← all articles

Private browsers compared: what each one actually blocks

browsers tracking fingerprinting content-blocking

Disclosure before the table, because it should change how you read it. I sell mobile proxy infrastructure, so my working week is spent on the side of this problem that tries to tell one visitor from another.

Browser Third party cookies, default Fingerprinting Trackers Paid for by
Chrome Allowed Nothing meaningful Allowed Advertising
Edge Partly blocked Nothing meaningful Blocked from sites you have never visited Advertising, and Windows
Safari Blocked Reduction: it reports less Blocked, and tracking parameters stripped from links Hardware, plus a reported 20 billion a year from Google for the default search slot
Firefox, Standard Partitioned per site Known fingerprinting scripts blocked Known trackers blocked A search deal with Google
Firefox, Strict Blocked Same, plus an opt in standardisation mode Blocked Same
Brave Blocked Randomisation, per site and per session Blocked, ads included Its own on device ad network
DuckDuckGo browser Blocked Some reduction Blocked Contextual search ads
Mullvad Browser Blocked Standardisation, Tor’s configuration Blocked A VPN company
Tor Browser Partitioned by first party, everything Standardisation Blocked Grants, historically mostly US government

Brave and Firefox on Strict do the most with no configuration. Safari is genuinely strong on cookies and then hands your default search to the largest advertising company in the world. Chrome finishes last for a structural reason rather than a lazy one.

The row that decides your real protection never appears in tables like this: whether you installed a content blocker.

Blocking and partitioning are different products

Two ways exist to handle a cookie set by a company that is not the site you are on. You can refuse it. Or you can accept it and lock it in a jar labelled with the site you were visiting, so the same tracker on another site gets a fresh jar and cannot join the two.

The second is partitioning. Firefox calls it Total Cookie Protection, and it is good engineering a long way short of blocking. The request goes out. The tracker executes. It just cannot correlate you across sites using that cookie.

That distinction gets flattened in every comparison I have read, because “blocks third party cookies” sounds identical to “keeps third party cookies apart” if you are skimming.

Where it matters: partitioning does nothing about the fingerprint the tracker collects while it runs, or about the request itself carrying your address, your user agent, and the page you were on.

Chrome, in 2026, still accepts third party cookies by default. Google announced their end, moved the date four times, then abandoned the deprecation in 2025. The replacement was a set of in browser targeting interfaces that calculate your interests locally and hand them to advertisers as topics, and by late 2025 several of those were being wound down too. The third party cookie outlived both.

You can switch them off in Chrome settings in about twenty seconds. Almost nobody has.

Randomising or standardising

Fingerprinting is where these products genuinely diverge.

Your browser hands every site a description of your machine. Fonts, screen dimensions, timezone, the exact output of your graphics hardware drawing a test image. Enough of those outlive any cookie you clear.

Brave randomises. Every site and every session gets slightly different answers, so you are never the same person twice. That kills naive fingerprinting outright and it gives a persistent tracker samples to average, and being unlike yourself on every reload is itself unusual.

Tor Browser and Mullvad Browser standardise. Everyone reports the same fonts, the same rounded window dimensions, the same graphics behaviour. Strong when the crowd is big, worthless when it is small, and you shrink the crowd yourself every time you resize a window or add a language pack.

Safari reduces instead. It reports fewer fonts and a simplified system profile, and declines some questions entirely. Less theatre, smaller surface.

Chrome does effectively nothing here. On the advertising side Google went the other way in early 2025 and started permitting fingerprint based targeting its own policies had previously banned.

Who funds it sets the ceiling

A browser built by an advertising company has a limit on how far it will go against tracking. Call that arithmetic, not an accusation. No individual has to behave badly for the ceiling to exist.

That is why Chrome’s position on cookies is predictable rather than surprising, and why Safari can be hostile to trackers while taking a very large annual payment to keep Google in the search bar. Mozilla has been building an advertising business since around 2024, which produced an attribution experiment enabled by default and a terms of use rewrite that annoyed a lot of long standing users.

Brave deserves a fair hearing. Its ads are matched on your device, with no cross site identity following you around, which is a different design from the surveillance model. It remains an advertising business, worth holding in mind before you treat Brave as a neutral referee.

Tor Browser runs on grants, historically mostly from US government sources, which alarms people. It alarms me less than a search deal, because a grant creates no daily commercial incentive to keep you legible.

Private mode protects you from your flatmate

The most widespread privacy misconception there is, so it gets a section.

Private browsing deletes local traces when the window closes. History, cookies, form entries, the session. That is the whole feature.

It does not hide you from the site you visit, your internet provider, your employer, your school, or the network you are sitting on. It will not make you anonymous to a company you are signed into in another window.

What it defends is your own machine against the next person who uses it. That is the threat model it was built for.

Google was sued over exactly this confusion. The case settled in 2024 with an agreement to delete browsing records and rewrite the wording on the Incognito splash screen. The wording improved. The belief did not.

The extension decides more than the browser

For most people the content blocker is the entire game. It stops the tracking request before it leaves the machine, which takes out the cookie, the fingerprinting script, and the ad in one move.

Which is why the most consequential browser change of the past two years had nothing to do with a privacy feature. Chrome completed its extension platform migration and removed the capabilities the strongest blockers relied on. The full version of the blocker most people used no longer runs there. What remains is a reduced edition driven by a fixed rule list.

Firefox kept the old platform working. Brave kept a version of it alive on its own terms.

So if you are on Chrome with a blocker, your protection dropped a level and nothing on screen told you. That fact rearranges the table above more than any fingerprinting benchmark does.

What I got wrong

For a while I graded browsers by whether a fingerprint test page called my configuration unique. That score is close to meaningless and I should have spotted it sooner. The population on those pages is people who deliberately visited a fingerprinting test page, the most privacy hardened crowd on the internet. Being rare among them says nothing about being rare among visitors to a shopping site.

The second mistake cost other people time. For about a year I set up hardened Firefox profiles for friends and family: resist fingerprinting on, Strict mode, third party cookies dead. Nine months later every one of them had either turned the protections off or gone back to Chrome. A banking login that would not complete, a work sign on page that span forever, a video that refused to play.

The protection I delivered was zero, and worse than zero, because they came away believing privacy tooling breaks computers.

What breaks, and why the real number is lower

Sign on flows are the big one. Plenty still pass identity through a third party cookie, and when you kill those the login loop spins with no useful error.

Embedded payment frames. Video from certain providers. Support chat widgets. Sites that route their own images through a domain your filter list happens to cover.

With fingerprint resistance turned all the way up, failures stop looking like privacy failures at all. A video that will not decode. A map that renders blank. A chart that arrives as an empty rectangle.

The correct fix is a per site exception. The common fix is switching the whole thing off, which is why measured protection in the wild sits well below what any benchmark reports.

Where to stop

A mainstream browser, a good content blocker, third party cookies off. That is the honest stopping point for the large majority of people, and I would rather you keep that setup for three years than abandon a stricter one in a month.

Brave out of the box gets you most of the way with no work. Firefox on Strict with a blocker you already trust does the same. On Apple hardware, Safari with a blocker is defensible, and change the search engine while you are there. On Chrome, turn off third party cookies today and accept that your blocker is the weaker edition.

Tor Browser belongs to a threat model where somebody is actively trying to identify you and the consequences are serious. Mullvad Browser is the interesting middle: the standardised fingerprint on the ordinary internet, without onion routing. The settings I run on each are written up here.

Then stop tuning. Returns fall off a cliff after the blocker, and the attention is better spent on the accounts you stay signed into, because those identify you by name whichever browser is doing the asking.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →