Here's What the New Safari Will (and Won't) Do to Protect Your Privacy

At WWDC 2018 yesterday (June 4), Apple gave thousands of developers a sneak peek at upcoming Safari features. The next version of Apple's browser on macOS 10.14 Mojave and iOS 12 will aim to push back against the ad-tracking and browser-fingerprinting techniques that, in the wake of Facebook's Cambridge Analytica scandal, the internet is so afraid of.

The new features are a big deal -- but perhaps not as big of a deal as Apple says they are.

The most noticeable change is that users will receive popups prompting them to grant (or revoke) permission for websites (such as, ahem, Facebook) to use cookies while they browse.

"You can decide to keep your information private," explained Apple VP Craig Federighi onstage.

Apple also announced that Safari will try to block advertisers from using browser fingerprinting, which lets them track users who delete their cookies. (All these features involved Safari on Mojave and iOS 12, but there's no indication they won't also be available for earlier Apple OS's.)

Fingerprinting involves using the information that browsers provide web servers about individual devices, including time zones and installed extensions, fonts and ad blockers. Get enough information, and you can identify individual browsers and track them even without tracking cookies.

To combat this, the new Safari will tell web servers only the browser version, operating system, default fonts and generic configurations, making your Mac indistinguishable from many others.

Finally, the new Safari will offer to generate and auto-fill strong passwords and discourage you from using the same password in multiple places. (If you want to save your passwords in more than one browser, try a stand-alone password manager.)

There's no question that these modifications are a good start and may justifiably ease some people's post-Cambridge Analytica fears.

But contrary to what Apple would like you to believe, you can hardly rest easy at this point. For one, as Facebook Chief Security Officer Alex Stamos pointed out on Twitter, the new Safari will still be vulnerable to some other major tracking techniques.

These include tracking pixels, which are tiny invisible images that advertisers can hide in the background of a web page or email message to alert them when you load the content. Safari also won't block sites from using third-party scripts which can also track your browsing.

If this is about protecting privacy, and not just cute virtue signaling, then they should block all 3rd party JS and pixels. — Alex Stamos (@alexstamos) June 4, 2018

If you're worried about your browsing data, Firefox and Chrome may still be your best bets.

Mozilla has begun work on integrating a technology called DNS over HTTPS (DoH) into its browser, a technology which encrypts Domain Name Service (DNS) queries to keep ISPs from receiving them (and crooks from tampering with them). Mozilla has also partnered with Cloudflare, an internet infrastructure company known for high standards of security and a publicly available DNS service.

Google is taking a similar approach with Chrome and Android P as well. Its tool of choice, DNS over TLS, uses a protocol called Transport Layer Security (TLS) to establish a secure channel between clients and DNS servers to prevent snoops from obtaining (and tampering with) them. Chrome also features a native ad blocker, but it stops only ads that Google finds too annoying.

Both browsers also support extensions to increase your privacy and security. NoScript on Firefox makes sure no JavaScript runs without your permission, and ScriptSafe offers similar protection in Chrome. Ghostery lets you detect and block trackers on both Firefox and Chrome.

Image credits: Tom's Guide

Latest in Antivirus & Cyber-security
TP-Link routers targeted by Chinese state-sponsored cyber attacks
TP-Link routers may face nationwide ban after 'significantly alarming' link to US cyberattacks
What is a VPN kill switch — and why you should use one
You need a VPN for school, here are 3 services we recommend
The AMD Ryzen and NVIDIA RTX stickers on the Acer Nitro 17
'You basically have to throw your computer away': Researchers explain AMD 'Sinkclose' vulnerability, but do you need to worry?
Google Search
This malware is posing as Google Authenticator using Google ads — here's how to protect yourself
Windows 10 BSOD saying "It's not you, it's me."
Microsoft reveals CrowdStrike outage could have a surprising long-term impact on everyday users
MANILA, PHILIPPINES - JULY 19: Long queues of passengers form at the check-in counters at Ninoy Aquino International Airport, amid a global IT disruption caused by a Microsoft outage and a Crowdstrike IT problem, on July 19, 2024 in Manila, Philippines. A significant global outage affecting Microsoft services, particularly Microsoft 365, has caused widespread disruptions across various sectors, including airlines, banks, and health systems. The outage was attributed to a glitch in CrowdStrike's "Falcon Sensor" software, which impacted Windows systems, leading to thousands of flight cancellations and operational chaos in multiple industries. Microsoft has reported that the underlying cause of the outage has been fixed, but residual effects continue to impact some users as the company works on full recovery. (Photo by Ezra Acayan/Getty Images)
The CrowdStrike outage spotlights major vulnerabilities in the global information ecosystem
Latest in News
A close-up of a light-colored computer keyboard shows the keys T, Y, G, and H replaced by the logos of OpenAI, DeepSeek, Grok, and Gemini, the leading competitors in the artificial intelligence market. This serves as a visual metaphor for the intense rivalry and innovation in the AI industry. (Photo by Matteo Della Torre/NurPhoto via Getty Images)
Is generative AI inadvertently reducing the voices of many to the banality of one?
WWDC 2025 could mark the beginning of the end for certain iPhone users
Error when installing Google Chrome on the Asus Vivobook 16 Flip, on a white desk against a blue background.
"This app can't run on your PC": Google's Chrome Installer broke on Windows, but there's a fix
Nintendo Switch 2 handheld gaming console
Nintendo Switch 2 preorder date: It might be a lot closer than you think, say tipsters
Microsoft Surface Laptop (7th Edition, 2024)
Windows-on-Arm woes: Amazon warns customers about Surface laptop returns
Apple Watch Series 8
Siri is the biggest obstacle to making the Apple Watch an AI hit