When you open up a browser window in “privacy mode,” do you know who’s watching? According to new research from the University of Chicago, most users carry misconceptions about what these features do and don’t do — and the information provided by the browser itself doesn’t help.

In a paper presented at the The Web Conference 2018 in Lyon, France last month by masters student Yuxi Wu and researcher Miranda Wei, a survey of 460 participants found that many overestimate the protections provided by private browsing modes, even after they read the information provided by different popular browsers about they do and don’t do.

The authors found that many people were unaware that internet service providers and websites could still track user activity and information while in private mode, a myth perpetuated by misleading browser-provided language such as “browse like no one’s watching.” The research comes from the Security, Usability, & Privacy Education & Research group, or SUPERgroup, led by Neubauer Family Assistant Professor Blase Ur.

“In general, transparency and communication about technology is very difficult,” said Wu, a student in the Master of Science in Computational Analysis and Public Policy program offered by UChicago CS and the Harris School of Public Policy. “It's becoming increasingly important that people need to be better educated about what they're doing and the implications of their behaviors online.”

When you open a new, private browsing window, your browser provides a brief statement about what protections that mode provides. In the study, researchers used the actual disclosure statements from the desktop and mobile versions of Chrome, Edge, Firefox, Safari, Opera, and Brave, as well as one purposefully vague statement that served as a control. Subjects read one of these disclosures, received different browsing scenarios on subjects such as targeted advertising and tracking by employers, and answered various questions on how privacy mode affects these situations.

Most of the disclosures failed to improve users’ understanding of what private mode actually protects. Of the thirteen disclosures tested, only those from the mobile and desktop Chrome browsers produced significantly more correct responses than the control statement. Wu and Wei suggested that the Chrome disclosure format — two bullet-pointed lists of what it does and does not do — was more effective for informing users, as opposed to unclear phrases such as “tracking protection” used by other browsers.

Even the name of the mode could have influenced users; where most browsers use some form of the word “privacy,” Chrome calls its version “Incognito Mode.”

“The term ‘private’ is heavily overloaded, and our results suggest the name ‘private mode’ implies unintended meanings,” the authors write in the paper.

Almost all users understood that private mode prevents browsing history from being saved locally, but that files downloaded in private mode would still remain after the session ended. In some cases, subjects actually underestimate privacy mode functions, most notably on whether the names of files downloaded during a private session would appear in the browser’s download history.

However, most protections were incorrectly overestimated. For example, more than half of participants believed that their search history in private mode was not logged by Google, even if they were logged into their Google account. Many participants also did not realize that their ISP, employer, or the government would be able to track their activity in private mode, and 27 percent mistakenly believed that it offered protections against viruses and malware.

The central theme of these misconceptions was mistaking the local protections of privacy mode for how a user’s activity can still be viewed and saved by service providers and websites. That general confusion could be the result of changes in Internet-connected device ownership, Wei suggested.

“Private browsing mode was created for your local computer, and it was more useful when people were sharing devices, because that's when you really run into other people being able to see what you do and wanting your own individual privacy,” Wei said. “Now that people often have their own devices, even private modes create a data trail that you might think is private, but actually isn’t.”

The study is one of many at SUPERgroup examining how much internet users know about the information collected about their activity online, and how that knowledge changes browsing behavior. Additional co-authors on the paper include Panya Gupta of the University of Chicago and Yasemin Acar and Sascha Fahl of Leibniz University Hannover.

Related News

More UChicago CS stories from this research area.
Video

Nightshade: Data Poisoning to Fight Generative AI with Ben Zhao

Jan 23, 2024

Research Suggests That Privacy and Security Protection Fell To The Wayside During Remote Learning

A qualitative research study conducted by faculty and students at the University of Chicago and University of Maryland revealed key...
Oct 18, 2023

UChicago Researchers Win Internet Defense Prize and Distinguished Paper Awards at USENIX Security

Sep 05, 2023

Chicago Public Schools Student Chris Deng Pursues Internet Equity with University of Chicago Faculty

May 16, 2023

Computer Science Displays Catch Attention at MSI’s Annual Robot Block Party

Apr 07, 2023

UChicago / School of the Art Institute Class Uses Art to Highlight Data Privacy Dangers

Apr 03, 2023

Virtual Bakery Game Serves Up Both Cupcakes and Quantum Concepts For K-12 Students

Mar 27, 2023
Young students on computers

UChicago and NYU Research Team Finds Edtech Tools Could Pose Privacy Risks For Students

Feb 21, 2023

UChicago Scientists Develop New Tool to Protect Artists from AI Mimicry

Feb 13, 2023
Garcia sitting in a jet engine

Student Spotlight: Gabi Garcia’s Bridge Between CS and Classics

Jan 30, 2023

Professors Rebecca Willett and Ben Zhao Discuss the Future of AI on Public Radio

Jan 26, 2023

Professor Heather Zheng Named ACM Fellow

Jan 18, 2023
arrow-down-largearrow-left-largearrow-right-large-greyarrow-right-large-yellowarrow-right-largearrow-right-smallbutton-arrowclosedocumentfacebookfacet-arrow-down-whitefacet-arrow-downPage 1CheckedCheckedicon-apple-t5backgroundLayer 1icon-google-t5icon-office365-t5icon-outlook-t5backgroundLayer 1icon-outlookcom-t5backgroundLayer 1icon-yahoo-t5backgroundLayer 1internal-yellowinternalintranetlinkedinlinkoutpauseplaypresentationsearch-bluesearchshareslider-arrow-nextslider-arrow-prevtwittervideoyoutube