Many Internet browsers offer “private mode” or “InPrivate” mode to protect surfers against those who might want to retrace their steps later.
However, a study by scientists at Stanford University in California showed that significant holes remain in the protection offered by such modes. The desired security levels can be negated by certain plug-ins that store information about which Web sites have been visited.
“Many popular browser extensions and plug-ins undermine the security offered by private surfing,” the four authors of the study explained prior to its recent publication at a security conference in Washington. The team, under the leadership of computer scientist Dan Boneh, examined four browsers: Internet Explorer, Firefox, Chrome, and Safari.
The scientists identified 16 extensions in Firefox alone that stored Internet usage data on the hard drive. That data could then be misused by an attacker to spy on information related to visiting specific Web sites.
The authors of the study developed a plug-in of their own which they call “ExtensionBlocker.” The program deactivates all extensions that compromise the security of surfing in private mode.
Private mode is found in Internet Explorer and Firefox under the “Tools” menu. It prevents cookies from being stored on the hard drive and turns off the history function while private mode is on. Cookies are text files that many Web sites use to retain settings for the user’s next visit. The researchers found that private mode is most frequently used to visit erotic Web sites.