Microsoft Edge received the lowest privacy rating in a recently published study that compared the user information collected by major browsers. Yandex, the less-popular browser developed by the Russian Web search provider Yandex, shared that dubious distinction. Brave, the upstart browser that makes privacy a priority, ranked the highest.
The rankings were revealed in a research paper published by Trinity College Dublin computer scientist Doug Leith. He analyzed and rated the privacy provided by Google Chrome, Mozilla Firefox, Apple Safari, Brave, Edge, and Yandex. Specifically, the study examined the browsers’ sending of data—including unique identifiers and details related to typed URLs—that could be used to track users over time. The findings put the browsers into three categories with Brave getting the highest ranking, Chrome, Firefox, and Safari receiving a medium ranking, and Edge and Yandex lagging behind the rest.
In the paper, Leith wrote:
From a privacy perspective Microsoft Edge and Yandex are qualitatively different from the other browsers studied. Both send persistent identifiers that can be used to link requests (and associated IP address/location) to backend servers. Edge also sends the hardware UUID of the device to Microsoft and Yandex similarly transmits a hashed hardware identifier to back end servers. As far as we can tell this behaviour cannot be disabled by users. In addition to the search autocomplete functionality that shares details of web pages visited, both transmit web page information to servers that appear unrelated to search autocomplete.
Strong, enduring identifiers
Both Edge and Yandex send identifiers that are tied to device hardware, the study found. These unique strings, which can also link various apps running on the same device, remain the same even after fresh installs of the browsers. Edge sends the universally unique identifier of a device to a Microsoft server located at self.events.data.microsoft.com. This identifier can’t easily be changed or deleted. What’s more, the Edge feature that autocompletes website requests—and in so doing, sends details of typed sites to a backend server—can’t be disabled. The researcher said that he was unaware of any way users could disable the data collection.
Yandex, meanwhile, collected a cryptographic hash of the hardware MAC address and details of visited websites through the autocomplete function, although the latter could be disabled. Because Edge and Yandex collect identifiers that are linked to the hardware running the browsers, the data persists across fresh browser installs and can also be used to link various apps running on the same device. These identifiers can then be used to track IP addresses over time.
“Transmission of device identifiers to backend servers is obviously the most worrisome since it is a strong, enduring identifier of a user device that can be regenerated at will, including by other apps (so allowing linking of data across apps from the same manufacturer) and cannot be easily changed or reset by users,” the paper warned.
A Microsoft representative provided a response on condition she not be named and the response not be quoted. She gave no reason for this requirement. She said that Edge asks for permission to collect diagnostic data that’s used to improve products. She said this collection can be turned off. While the data “may” contain information about visited websites, it isn’t stored with users’ Microsoft accounts.
When users are signed into Edge, they can sync their browser history to make it available on other devices. Users can view and delete this history on the privacy dashboard located at privacy.microsoft.com. Microsoft’s Defender SmartScreen—a Windows 10 feature that protects against phishing and malware websites and the downloading of potentially malicious files—works by inspecting URLs that users intend to visit. This default functionality can be disabled through the Edge Privacy and Services settings.
The unique identifier allows Edge users to use a single click to delete associated diagnostic data stored on Microsoft servers.
At the other end of the privacy spectrum was Brave. The study found the default Brave settings provided the most privacy, with no collection of identifiers allowing the tracking of IP addresses over time and no sharing of the details of webpages visited with backend servers.
Chrome, Firefox, and Safari fell into a middle category. The autocomplete feature in all three browsers transmitted details of visited sites in real time as the URLs are being typed. These default settings, however, can be disabled. Other potentially privacy-harming behaviors included:
- Chrome: sends a persistent identifier along with website addresses, allowing the two to be linked
- Firefox: includes identifiers in telemetry transmissions that can link these things over time (telemetry is on by default but can be disabled). Firefox also opens a persistent websocket for push notifications. The websocket, the researcher said, is linked to a unique identifier and can potentially be used for tracking that’s not easily disabled.
- Safari: Defaults to a start page that can leak information to “multiple third parties” who can preload pages containing identifiers to the browser cache. What’s more, associated iCloud processes made connections containing identifiers.
Representatives of Google, Mozilla, and Apple didn’t immediately provide responses to the findings. This post will be updated if responses come later.
Users of Chrome, Firefox, and Mozilla can improve privacy protections by disabling the website autocomplete feature, which I’ve never found to be all that useful anyway. My inspection of Edge seemed to confirm the researcher’s contention that there’s no way to turn off autocomplete in Edge. Microsoft’s response above, however, provides ways to curb some of the other data transmissions. While the browser comes with enhanced security measures that are resistant to exploits, users who prioritize privacy should consider disabling default behaviors or using a different browser.