.

extensions that actually help

every extension is code you trust with everything you read and type, and every extension adds bits to your fingerprint. the goal is the shortest list that does the job, not the longest. these earn their place:

ublock origin essential content blocker

the one that matters, and close to the only one most people need. a wide-spectrum blocker that stops ads, third-party trackers and known-malicious domains before they load, on very low memory and cpu. default settings are already strong. the advanced "dynamic filtering" mode lets you allow or block per-site, per-request, which is powerful and worth learning. cisa has recommended content blockers as a defense against malvertising and drive-by malware, so this is a security control, not just a comfort. install it from the official source and enable a couple of extra filter lists (annoyances, privacy) and you are done.

a password manager essential bitwarden / keepassxc

unique strong passwords everywhere so a single breach never cascades, generated and stored for you. the phishing benefit is underrated. a manager fills your bank password only on the exact domain it was saved for, so a convincing lookalike gets nothing, because the url does not match. bitwarden if you want sync (hosted, or self-hosted with vaultwarden). keepassxc if you want a purely local encrypted file you control end to end. pair it with a hardware key or an authenticator app for two-factor. arguably the single highest-impact tool on this entire site.

firefox containers recommended multi-account containers

the built-in way to keep sites in separate cookie jars, so a login in one context cannot follow you into another. with the multi-account containers add-on (plus temporary containers for one-off isolation), facebook lives in its own sealed box, your work google and personal google never see each other, and a pseudonymous session cannot leak into your real identity. this is compartmentalization built into the browser, and the cleanest defense against cross-site tracking without breaking logins.

the smaller wins optional clearurls, cookie cleanup

clearurls strips tracking parameters from links, the utm_* and click-id tails that follow you between sites. if you do not run strict tracking protection, cookie autodelete wipes a site's cookies when you close its tab. and then stop. two old favourites, decentraleyes and standalone referrer-control add-ons, are largely redundant now that firefox handles those cases natively, and every extra extension is more attack surface and more fingerprint for a shrinking return. more extensions is not more privacy.

settings that matter, in five minutes

in firefox: enhanced tracking protection on strict, telemetry and studies off, https-only mode on, and change the default search engine if you would rather not route every query through google. that is most of the benefit for almost none of the effort. resist the urge to hand-edit fifty about:config flags from a forum thread, for the reason in the next section.

search

your search history is one of the most intimate datasets that exists about you, and google ties it to your account, your ip and its ad machine. leaving it costs one minute in settings, so this section has no google in it. the honest landscape, from turnkey to sovereign.

and then there is the niche shelf, small independent indexes that are not trying to replace the engines above. they are discovery tools for the web that commercial ranking buried, and they collect nothing worth speaking of, because nobody is monetizing them.

a sober note on this shelf: stract, the most promising of the recent one-person engines, no longer answers searches, and its old domain now sells pr software. small indexes run on one person's evenings. enjoy them, donate if you can, and keep a daily driver from the list above.

the fingerprint paradox

the more you customize, the more unique you look. a heavily tweaked firefox can be more identifiable than a stock one, because almost nobody else has your exact set of changes. you have traded cookie-tracking for fingerprint-tracking. eff's cover your tracks tool lets you measure how identifiable your browser actually is. if you want deep hardening, do not improvise it. use a curated, community-reviewed config like arkenfox user.js, or simply run librewolf, which ships those defaults. understand that you are trading convenience and blending-in for a stricter policy, and decide whether your threat model is worth it.

the same logic applies to the spoofing extensions people keep asking about, chameleon and user-agent switcher and manager. they randomize or rewrite what your browser claims to be, per site or per session, which sounds like camouflage. the catch is that a claim can be checked. advanced scripts compare the user-agent string against dozens of signals it cannot fake (rendering quirks, fonts, javascript behavior, the network stack), and an inconsistent identity is itself a strong fingerprint. arkenfox and the tor project both advise against extension-level spoofing for exactly this reason, and engine-level protection (firefox's resistfingerprinting, librewolf, mullvad browser) does the same job coherently instead. if you enjoy per-site identity control and accept being detectable as a spoofer, chameleon is the better built of the two. know the trade before you install.

when you need to actually disappear

tor browser, unmodified, is the tool for real anonymity: don't resize the window, don't install extensions, don't log into accounts that know you, don't maximize. its entire design is that every user presents an identical fingerprint, and every change you make chips at that. where tor is blocked, bridges (including obfs4 and snowflake) get you onto the network. mullvad browser, covered above, is that same engineering at everyday speed, without the tor network.

the myth worth killingprivate or incognito mode only clears local traces on your own machine, cookies and history. the sites you visit, your dns resolver, your isp and your employer's proxy see exactly the same traffic as a normal window. it hides your browsing from someone who later uses your computer, and from no one else.

sources

[ home ]

.::  eof  ::.