Helping people with computers... one answer at a time.

Google Chrome offers Incognito mode, and IE8 offers InPrivate browsing. We'll look at how they work, and how private they really are.

Google Chrome promises Incognito mode. Is it true that no record of your web browsing is kept and in the future can not be recovered? I thought windows kept a log of everything you did as a matter of course. Scenario: could the law enforcement agencies find the web sites you have visited if you were using incognito mode?

Ah yes, "Incognito" in Chrome, and "InPrivate Browsing" in Internet Explorer 8.

Also known as "Porn mode" to the rest of us.

Let's review what these features do, and just how paranoid you should be when using them to surf porn whatever it is you want kept private.

First, let me address something from your question:

I thought windows kept a log of everything you did as a matter of course.

No.

Windows does not keep a log of everything you do. Period.

"Windows does not keep a log of everything you do. Period."

Now, that being said, Windows can be configured to log a lot of what you do, and the applications you use can often log a lot of what you do, and of course spyware can log a lot of what you do, but the statement "Windows logs everything" is simply untrue.

Let's look at what Google's Chrome says about Incognito browsing (IE8's "InPrivate" is similar in concept):

Pages you view in this window won't appear in your browser history or search history, and they won't leave other traces, like cookies, on your computer after you close the incognito window.

Read that carefully, because that's all that Incognito mode does:

  • It doesn't add sites to your browser history

  • It doesn't add searches to your search history

  • It doesn't leave cookies behind

That's a pretty short list. In fact, the list of what could still happen is longer:

  • Anything you download, like pictures, MP3's or video, remains.

  • Any bookmarks you create remain.

  • The websites you visit may still have your visits in their logs.

  • Your ISP can always see what you're doing if they elect to, unless you take additional steps such as using a VPN.

  • Malware can still collect everything you're doing.

I also like that Google mentions that Incognito Browsing will not prevent people from watching over your shoulder, or protect you from "Surveillance by secret agents". Smile

One thing Google does not mention explicitly in Chrome documentation is how Incognito affects the browser cache. I have to say that Incognito would be kinda pointless unless it also affects the cache (i.e. things that might be cached in an Incognito session should be removed on exit), but I've not seen confirmation on that.

So, let's get to the meat of your question: could someone still figure out where you've been going even if you've been using Incognito or InPrivate modes?

Maybe.

I'll leave aside the fact that all bets are off if there's spyware installed.

One of the most fundamental concerns, as I see it, is that even in an incognito mode the browser still keeps information in memory (RAM). That, in turn could be swapped to disk into the paging or virtual memory file under certain circumstances.

And yes, to a truly dedicated individual that could be found.

Easy? Nope. Possible? Yes. Likely? That's harder to say. It depends on a lot of things coming together. My gut says it's not very likely, but of course I could be wrong (and the technologies could change).

My advice is to look at it this way: Incognito and InPrivate are the equivalent to automatically clearing your private data when your done - clearing the cache (we think), cookies, your browsing history and the like.

And nothing more.

That's a fine level of privacy for many needs, most notably looking at, ah ... art images.

But if you're truly paranoid, or really, truly need much more security than that advice provides, you should not rely on these browser features, but should be taking additional steps that are more clearly understood, and more completely in your control.

Article C3739 - May 22, 2009

Leo Leo A. Notenboom has been playing with computers since he was required to take a programming class in 1976. An 18 year career as a programmer at Microsoft soon followed. After "retiring" in 2001, Leo started Ask Leo! in 2003 as a place for answers to common computer and technical questions. More about Leo.

Not what you needed?

Recent Comments
9 Comments

The main idea behind the privacy mode is that you don't have to clean up after you and leave any previous history as it was. Only the privacy session does not leave traces. Quite useful when using someone else's or a public computer.. Besides cleaning up after you takes time and effort.

Posted by: Rahul at May 26, 2009 8:40 AM

I think Leo really hit the nail on the head, as usual. As for law enforcement, if it's ever been on your hard drive, and that particular file has not yet been overwritten, they can and will find it. Period. Spyware is another major concern with privacy. I think the bottom line is - make sure what you are doing on your PC is legal!!! If anyone has ever tried even some of the freeware recovery tools such as 'Recuva', you'd be amazed at what you'll still find on your hard drive. Law enforcement spends millions a year on computer forensic tools and software. Handybits file shredder is a great freeware program to try if you want to delete a file and make it "un-recoverable". They claim to overwrite the deleted file to NSA and Military specifications.

Posted by: Dave Markley at May 26, 2009 10:29 AM

I don't trust those filters no matter what they say. As an example... You may want to search something medical - like diabetes and not do so on a work machine because you don't want them knowing anything about your medical history. Wanting to Hide things can have NOTHING to do with porn.

Posted by: Sandy Smith at May 26, 2009 12:35 PM

I think the real problem is not what is stored on my computer but what records the ISP retains about my surfing and downloading. I understand that there is now or is going to be a new UK law that requires the ISP to keep a record of everything we do including our emails. UK is now a proper police state brought about by what I believe are three antichrists: Blair, Brown and Mandelson.

Posted by: robin at May 27, 2009 8:06 AM

Would a better solution be if you use a virtual machine like VMWare for 'incognito' browsing and reverting back to a snapshot. Wondering if reverting leaves a previous state that could be revived. Can downloaded material within virtual OS transferred to thumb drive be recovered from hard drive?

It's a good approach, as it would make recovery more difficult, at least. Yes, you can transfer files between the VM and host if you like. If you want to be extra paranoid, I'd place the VM hard disk image on an encrypted TrueCrypt volume, so that it was completely unrecoverable when the volume wasn't mounted.
- Leo
28-May-2009

Posted by: Paul at May 27, 2009 5:16 PM
Post a comment on "Do new browser features offering privacy really work?":





Remember Me?

(You may use HTML tags for style)

Before commenting, please...

  • READ THE ARTICLE. A comment that shows you didn't will be deleted and ignored.

  • Comment only on the article. Use the search box at the top of the page if you have a question about something else.

  • NO PERSONAL INFORMATION in the comment. No email addresses. No phone numbers. No physical addresses.

  • Anything that looks the least bit like spam will be deleted. Links to unrelated sites or links that appear to be primarily promotional will be deleted, or the comment will be deleted.

  • Don't ask me to recover lost passwords or hacked accounts. I can't. Those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...