Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

Private Browsing Hides Less Than Its Name Suggests

A private window prevents your own device from keeping a record, and does almost nothing about the parties on the other end of the connection.

Individual using a VPN application on a laptop at a desk in a modern office setting.
Photograph by Dan Nelson via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Private browsing is widely understood as anonymity. The feature is precisely scoped, and what it covers is the local machine rather than the network.

The mode is a disposable container

Opening a private window creates a fresh storage area with no cookies, no history and no cached files carried over from the ordinary session.

When the window closes, that area is discarded. Nothing written during the session persists to the profile.

The design goal was somebody sharing a computer, and against that threat it works exactly as described.

The network sees the same traffic

Requests leave the device identically whether the window is private or not. The network operator, the employer and the connection provider observe no difference.

Encryption hides the content of pages from those parties in both modes, and the addresses being contacted remain visible in both.

The mode changes nothing about the route, the identity of the endpoints or what is recorded along the way.

Sites can still recognise the visitor

Starting without cookies removes the simplest identifier, but a great deal of identifying information is transmitted by any browser as a matter of course.

Screen characteristics, installed fonts, language settings and the precise behaviour of the rendering engine combine into a signature that is often close to unique.

Logging into an account discards the protection entirely. From that moment the session is attributed to a person regardless of how the window was opened.

Isolation between windows is the useful property

Because the private session holds its own cookies, it can be logged into a different account on the same service simultaneously.

This separation is genuinely useful and is the reason many people use the feature daily, quite apart from privacy.

Some browsers generalise it into named containers that persist, which provides the isolation without the pretence that anything is hidden.

Traces still leak locally

Name lookups may be cached by the operating system rather than the browser, and downloaded files remain on disk after the window closes.

Managed devices frequently log activity at a level the browser does not control, so the local guarantee has exceptions on exactly the machines people most want it on.

Described accurately, the mode is a way to avoid leaving a record in one specific place. Every other observer is unaffected.

Questions readers ask

What happens if I lose my phone?

If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.

Is a passkey the same as biometric login?

No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.

Data & Privacysecurityauthenticationcryptographyaccounts
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas