HomeGuidesHardening your browser in an afternoon

Hardening your browser in an afternoon

You do not need to become a security expert to stop most of the tracking that follows you around the web. You need one afternoon, a handful of settings, and the willingness to leave a few things switched off.

Almost every guide to browser privacy starts by handing you a list of twenty extensions. This one does the opposite. Most of the work is done by four or five decisions, and the rest is noise that will slow your browser down and break the sites you use every day.

What “hardening” actually means

Hardening is not making yourself invisible. It is reducing the number of companies that get a copy of what you do, and reducing the amount they can join together. Think of it as closing the windows rather than moving house.

Before you change anything, spend two minutes on your threat model — who you are actually worried about. Someone avoiding advertising surveillance needs different settings than someone whose ex-partner has physical access to their laptop. If you skip this, you will spend the afternoon fixing the wrong problem.

Step 1: Pick a browser you trust

The single biggest decision is which browser you open in the morning. Any of the well-maintained ones will do: Firefox, Safari on Apple devices, or a Chromium browser that is not built by an advertising company. What matters more is that it updates itself automatically and that you actually keep using it. A hardened browser you abandon after a week protects nobody.

Whatever you choose, turn on automatic updates and restart the browser when it asks. Most real-world attacks use holes that were patched months ago.

Step 2: One content blocker, not five

Install a single, reputable content blocker and stop there. A good blocker removes trackers and ads in one pass; stacking three of them on top of each other mostly produces broken pages and a browser that feels slow, and it makes you more identifiable rather than less.

Expect to whitelist two or three sites — your bank, a work tool, a video player. Learn where the “pause on this site” button is on day one, so that the first broken checkout page does not make you uninstall everything.

Step 3: Turn off third-party cookies

Third-party cookies are the classic way one company recognises you across hundreds of unrelated sites. Every major browser can now block them, and in most of them it is a single switch in the privacy settings. Turn it on.

You will barely notice the difference. The sites you log into use their own cookies, which keep working. What stops working is the invisible handshake between a news site and the ad networks and data brokers behind it.

Step 4: HTTPS-only and a better DNS

Switch on HTTPS-only mode. Your browser will then refuse to load pages over an unencrypted connection without warning you first. On the modern web this breaks almost nothing, and it removes a whole family of problems on public Wi-Fi.

Then consider encrypted DNS. Every time you visit a site, something has to translate the name into a number, and by default your internet provider does it and can see the list. Encrypted DNS moves that lookup to a provider you pick, over an encrypted connection. Be honest about the trade: you are choosing who sees your browsing list, not making it disappear.

Step 5: Separate profiles for separate lives

This is the step people skip and later wish they had not. Use one browser profile for your logged-in life — email, banking, work — and a second one for general reading and searching. Two profiles cost you nothing and break the easiest way to link your identity to your browsing.

If your browser supports container tabs, the same logic applies inside one window: the social network in one container cannot see what you do in another. Whichever mechanism you use, the rule is the same — the profile where you are logged in as yourself should not be the profile where you browse everything else.

Step 6: Decide what survives closing the window

Now choose how much your browser remembers. The comfortable setting is to clear cookies and site data when you quit, while keeping your history and bookmarks. The stricter setting clears everything. Either is fine; what matters is that you decided rather than accepting the default.

If you clear cookies on exit, you will log in more often, so use a password manager — and for a start the one already built into your browser or phone (Apple, Google) is perfectly good, because anything is better than reusing one password everywhere. Private windows are a different tool: they forget locally, but the sites and networks you visit still see you.

Step 7: The address bar and your default search

Two small settings with a surprisingly large effect. First, turn off the suggestions that send everything you type in the address bar to a search engine as you type it — including the half-finished thoughts you never pressed enter on. Second, change your default search engine to one that does not build a profile of you. You can always run a single query on the big engine when you need it.

Fingerprinting, honestly

Even with cookies gone, sites can guess who you are from the combination of your screen size, fonts, language, time zone and graphics hardware. This is fingerprinting, and it is the part of this guide where the honest answer is: you can reduce it, not eliminate it.

Anti-fingerprinting features in mainstream browsers help against lazy tracking. Anything stronger means accepting real inconvenience — a browser that lies about your screen, blocks fonts, and looks broken. If you need that level of protection, you are in the territory of Tor rather than a hardened everyday browser, and it is worth knowing where that line is before you cross it.

Your phone, in ten minutes

Phones deserve their own afternoon, but three settings cover most of it: install a browser that supports content blocking and set it as your default, turn off the advertising identifier in the system privacy settings, and go through the list of apps that have location permission and set most of them to “while using the app” or never. Ten minutes on the phone is often worth more than an hour on the laptop.

The afternoon, in order

  • Update your browser and turn on automatic updates.
  • Install one content blocker. Just one.
  • Block third-party cookies.
  • Switch on HTTPS-only mode; set up encrypted DNS if you are comfortable with it.
  • Create a second profile: logged-in life in one, everything else in the other.
  • Decide what gets cleared when you quit, and set up a password manager.
  • Fix the address bar suggestions and your default search engine.
  • Do the three phone settings.

That is the whole list. If a step fights you, skip it and come back — a browser you can live with beats a perfect configuration you abandon on Tuesday.

What this doesn’t solve

A hardened browser does not protect your messages once they leave the browser; for that, see our guide to encrypted messaging without the myths. It does not hide your traffic from your employer if you are on a managed device, it does nothing about what you voluntarily post, and it will not stop a company you have an account with from collecting what you do while logged in.

What it does do is make you a much harder target for the routine, industrial-scale tracking that treats every reader as a data point. That is a realistic goal, and you can reach it before dinner.

Get the weekly briefing

Five things worth your attention — censorship, privacy, algorithms and digital rights. One email a week, no noise.

We’ll send you a confirmation email first. No tracking, no sharing, unsubscribe in one click. See our Privacy Policy.

Must Read

spot_img