What this protects, and what it doesn't
Protects
- Against most cross-site tracking by advertisers and data brokers through third-party cookies and known tracking scripts.
- Against someone on the same Wi-Fi or your internet provider reading which pages you load over plain HTTP, and (with encrypted DNS) seeing the names of the sites you look up.
- Against a malicious or sold-off extension reading every page you visit, by keeping only the few extensions you really need.
- Against one account or activity leaking into another, by keeping work, personal and sensitive browsing in separate profiles or containers.
Does not protect
- It does not hide your IP address. Sites, your provider and anyone they share data with still see where you connect from.
- It does not stop browser fingerprinting completely. Your screen size, fonts and hardware still make you stand out; only Tor Browser is built to make its users look alike.
- It does not protect you once you sign in. A site you are logged into knows who you are, whatever your settings.
- Encrypted DNS hides lookups from the local network, not from the DNS provider you choose, and the site address still shows in other parts of the connection.
Prerequisites
- An up-to-date browser: Firefox, Brave or Chrome. Updates fix security holes, so turn automatic updates on.
- A list of the extensions you have installed (open the browser's extensions or add-ons page).
Step by step
-
Turn on stronger tracking protection
Firefox: open Settings, then Privacy & Security. Under Enhanced Tracking Protection, choose Strict and reload your tabs. Strict blocks social media trackers, cross-site cookies, tracking content in all windows, cryptominers and fingerprinters. It can break a few sites; you can switch protection off for one site from the shield icon in the address bar.
Firefox also keeps each site's cookies in a separate "cookie jar" (Total Cookie Protection), on by default for desktop users, so a tracker embedded on many sites cannot join up your visits through cookies.
Brave: Shields are on by default and block third-party ads and trackers, cross-site cookies and fingerprinting attempts. For more protection, set Shields to Aggressive, which may break more sites. You can turn Shields off for one site from the Shields icon in the address bar; other sites stay protected.
-
Block third-party cookies
Chrome: open Settings, then Privacy and security, then Third-party cookies, and choose Block third-party cookies. Some sign-in pop-ups and embedded content may stop working; you can allow a specific site from the same page.
In Firefox (Strict) and Brave (Shields), cross-site cookies are already blocked by the previous step.
-
Always use HTTPS
HTTPS encrypts the page between your browser and the site. Make the browser try HTTPS first and warn you before loading an unencrypted page:
- Firefox: Settings → Privacy & Security → HTTPS-Only Mode → enable it in all windows. If an old site only works over HTTP, add an exception with Manage Exceptions.
- Chrome: Settings → Privacy and security → Security → under Secure connections, turn on Always use secure connections and choose to be warned for insecure public sites (or public and private sites).
-
Encrypt your DNS lookups
Every time you visit a site, the browser asks a DNS server for its address. Without encryption, anyone on your network and your internet provider can read those questions.
- Firefox: Settings → Privacy & Security → DNS over HTTPS, choose a protection level and, if you want, a provider. Firefox shows whether it is active; it switches itself off on some networks (VPN, parental controls, company policies).
- Chrome: Settings → Privacy and security → Security → under Advanced, turn on Use secure DNS and keep your provider or pick one from the list. It is not available on managed devices or with parental controls.
Encrypted DNS goes around your local DNS server, so filtering or parental controls that rely on it stop working in that browser. You are trusting the DNS provider you choose instead of your internet provider.
-
Keep few extensions, from the official source
An extension with "read and change all your data on all websites" sees every page, including your bank and your e-mail. Open your extensions page and remove everything you do not use every week. Extensions get sold and updated with tracking code without much notice.
A content blocker is the one extension most people should keep. uBlock Origin is free and open source; install it only from your browser's official add-on store as linked from its official project page. The website ublock.org is not related to uBlock Origin. On Chrome, which is phasing out the older extension format, the project offers uBlock Origin Lite, a pared-down version with fewer features. Brave users already have blocking built into Shields and do not need it.
-
Separate your browsing
Use different browser profiles (or a second browser) for activities that should not meet: work, personal accounts, and anything sensitive such as health or legal research. Each profile has its own cookies, history and logins.
In Firefox, Mozilla's Multi-Account Containers add-on keeps sites in colour-coded tabs with separate cookies inside one window. Install it only from addons.mozilla.org.
-
Clear cookies when you close the browser
For a profile you use for sensitive browsing, delete cookies and site data every time you close the browser, so nothing carries over to the next session. In Firefox, this is the Delete cookies and site data when Firefox is closed option under Privacy & Security; you can add exceptions for sites you want to stay signed in to. In Chrome, you can delete browsing data from Privacy and security.
Private or Incognito windows do this automatically for one session, but they do not hide you from the sites you visit or from your network.
-
Know when to switch to Tor Browser
The steps above reduce tracking; they do not make you anonymous. If you need to hide who is visiting a site (your IP address and identity), use Tor Browser. It is engineered so that its users have a nearly identical fingerprint, for example by putting window sizes into a few shared groups.
Do not add extensions to Tor Browser: the Tor Project strongly discourages it, because an add-on can make your fingerprint unique and harm your privacy.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Installing five privacy extensions on top of each other. They conflict, slow the browser and make your fingerprint more unique, not less.
- Downloading a "uBlock" from a search ad or an unofficial site instead of the official add-on store.
- Thinking a private window or a hardened browser hides you from sites you are logged into.
- Turning everything to the strictest level, then switching protection off for every site that breaks, and forgetting to turn it back on.
- Adding extensions or changing settings in Tor Browser, which defeats its "everyone looks the same" design.
Going further
Review your browser's site permissions (camera, microphone, location, notifications) and remove those you did not mean to grant. If your threat model is Medium or High, use a separate, hardened browser profile for sensitive work only, and use Tor Browser when the identity of the visitor must stay hidden. To see what any site can read about your browser before and after these changes, open the Browser Fingerprint Inspector.