/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Super cookies allow sites to track users using most popular browsers even in privacy mode

Browsing in privacy mode?  Super Cookies can track you anyway  —  For years, Chrome, Firefox, and virtually all other browsers have offered a setting that doesn't save or refer to website cookies, browsing history, or temporary files.

Ars Technica Dan Goodin

Context & Ripple Effects

Private browsing has been a promise browsers kept badly. Months after this report, [[a:833383|researchers showed cookies could also bypass HTTPS to expose session data in every modern browser]], and later work found favicon caches leaking identity even under script blockers — a steady drumbeat showing 'incognito' was a UI label, not an isolation boundary.

The vendors' responses define this story's arc: Mozilla began testing tracking protection inside Firefox's private mode shortly after, Google committed years later to anti-fingerprinting and opt-in cross-site cookies in Chrome, and Brave went further by hiding cookie consent prompts altogether. Each move concedes that per-user settings alone cannot stop persistent identifiers.

First-order effects

  • Users of Chrome, Firefox, and other mainstream browsers who rely on privacy mode get a false guarantee: sites can still write and read persistent identifiers outside the cookie jar, so sessions, history, and profiles leak into their normal browsing profile.

Second-order effects

  • The finding forces browser makers into a defensive product cycle — Mozilla ships tracking protection into private mode, Google commits to anti-fingerprinting and opt-in requirements for cross-site cookies, and rivals like Brave differentiate on aggressively blocking consent-and-tracking surfaces rather than just sandboxing them.

Third-order effects

  • If the pattern of researchers defeating each privacy-mode mechanism holds, the industry's endpoint is structural: killing third-party cookie storage outright — as Google began doing by restricting them even for a first slice of Chrome users — rather than promising users that any local mode keeps them anonymous.

The trend: Browser privacy is migrating from user-toggled settings like private mode to vendor-enforced defaults, because persistent-identifier research keeps proving the toggles don't hold.