[00:00.000 --> 00:01.120] My name is Arthur Edelstein. [00:01.460 --> 00:08.560] I'm based in California, and I'm going to tell you today about my hobby project, which is called privacytest.org. [00:08.760 --> 00:10.780] It's a website, if that's not obvious. [00:12.800 --> 00:19.700] So in this talk, I'm going to give you an overview of what I've been working on in web privacy for the past 11 or 12 years. [00:20.260 --> 00:25.420] And then I want to talk about why we care about privacy, and web privacy in particular. [00:26.220 --> 00:33.320] And then I want to go give a high-level overview of the approach to how this project works. [00:34.380 --> 00:42.540] Then I'm going to talk about specific leaks that I've been measuring to try to understand the privacy of different web browsers. [00:43.840 --> 00:46.940] And I'll tell you what we've learned from this at a higher level. [00:47.300 --> 00:51.500] And then we can discuss future work and any other questions you have. [00:53.200 --> 00:58.560] So just to give a quick overview to why I'm working on this project. [00:59.780 --> 01:04.940] I started getting... working on browsers and learning about browsers working at Tor Browser. [01:06.080 --> 01:09.260] And I worked on a variety of privacy protections. [01:11.060 --> 01:14.000] And then I moved to Firefox, which Tor Browser is based on. [01:14.000 --> 01:17.360] And we brought some of those protections into Firefox. [01:18.640 --> 01:25.220] And then since 2022, I've been at Brave doing some of the same kinds of things, but on a Chromium browser. [01:25.400 --> 01:27.240] So it's kind of learning things all over again. [01:27.380 --> 01:32.440] But a lot of the principles are the same for all these browsers in terms of how they are protecting your privacy. [01:33.460 --> 01:38.880] And so, yeah, today I'm going to tell you about this project I've been working on actually since probably 2018. [01:38.880 --> 01:41.820] But it's been public since 2021. [01:44.740 --> 01:48.860] So first, I just want to give a little motivation of why do I care about mass surveillance? [01:49.120 --> 01:55.360] And to me, the thing that's really scary about surveillance is that it makes power imbalances possible. [01:55.460 --> 01:57.220] In other words, it makes oppression possible. [01:59.200 --> 02:06.920] So if you look at countries with a lot of censorship, what they're doing is they are trying to tamper with the flow of information between citizens in that country. [02:07.780 --> 02:17.340] They deny access to information, they deny freedom of expression, they violate everybody's privacy, and they restrict private communication. [02:17.520 --> 02:25.560] And this has always existed to some degree, but now in the digital age, it's becoming a much bigger issue, I think. [02:27.340 --> 02:29.580] Just a few motivating examples. [02:30.060 --> 02:36.060] In 2020, the Trump campaign had a strategy to deter millions of black Americans from voting. [02:36.300 --> 02:37.680] Sorry, that was in 2016. [02:39.360 --> 02:45.740] By basically having profiles of everybody and then trying to target particular ads to particular voters. [02:46.100 --> 02:49.680] And telling them, for example, not to vote in some way. [02:53.470 --> 02:59.510] So 3.5 million black Americans were categorized by Donald Trump's campaign as deterrents. [03:02.170 --> 03:04.630] These are the voters, they wanted to stay home on election day. [03:06.350 --> 03:09.350] So to me, this is a super alarming tactic. [03:11.810 --> 03:29.650] Another interesting piece of news from a couple of years ago is that the U.S. government admitted or published this interesting information, which is that the spy agencies are buying up huge amounts of personal data about Americans, as well as around the world. [03:30.530 --> 03:32.510] And this is commercially available data. [03:32.950 --> 03:35.810] They talked about from cars, phones, and web browsers. [03:36.330 --> 03:40.890] And they said this is comparable to the data that we get from our own surveillance... [03:43.290 --> 03:45.030] From our own surveillance that we're doing. [03:45.270 --> 03:46.650] So basically, the commercial surveillance... [03:47.310 --> 03:52.090] Maybe we don't call it surveillance, we call it, you know, data collecting for advertising or something. [03:52.190 --> 03:56.670] But that is actually a huge part of what the spy agencies are using. [03:59.650 --> 04:10.370] More recently, there was this horrifying story about the AI machine that is being used to target people in Gaza. [04:11.250 --> 04:12.610] It's called Lavender. [04:15.560 --> 04:19.100] And I thought this passage was kind of amazing. [04:19.280 --> 04:32.520] It says, The Lavender software analyzes information collected on most of the 2.3 million residents of the Gaza Strip through a system of mass surveillance, then assesses and ranks the likelihood that each particular person is active in the military wing of Hamas or Islamic Jihad. [04:32.620 --> 04:38.540] According to the sources, the machine gives almost every single person in Gaza a rating from 1 to 100, expressing how likely it is that they are a militant. [04:39.000 --> 04:42.140] The more information and the more variety, the better, the commander writes. [04:42.260 --> 04:47.200] Visual information, cellular information, social media connections, battlefield information, phone contacts, photos. [04:48.340 --> 04:53.660] And then the machine is aggregating all of this stuff and using it to decide if you should live or die. [04:54.420 --> 05:03.520] And this is the kind of, like, dystopian thing that the people wearing tinfoil hats have been thinking about for years, like all of us. [05:03.620 --> 05:06.400] But it turns out this is really happening today. [05:06.400 --> 05:15.440] And to me, this is, it's kind of, it's actually shocking, but also very motivating that we need to do something about, about protecting people's privacy. [05:17.540 --> 05:24.560] So, from my point of view, this, you know, we should, we should be taking the Universal Declaration of Human Rights seriously. [05:24.560 --> 05:30.780] We should take Article 12 seriously, which says no one shall be subjected to arbitrary interference with his privacy. [05:33.420 --> 05:36.020] And everyone has the right to, the protection of the law. [05:36.200 --> 05:39.280] And I would argue protection also of, of their technology. [05:41.180 --> 05:46.380] So the problem is, I mean, that was generally about surveillance, but the web is one of the major targets of mass surveillance. [05:47.820 --> 05:53.920] It's, today, one of the primary means of modern reading, writing, communication, and commerce, as we, as we all know. [05:53.920 --> 05:55.600] And there's, there's billions of people using it. [05:56.240 --> 06:02.200] And most web browsers are exposing most people to mass surveillance basically all the time. [06:02.440 --> 06:03.760] And all their data is being collected. [06:04.140 --> 06:09.740] And we've kind of been unable, collectively, to figure out how to stop this. [06:12.540 --> 06:13.560] So why is that? [06:13.660 --> 06:15.680] Why, why is this persisting, this situation? [06:16.080 --> 06:18.980] I think there's a couple of reasons, a couple of major reasons. [06:19.200 --> 06:32.560] One is that the incentives are bad, because web browsers are made by companies that, that make money from the surveillance, and also because there's a lack of visibility, that it's actually impossible to see what your web, or almost impossible to see what your web browser is doing. [06:32.840 --> 06:35.660] Any, any ordinary person is not going to be aware of this spying. [06:36.100 --> 06:37.040] So it's invisible. [06:38.020 --> 06:40.140] And we have this out of sight, out of mind problem. [06:41.960 --> 06:43.440] So what can we do about it? [06:44.760 --> 06:47.940] It's, it's both a technical and a social problem. [06:48.460 --> 06:57.620] We know that some people care about privacy, but many people don't know about privacy, what's going on, or they don't care, or at least they say they don't care, or they've given up hope. [06:58.380 --> 07:09.620] And so, while there are technical fixes, we, we need the political backing at the companies who make the web browsers, to actually implement these fixes. [07:10.720 --> 07:17.500] And it turns out, as I discovered, working for a couple of companies, is that corporate politics is very challenging. [07:17.940 --> 07:20.160] It's very hard to, to fight those fights. [07:20.680 --> 07:23.040] So is there some way that we can be more effective? [07:23.320 --> 07:24.160] How, how can we do that? [07:26.620 --> 07:32.380] Another question is, uh, why are the, why are the browsers still so leaky? [07:32.380 --> 07:36.700] One is that the, these leaks, as I mentioned, are hidden and technical and complex. [07:37.460 --> 07:40.440] And that they get their revenue from top trackers. [07:40.560 --> 07:43.280] Another reason is that people have concerns about web compatibility. [07:43.280 --> 07:51.540] They're worried that if we stop the, some of these, uh, web APIs from working the way they've always been working, then some websites will break. [07:52.160 --> 08:02.020] And so, all of these things are kind of together, uh, pushing privacy down on the list of priorities for the decision makers who are, who are designing these, these web browsers. [08:04.620 --> 08:13.020] So just to get into the details a little more, um, browsers allow websites you visit and the trackers embedded in them to gather your browsing history. [08:13.400 --> 08:18.460] And browsers leak a lot of unnecessary data that can be tracked, that can be used to track your browsing. [08:18.800 --> 08:25.600] And browsers also fail to encrypt your network connections, allowing your ISP or other network eavesdroppers to watch your browsing. [08:25.600 --> 08:31.440] So all of these things are, are important leaks that are allowing this to happen. [08:32.940 --> 08:38.400] So the question is, can we try to make browser makers accountable for fixing these, these leaks? [08:42.510 --> 08:48.330] So in my opinion, opinion, mass surveillance demands that we protect everybody. [08:48.330 --> 08:51.890] And that's because mass surveillance causes harm to whole societies. [08:52.750 --> 09:01.590] So the initial idea that I had is that we'll get some people using Tor browser, protecting a few people who are tech savvy or privacy conscious. [09:01.770 --> 09:05.530] That's not really adequate because really the harm is to the whole society. [09:05.690 --> 09:07.070] It's not merely to, to individuals. [09:07.370 --> 09:10.690] So in my view, all browsers should be private by default. [09:13.030 --> 09:24.410] So my project privacy test.org is an, is an effort to hold these browsers accountable, to force them or to at least encourage them to protect all web users from mass surveillance. [09:24.990 --> 09:30.950] And the way that this project basically works is that we try to detect the privacy leaks. [09:31.790 --> 09:33.930] We try to monitor those leaks over time. [09:34.130 --> 09:42.290] And then with this information, inform the public and try to inform the browser makers that their browsers are leaking and try to pressure them a little bit. [09:44.870 --> 09:48.230] So I initially started working on it while I was at Tor. [09:49.870 --> 09:55.150] And then in 2020, that was in 2018, 2021, I started working on it independently full time. [09:55.190 --> 09:59.870] And I launched it in October and I'm still working on it today. [09:59.870 --> 10:01.430] It's, it's an iterative project. [10:03.530 --> 10:09.370] So I, there were a lot of issues I had to consider in terms of how to design this project. [10:10.590 --> 10:14.530] First, we know that the leaks from browsers are invisible. [10:15.090 --> 10:22.410] So I felt the, the key thing that was that we needed to run the tests and we needed to make the results public so that everybody could see them. [10:22.510 --> 10:24.510] So they wouldn't be invisible, completely invisible anymore. [10:25.390 --> 10:28.210] Another problem is that it's a very technical issue. [10:28.210 --> 10:31.670] Like all of the cookies and things are not really understood by most people. [10:31.850 --> 10:38.810] So another issue is, yeah, is, is how, how can people trust me? [10:38.950 --> 10:39.990] And, and they really can't. [10:40.090 --> 10:42.850] So the, the approach had to be an open-source project. [10:42.870 --> 10:45.090] And I have, I try to keep my opinions out of it. [10:45.210 --> 10:46.470] So I don't recommend any web browsers. [10:46.470 --> 10:50.930] And I just stick to just the things that I was able to measure and what those facts are. [10:52.510 --> 10:56.950] And then the, the last challenge that I was dealing with is that there's tons of web browsers out there. [10:57.130 --> 10:58.230] And they have tons of privacy leaks. [10:58.410 --> 11:02.050] And so I had to accept the idea that I'm not going to do this in a complete sense at the beginning. [11:02.190 --> 11:05.450] That I'm doing it in a, in a gradual way and slowly building it up. [11:08.310 --> 11:09.890] A few more issues. [11:10.250 --> 11:14.950] One is that each test is going to, is to measure a single privacy leak. [11:15.910 --> 11:21.110] And I would test each browser with default settings because that's the, the fairest way that I can compare them. [11:21.790 --> 11:25.590] And then I repeat every test five times to account for randomness. [11:25.590 --> 11:35.370] And the tests, uh, need to not focus on a browser conforming to existing standards because the standards are often anti-privacy. [11:35.590 --> 11:40.630] But actually what's really important is that I, that we're testing for real privacy leaks. [11:45.050 --> 11:47.470] So this is the basic setup. [11:48.670 --> 11:55.810] Um, I have a Mac because that, uh, supports all the different browsers, including Safari. [11:56.470 --> 12:02.970] Um, and then basically I launch each browser programmatically via the command line. [12:03.250 --> 12:04.350] That's on desktop. [12:04.670 --> 12:09.630] Or I use Appium to control browsers in, in an iPhone and an Android phone. [12:10.310 --> 12:18.950] And then I control these browsers to visit a, a test server, to, to visit a website, basically. [12:19.210 --> 12:24.190] And that website is doing typical things that websites would do to try to track you. [12:24.190 --> 12:28.330] Or to try to extract private data from your browser. [12:29.150 --> 12:34.770] Um, so, and then that server then reports back what information it was able to extract. [12:35.010 --> 12:38.390] So that gives you, that, that gives us the, the results of the test. [12:40.970 --> 12:46.070] And this is just a schematic of what, what the pipeline looks like. [12:46.450 --> 12:51.730] For each test, I have a configuration file that describes what tests I want to run. [12:52.470 --> 12:58.330] Um, it then runs the tests, produces a JSON file so that anybody can consume. [12:59.370 --> 13:04.150] Then renders that to human readable site pages, publishes it on, on the web. [13:04.430 --> 13:06.190] And then I share it on social media. [13:06.370 --> 13:10.710] So this is more or less an automated pipeline, although things constantly break. [13:10.810 --> 13:12.070] So I have to keep fixing them. [13:12.070 --> 13:12.070] Um, [13:15.560 --> 13:18.860] this just shows what different, uh, platforms that I'm testing are. [13:24.550 --> 13:29.450] So there's a variety of different things that are being tested in, in the web browser, different privacy leaks. [13:29.670 --> 13:33.810] I'm going to go through a bunch of these in, in the following slides. [13:38.160 --> 13:46.320] So the first one that I think is the, probably, um, one of the most important is what is often called stateful tracking. [13:46.820 --> 13:56.900] Uh, and this is tracking where, when you visit a website, uh, it's able to store a little bit of data, or even a large amount of data, in your browser. [13:58.780 --> 14:06.160] And if, uh, the, the way that browsers have traditionally operated is that if you could visit two different websites, a.com and b.com. [14:06.420 --> 14:10.400] And they would both be able to share through the help of third-party scripts. [14:10.560 --> 14:12.020] They'd be able to share data. [14:12.400 --> 14:18.800] So they could, a.com could say, okay, I saw this person and I'm going to give them this UUID, this unique ID. [14:19.160 --> 14:25.140] And then b.com, when, when the same person visits b.com, they can record the same UUID. [14:25.140 --> 14:29.380] And now that they have this information that this person visited both of these websites. [14:29.700 --> 14:34.820] So this is a way that you can be tracked with, with, uh, for example, with cookies. [14:35.180 --> 14:35.600] Okay. [14:36.760 --> 14:58.240] Um, so that means, uh, that basically, I think if you, if you go back like 10 years, essentially all browsers, except maybe Tor browser, were leaking, had tons of leaks that were, uh, by this method of, of sharing data between websites. [14:59.200 --> 15:15.500] So this is just a diagram that, um, came from Firefox, where previously, um, all these websites could use third-party cookies and share these cookies from, from Facebook, for example. [15:15.500 --> 15:23.600] Um, but then after state partitioning, you could separate, uh, the cookie jar into three separate cookie jars. [15:24.000 --> 15:29.060] And these websites are no longer able to, to share data to, to track you. [15:33.590 --> 15:42.390] So this was actually a, a known issue way back in 97, uh, when cookies were first described in this RFC. [15:43.610 --> 15:45.890] And they have a section on unexpected cookie sharing. [15:46.030 --> 15:53.310] And it says, a user agent should make every attempt to prevent the sharing of session information between hosts that are in different domains. [15:54.230 --> 16:02.790] Um, for example, a malicious server could embed cookie information for hosta.com in a URI for a CGI on hostb.com. [16:03.250 --> 16:07.630] So they already knew what was happening and, and why this was a problem. [16:08.450 --> 16:10.830] Unfortunately, the browsers didn't take this suggestion. [16:11.050 --> 16:16.710] And they actually, it said, user agent implementers are strongly encouraged to prevent this sort of exchange whenever possible. [16:16.710 --> 16:21.210] Um, well, none of the browsers followed that encouragement. [16:21.550 --> 16:23.030] They, it was not enough. [16:24.310 --> 16:26.490] Then this RFC was superseded. [16:26.790 --> 16:33.150] And instead of encouraging, they just said it was worrisome now that third-party cookies are, are being shared across websites. [16:33.410 --> 16:35.590] Um, which I agree. [16:36.090 --> 16:43.870] But, uh, basically the standards, and I've seen this in, in many cases, the standards basically follow what the browsers actually do. [16:43.870 --> 16:51.790] And somehow, you'd think it would be the other, other way around where you write the standard and then you build the, what the, the web browser according to the standard. [16:51.930 --> 16:53.890] But it's actually more the other way. [16:54.070 --> 17:00.970] And the problem is that then that kind of locks in the browser community because now they've written down the bad thing they were doing. [17:01.110 --> 17:02.870] And now it's official, so they have to stick with that. [17:03.170 --> 17:03.250] Right? [17:03.610 --> 17:05.550] But this is not really a, a healthy situation. [17:08.410 --> 17:12.450] So, um, this stateful tracking is not just restricted to cookies. [17:12.450 --> 17:18.650] There's many, many things in web browsers that potentially were leaking data between websites. [17:18.970 --> 17:21.070] So you could, some of them were called super cookies. [17:21.630 --> 17:29.790] Um, but they're, they're basically all, it's all the same principle that if you go to website A, it can write data to your browser. [17:29.950 --> 17:32.910] And then when you visit website B, website B can read that data back. [17:35.410 --> 17:45.150] So the simple thing is we, I, what I wanted to do was to test to see, uh, our browsers actually able to share this data between websites. [17:45.370 --> 17:47.290] So I have two simulated websites. [17:47.750 --> 17:50.650] Website A writes some state. [17:50.870 --> 17:55.330] It could be a cookie or it could be one of these other, uh, stateful vectors. [17:56.310 --> 18:00.510] So these are many features of browsers that are able to, able to leak this data. [18:00.970 --> 18:06.650] Uh, one in each row and then website and then, and then, uh, basically. [18:06.910 --> 18:16.550] So I would record either a, a red X if the data leaked and a green check if the, if the data did not leak between those two test sites. [18:16.550 --> 18:22.110] Um, and I did it for each browser and each, uh, each vector here. [18:23.610 --> 18:26.830] Um, so that was back in 2021. [18:27.530 --> 18:30.170] And as you can see, browsers are super leaky. [18:30.890 --> 18:37.990] Um, the only one that was actually partitioning all the data correctly between websites was, was Tor browser. [18:40.490 --> 18:48.250] Um, so now if you look at four years later, actually the situation is much better. [18:48.910 --> 18:59.110] So if you look at, we have, um, Brave, Firefox, LibreWolf, MulVad, Safari, Tor browser, and un-Google chromium. [18:59.310 --> 19:02.370] They have completely partitioned everything that they can. [19:02.550 --> 19:07.990] So basically this entire type of stateful tracking is no longer possible in those web browsers. [19:08.690 --> 19:12.310] Um, Chrome actually has done a pretty good job. [19:13.150 --> 19:17.830] Most of the leaky vectors are, are fixed, as you can see. [19:17.970 --> 19:19.110] There's only a few red ones. [19:19.270 --> 19:21.830] The main red ones in the middle there, there's three here. [19:22.410 --> 19:24.770] These refer to cookies, third-party cookies. [19:25.330 --> 19:28.330] And Chrome wanted to get rid of third-party cookies. [19:28.490 --> 19:31.370] And they, they announced that that was their plan, that they were going to get rid of them. [19:31.790 --> 19:37.430] Uh, and then after a few years of the schedule slipping, they finally announced that they weren't going to do it anymore. [19:38.250 --> 19:42.790] So that's a really big problem because it means they've given up. [19:43.250 --> 19:49.030] And actually third-party cookies are the most important one in this table because that's the one that websites are all using today. [19:49.790 --> 19:59.790] Um, the reasons for this are complicated, but some of it does have to do with the revenue that advertisers are going to lose if third-party cookies are blocked. [20:00.430 --> 20:02.350] Uh, so it's a very unfortunate situation. [20:02.350 --> 20:07.210] I don't really know what the solution is going to be, but I do think we should keep trying to push for getting this fixed. [20:10.520 --> 20:19.360] If you look at the incognito windows or private modes of these browsers, then actually just about everything is, is fixed. [20:19.680 --> 20:24.160] Um, there's one little leak that Opera has there. [20:24.400 --> 20:26.320] Uh, I'm not sure why they have that. [20:26.500 --> 20:32.480] And DuckDuckGo has a, has a problem with favicons that you can be tracked by favicons across websites. [20:32.480 --> 20:39.120] Um, but, uh, but otherwise on, uh, on private modes, the situation is very good because third-party cookies are blocked. [20:39.180 --> 20:43.940] So this proves that it's very possible in all the browsers to make this fix. [20:44.100 --> 20:47.640] And so it's not a technical, there's no technical challenge here. [20:47.740 --> 20:51.240] This is a purely political or financial issue. [20:51.340 --> 20:53.720] Why this hasn't been fixed in, in by default. [20:57.210 --> 20:57.730] Yeah. [20:57.830 --> 21:03.450] So basically the, the Chrome based browsers, uh, uh, apart from brave are still not blocking third-party cookies. [21:03.790 --> 21:06.130] And unfortunately that's the, the most common thing. [21:07.830 --> 21:12.690] And I mentioned this, how Google had decided after all, they weren't going to do this. [21:12.690 --> 21:14.210] So somehow we have to change their mind. [21:17.330 --> 21:23.070] So, uh, second important, uh, tracking method is IP address based tracking. [21:24.090 --> 21:33.150] Most of the time users have a unique IP address that persists for a while, particularly on, on desktop or laptop computers. [21:33.750 --> 21:39.750] Um, and in order to hide your IP address, you need to share that address with other people. [21:39.850 --> 21:49.310] So you could use some kind of relay that could be a VPN, a proxy or tour, or there's also a private relay, which is sort of a, a, a, a two hop proxy. [21:49.650 --> 22:00.110] But if you're not using VPN or proxy, then your personal IP address, it makes it very easy for you to be tracked, not only by the websites you visit, but by the trackers that are embedded in those websites. [22:01.150 --> 22:03.410] Um, and there's a paper proving this. [22:03.530 --> 22:07.290] They said, we show that IP addresses remain a prime vector for online tracking. [22:07.490 --> 22:12.250] 87% of participants retain at least one IP address for more than a month. [22:12.250 --> 22:17.390] And 45% of ISPs in our dataset allow keeping the same IP address for more than 30 days. [22:18.530 --> 22:21.110] So basically most people are trackable. [22:21.850 --> 22:35.070] Even if your IP address only lasted for a day though, that's already a big leak because it allows the correlation of everything you're doing during that day and also correlation with all the trackers that are, that are tracking inside those, those websites. [22:36.570 --> 22:44.870] So I, I have a test that basically checks to see, uh, is your IP address hidden or not? [22:46.030 --> 22:51.250] And in this case, none of these browsers are, do any kind of tunneling by default. [22:51.570 --> 22:53.710] The only ones, sorry, to do. [22:54.050 --> 22:57.710] The only cases are Tor browser because it's using the Tor network. [22:58.030 --> 23:01.050] And then the brave Tor mode, which also uses the Tor network. [23:02.430 --> 23:06.230] So, I mean, this, this picture alone shows why we can't have nice things. [23:06.370 --> 23:10.070] We can't have privacy because it's, this is already a huge leak. [23:10.070 --> 23:17.330] Um, so we need to hopefully encourage browsers to find a way to, to tunnel by default. [23:17.990 --> 23:20.610] And in the meantime, we need to encourage users to use a VPN. [23:24.290 --> 23:32.390] Another, uh, important vector is, or is, is another important leak is when your browser visits an HTTP site. [23:32.390 --> 23:40.610] So if you use HTTPS, as I think everyone knows, then your connection is secure between the browser and the server. [23:41.430 --> 23:45.570] Um, but when you're using HTTP, all the data is visible to anyone watching. [23:45.570 --> 23:51.670] And the web browser you receive, uh, and the, sorry, the web page you receive is also vulnerable to modification. [23:53.170 --> 24:01.530] Um, and HTTPS hides not only the content, but also the path of the web page you're visiting in the URL of that page. [24:02.030 --> 24:05.190] So only the website is visible to third parties if you're using HTTPS. [24:05.390 --> 24:17.510] So for example, with this Wikipedia URL, um, if you're using HTTPS, which you always are with Wikipedia, then this path, which, which says what page you're visiting, that's going to be hidden. [24:17.730 --> 24:22.470] So that's a, that's a really, uh, important addition to your privacy. [24:28.340 --> 24:35.260] Um, the good news is that HTTPS has been growing over the past years. [24:35.260 --> 24:43.620] This is only up to 2023, but it's north of 80% for, uh, the U.S. and close to that for, for everybody else. [24:45.260 --> 24:54.200] So this is something that enabled a new, um, improvement in HTTPS use in web browsers. [24:54.440 --> 25:03.600] So if you look back, uh, in 2022, um, some browsers were upgrading images if they were not secure. [25:03.880 --> 25:08.580] But basically, if you clicked on a link and it wasn't secure, it'll just take you to that insecure link. [25:08.580 --> 25:12.880] And there's very little information to the user saying that you're doing something dangerous. [25:14.160 --> 25:16.120] If you visit an address, same thing. [25:16.600 --> 25:23.460] And if you're on an insecure website, there's a, there used to be, like a, or maybe there still is, a small warning in the address bar. [25:23.660 --> 25:28.160] But there's nothing before you've already visited the site, before it's too late to, to warn you that there's a problem. [25:31.510 --> 25:37.330] And now, uh, if you look in 2025, um, the situation is a lot better. [25:38.910 --> 25:44.530] Most browsers here, now, are upgrading everything they can, uh, by default. [25:44.750 --> 25:48.830] So if you visit, if you click on an insecure link, it's gonna first try a secure link. [25:48.990 --> 25:53.970] And only if the secure link doesn't exist, will it then, um, fall back to HTTP again. [25:54.170 --> 25:56.350] So it tries HTTPS and then falls back to HTTP. [25:57.430 --> 26:02.310] The only browser not doing that now is DuckDuckGo, which is sort of waddling behind. [26:03.210 --> 26:13.350] Um, and then some of these browsers now, uh, are doing this interesting thing, which is that they give you an insecure website warning. [26:14.230 --> 26:25.370] Uh, and this actually exists in, I think, all, all browsers, where if you visit an insecure site, um, it'll tell you this site does not support HTTPS. [26:25.630 --> 26:27.690] Are you sure you want to go ahead and visit this site? [26:28.730 --> 26:40.650] Um, so this now exists in, uh, this is now enabled in Chrome and other Chrome-based browsers, uh, by default. [26:40.650 --> 26:47.330] So it'll show you this warning, uh, in incognito windows before you visit an insecure, uh, website. [26:47.630 --> 26:55.910] And that basically ensures if you never click on continue on those buttons, then you're, you are guaranteed that all the connections from your browser are secure. [27:00.550 --> 27:04.970] Um, so that's actually, I think, a super positive thing that's happened. [27:07.310 --> 27:14.870] And hopefully the next stage will be that, uh, every browser by default will give you warnings before you visit an insecure site. [27:17.250 --> 27:19.170] The next category is fingerprinting. [27:19.390 --> 27:29.510] Um, these are characteristics or, of your device or your browser, um, settings that are leaked by your browser to any website that asks for it. [27:29.510 --> 27:32.910] So, for example, a website may ask, what's the size of your screen? [27:33.090 --> 27:37.230] And you, you don't, uh, have to give permission for that to be sent. [27:37.410 --> 27:40.130] Browsers will just send that information as if it doesn't matter. [27:40.230 --> 27:42.610] But that's one of the ways that you can be, you can be tracked. [27:44.370 --> 27:49.210] So, there's a way of protecting you, which is that browsers can spoof this data with a different value. [27:49.450 --> 27:54.170] Whether it's screens or your, or the fonts that are installed on your system or other things like that. [27:55.070 --> 28:00.030] So, if all browsers are spoofing this data, then you're, you're gonna be much better protected. [28:00.710 --> 28:04.070] So, I, I'm doing a limited set of, uh, tests on that. [28:04.810 --> 28:11.870] Um, basically, most browsers are still not, uh, doing that much to protect against fingerprinting. [28:13.110 --> 28:22.830] Um, but you can see that there's, there's some work being done at, um, Brave and, uh, MoVAD and, and, uh, Tor. [28:27.180 --> 28:30.320] The next category is, uh, tracking cookies and tracking content. [28:31.940 --> 28:38.720] So, something that I think is invisible to, to most people is that when you visit a webpage, you're not really just visiting one server. [28:38.720 --> 28:45.200] There's actually all these third-party scripts and images and other things that are embedded in the, uh, in the webpage. [28:45.800 --> 28:48.460] And we call these third-party content. [28:48.820 --> 28:51.820] And some of the third-party content is ads. [28:51.980 --> 28:53.440] There's also just pure trackers. [28:53.640 --> 28:57.600] There's other kinds of things that are useful for the webpage to run, like a utility script. [28:57.600 --> 29:10.780] Um, so, but if you look at a third-party tracker such as Google Analytics, which is embedded in millions of webpages, that script can see you again and again and report back to the, to the mothership about you. [29:10.940 --> 29:13.360] Um, and all the sites that you visited. [29:14.100 --> 29:17.300] Um, and it can do that by using cookies. [29:17.300 --> 29:18.720] It can see your IP address. [29:18.940 --> 29:23.840] It can look at the parameters in your, in your address, the, the, the address of the page you're visiting. [29:24.020 --> 29:25.300] And it can do fingerprinting. [29:25.400 --> 29:28.800] So these scripts, third-party scripts, are super powerful for tracking. [29:31.000 --> 29:35.860] This is a plot from Princeton of the, the top trackers. [29:35.980 --> 29:47.600] As you can see, um, Google, uh, they, they run some of the top embedded, uh, third-party content, including the top trackers, and then Facebook is the, is the next highest. [29:47.820 --> 29:50.220] This is from a few years ago, but I, I don't think it's changed that much. [29:52.340 --> 29:56.960] So, what I wanted to do was to see, well, which browsers are blocking the top trackers. [29:57.080 --> 30:01.520] So I used a list of the top trackers, uh, from this website called WhoTracksMe. [30:09.310 --> 30:25.450] Um, and so you can see here, uh, that a lot of browsers are actually track, uh, blocking, um, um, this third-party, uh, cookies from known trackers. [30:25.670 --> 30:30.250] Um, some of the browsers are just blocking all third-party cookies, so that's easy for them to do this. [30:30.470 --> 30:36.330] And then other browsers, such as Edge, they have a specific list, uh, of trackers that they block. [30:37.230 --> 30:46.650] Now, though, in that case, that's a bit, um, self-serving because you'll notice that Bing Ads is not blocked. [30:47.170 --> 30:49.570] Now, you can, you can think about why that might be. [30:53.100 --> 30:58.300] Similarly, you can block not just the cookies, but you can also block the, the content itself, block the scripts. [30:59.420 --> 31:03.940] Fewer browsers are doing that, um, but, but some of them are. [31:04.060 --> 31:06.040] It's very similar to how an ad blocker works. [31:06.060 --> 31:08.440] You can also block a list of, of trackers. [31:08.580 --> 31:11.100] And some of them are ads, both ads and trackers. [31:11.520 --> 31:20.540] Um, so, uh, as you can see, um, basically some browsers have decided they want to do this, and other browsers have decided they don't want to do it. [31:20.640 --> 31:22.700] So they're either blocking all or none on, on the list. [31:25.700 --> 31:31.960] If you look at private browsing, however, there's a few, couple more browsers that are, that are doing interesting things. [31:31.960 --> 31:36.200] Firefox, uh, is blocking most of the trackers. [31:36.400 --> 31:42.360] Although, mysteriously, they don't block Google third-party ad pixel or Google tag manager. [31:43.240 --> 31:45.800] And Safari also is blocking a few. [31:52.020 --> 31:54.040] Uh, one, one more vector. [31:55.120 --> 32:01.460] Tracking query parameters, uh, are the, these are parameters in the address of the page you're visiting. [32:01.460 --> 32:05.140] Um, and they can track you as you navigate from site to site. [32:05.360 --> 32:10.420] One page can send the, attach a query parameter to a, a, a URL address. [32:10.600 --> 32:14.880] And then when you click on it, it's gonna, that parameter is gonna be seen by the next website. [32:15.560 --> 32:17.940] Um, so this is an example of a real URL. [32:18.240 --> 32:21.500] Uh, and it has a Google double click ID embedded in it there. [32:22.100 --> 32:24.760] And what a browser can do is just delete that parameter. [32:24.960 --> 32:27.240] And then your privacy is, is protected better. [32:28.680 --> 32:32.780] So I have a list of, uh, popular query parameters. [32:32.780 --> 32:36.560] And I was measuring which browsers are deleting those query parameters. [32:36.880 --> 32:45.600] And what you find is that, uh, well, in 2021, 2022, when I first started doing this, Brave was the only browser that was blocking query parameters. [32:46.800 --> 32:55.160] Um, now in 2025, uh, more browsers, including Tor, LibreWolf, and Mulvad are doing it by, by default. [32:56.560 --> 33:00.280] And Safari is now doing it, uh, in their private windows. [33:00.600 --> 33:01.720] So we're making progress. [33:06.790 --> 33:17.330] So, there's another kind of tracking that is something that I hadn't really thought about as much until recently, but I realized is quite, quite an important case, which I was calling cross section tracking. [33:17.610 --> 33:26.590] Which is simply that when you visit a website for the second time, the website could recognize you because it, it can store a cookie or any other kind of data in the browser. [33:26.590 --> 33:29.550] This is different from cross-site tracking that I was talking about before. [33:29.870 --> 33:39.010] So this is like if you visit CNN.com, uh, today and then you visit it again tomorrow, it's gonna start to build up a, a list of all the things that you've read over time. [33:41.030 --> 33:50.790] Um, similarly, things like Google Search are, are, uh, assembling this longitudinal study of everything that you search for because they know who you are every time you visit. [33:51.730 --> 34:04.550] But it seems to me that this is a mistake, that browsers shouldn't be retaining this state and keeping track of you, uh, and telling, telling websites that, that who you are every time you visit them. [34:04.810 --> 34:15.090] Unless you've logged into the website and you voluntarily said, I want to identify myself to this site, um, you should be basically a new identity every time you visit. [34:15.790 --> 34:17.970] So this requires some innovation in the browser. [34:19.050 --> 34:23.870] Um, there are, uh, a couple of browsers that are doing this. [34:24.530 --> 34:25.990] Mulvad, Librewolf, and Tor. [34:26.470 --> 34:34.710] Um, the problem is that, uh, they just do it blindly where they erase all state after your browsing session. [34:34.710 --> 34:36.030] So that means you get logged out. [34:36.350 --> 34:41.990] So we need something a little bit with a little more finesse for the other browsers probably for it to be something commercially viable. [34:49.240 --> 34:54.700] Um, so another, another area that I, uh, was looking at is unencrypted DNS. [34:55.140 --> 34:56.940] So this is the normal kind of DNS. [34:57.240 --> 34:59.020] DNS is where your browser looks up. [34:59.020 --> 35:01.720] I want to know what the IP address of a, of a website. [35:02.000 --> 35:06.420] So it puts the website's name into the DNS, uh, service. [35:06.860 --> 35:13.440] And the DNS service will reply with, this is the, this is the, uh, um, the IP address. [35:14.340 --> 35:25.960] Um, and so this is done unencrypted, which means that any third-party can be listening to, uh, your DNS requests and find out which websites that you're going to be visiting and which trackers you're going to be visiting. [35:26.860 --> 35:28.240] There are alternatives. [35:28.560 --> 35:31.300] There's encrypted DNS, such as DNS over HTTPS. [35:31.600 --> 35:39.280] Um, or you can run your DNS over a proxy, which would hide the web, the list of websites that you're visiting from, from eavesdroppers. [35:40.640 --> 35:55.580] So I have a test that basically, uh, attempts to visit different, um, test domains and then, and then listens on the, uh, computer where the test is happening if DNS requests are going out. [35:55.580 --> 35:59.860] Um, and if it can see those DNS requests, that means that the requests are not encrypted. [36:00.760 --> 36:08.500] Um, and what you can see is right now, by default, most of the time, most browsers are not doing anything to protect you. [36:09.140 --> 36:16.060] Mulved has their own DNS over HTTPS service, which is awesome, so that they're actually protecting their users by default. [36:16.060 --> 36:23.960] And then Tor is protecting the users by default because the Tor network, uh, is, is encrypting everything, including the DNS requests. [36:28.360 --> 36:32.120] So there's been a lot of, uh, great progress in the past few years. [36:32.360 --> 36:41.440] Um, we've seen gradually that all the browsers have been partitioning, uh, state so that data is not shared between websites. [36:41.440 --> 36:46.180] We've seen a big increase in the use of HTTPS by default. [36:47.080 --> 36:56.120] Um, and, uh, we're seeing some uptake of the query parameter, uh, deletion, among other things. [36:59.060 --> 37:00.540] So what have we learned so far? [37:01.860 --> 37:06.740] First is that all three browser engines have already been hardened for privacy in some browsers. [37:07.300 --> 37:18.080] Like, um, uh, Firefox is not completely hardened, but Tor browser, which is based on Firefox or based on the Gecko engine, is, is more hardened. [37:18.100 --> 37:20.280] So we know that it's technically possible to do that. [37:20.700 --> 37:21.840] Same for Chromium. [37:22.020 --> 37:25.560] We see that Brave has a lot more protections than, than Chrome does. [37:25.560 --> 37:29.700] Um, so it, in my opinion, there's just no excuse. [37:29.860 --> 37:31.240] All browsers should be able to do this. [37:31.340 --> 37:32.900] There's no technical obstacles. [37:34.720 --> 37:37.660] And some browser makers are making a good effort on privacy. [37:39.860 --> 37:41.240] And others are dragging their feet. [37:44.210 --> 37:47.550] Uh, I also learned that browser testing is finicky, especially on mobile. [37:48.930 --> 37:52.850] And continuous monitoring is hard because I have to keep doing it. [37:54.110 --> 37:58.350] Um, but the reward is that lots of people are really interested in browser privacy. [37:58.590 --> 38:00.210] So that's a really, really nice thing. [38:01.630 --> 38:04.430] Um, there's a lot more things I still need to test. [38:05.090 --> 38:07.730] Uh, it's, it's my hobby. [38:07.750 --> 38:11.030] So I have to, uh, find hours here and there where I can work on it. [38:11.030 --> 38:14.570] But this is, this is kind of the short list of things that I want to deploy. [38:16.630 --> 38:19.410] Um, and yeah, thank you for listening. [38:19.750 --> 38:22.570] And I'm, I'd be, uh, happy to take questions. [38:22.570 --> 38:23.570] Thank you. [38:27.480 --> 38:35.560] So, uh, you know, uh, you can recommend people use, uh, Piehole at home or ad blockers. [38:35.760 --> 38:51.540] But I think the challenge is, and I'd love to hear your thoughts on this, what options there are for people where laws are requiring you give up your ID or, uh, in, in the case with like YouTube where they're like, hey, we feed dealer. [38:51.820 --> 38:53.880] AI thinks you're not an adult. [38:54.120 --> 38:54.560] Right. [38:54.680 --> 38:55.700] You know, you have to prove yourself. [38:55.920 --> 38:59.260] So what, what options do people have in cases like that? [39:00.420 --> 39:05.280] Yeah, I mean, it's quite a scary thing what's happening now that governments are moving in that direction. [39:05.540 --> 39:14.760] I'm hoping that some governments won't, and that, that will then give people, uh, an alternative where they can use a VPN and connect through a different country. [39:14.760 --> 39:19.100] Um, but that's, yeah, it's not gonna be a purely technical solution. [39:19.260 --> 39:38.860] We need to also have strong political pushback, because otherwise, eventually, I think the temptation is really, really high to, to, um, basically have everybody be, you know, enter their, their, uh, their ID and their social security number and everything, [39:39.260 --> 39:40.000] wherever they go. [39:41.520 --> 39:42.080] So... [39:43.360 --> 39:43.920] So... [39:43.920 --> 39:58.460] Uh, you mentioned in the beginning and just now political pushback, um, for these results, and you also focus them on social media, uh, who do you hope most, uh, strongly sees these results and takes action on them, besides the, um, browser creators themselves? [40:03.060 --> 40:14.060] Uh, I mean, I would love if people with some, uh, policy influence would, would, uh, would be influenced by it, but I don't know whether they are or they aren't. [40:14.160 --> 40:16.560] I actually don't really know who, who's reading it if it isn't. [40:16.740 --> 40:27.700] So, um, I think, you know, actually, I think public pressure is really valuable, even if it's not millions of people, but even if a few people are being annoying about something, I think that can have an impact. [40:27.900 --> 40:36.160] So, I, I, my, most of my hope is actually in just people, people who voluntarily try to make us think about, about these issues. [40:37.600 --> 40:48.000] So I noticed you don't do tests on, uh, Linux desktop and Windows desktop only, is it gonna be the same results on that, that you're doing on a Mac? [40:48.420 --> 40:50.400] Yeah, it's, it's basically the same. [40:50.580 --> 40:55.080] The reason I don't do it is just due to limited time, but I would hopefully like to... [40:55.080 --> 40:55.380] Got it. [40:55.700 --> 40:56.920] And one more question. [40:57.280 --> 41:04.240] Uh, when somebody's logged in, say, to Google, right, they know your email, and then, does that get to the advertisers as well? [41:06.140 --> 41:06.540] Um... [41:06.540 --> 41:10.820] Or do, do they have some way to pull that when you're logged into the browser? [41:11.660 --> 41:12.480] That's a good question. [41:12.660 --> 41:13.520] I don't know for sure. [41:13.700 --> 41:13.940] Yeah. [41:14.280 --> 41:14.480] Yeah. [41:15.040 --> 41:15.860] That's a good question. [41:15.860 --> 41:17.340] You'd rather not log in then. [41:17.700 --> 41:18.260] That's what I'm thinking. [41:18.660 --> 41:18.660] Yeah. [41:19.220 --> 41:22.380] Well, Google is the biggest advertiser, so that, it is in that case for sure. [41:22.420 --> 41:27.080] I noticed Brave is very good, and I'll probably start using it, but I, I know that it's been around for a while. [41:27.320 --> 41:29.440] Aren't they a cryptocurrency reward? [41:29.720 --> 41:33.180] They have like, if you're using the browser, that's probably why they, they're doing it. [41:33.300 --> 41:37.640] They have, well, it's better because they're actually paying people to use it. [41:38.060 --> 41:39.480] They don't have advertisers, right? [41:39.600 --> 41:40.000] I mean, that's... [41:40.560 --> 41:41.920] Well, there is some advertising. [41:42.180 --> 41:48.120] So Brave does have kind of a different, um, business model, and I'm not an expert, although I do work there. [41:48.280 --> 41:51.740] But, um, the, a lot of what they're doing is the, the Brave search. [41:52.280 --> 41:54.900] Um, I think that's, that's one of the more important areas. [41:55.060 --> 42:02.560] So, I mean, I think that, the principle that if you're not, uh, the customer, you're the product, definitely holds. [42:02.720 --> 42:02.780] Yeah. [42:02.780 --> 42:07.600] And so, this might be, you know, a promising business model for the future. [42:07.700 --> 42:07.820] Sure. [42:07.820 --> 42:12.680] Depending also on what the legal ramifications for Google are, if they have to spit off Chrome. [42:13.020 --> 42:13.680] Yeah, exactly. [42:17.480 --> 42:17.920] Yeah. [42:21.060 --> 42:24.460] So, I, basically, it's sort of really two pools of browsers. [42:24.660 --> 42:28.680] One is just, what are the most popular ones that, that millions of people are using. [42:28.680 --> 42:33.240] And then, I also picked a couple that, uh, were interesting in some particular way. [42:33.420 --> 42:35.860] Like, Tor Browsers is quite different from every other browser. [42:36.200 --> 42:40.220] And, Movad is, uh, kind of quite far ahead of, of the other browsers. [42:40.380 --> 42:42.420] So, that's basically how I chose this. [42:43.220 --> 42:43.660] Yeah. [42:43.660 --> 42:47.580] Um, uh, so, when you're, like, selecting, [42:50.840 --> 43:04.220] I guess, like, like, what, if someone in my personal browser, and, like, if you really want to be able to use this browser, and, like, what is the process of that browser, and, like, what kind of uses is, like, just having . [43:04.780 --> 43:11.340] Yeah, it does take some effort, because, um, every browser has its own idiosyncrasies that I have to, sort of, work around. [43:11.640 --> 43:25.340] Um, I've tended to say no to most, because there are, actually, there's a list, it's kind of an embarrassing list for me, but on the issues, the GitHub issues of, like, I think it's a hundred browsers that I could be adding to the, to the site. [43:25.500 --> 43:31.520] I, I don't want to add too many, because I think it would actually dilute the message if I had too many, as well as being a lot of work. [43:32.100 --> 43:40.520] Um, but yeah, if there's a particular browser that has something, um, unusual, or if one browser, like, became very popular, then I would, I would definitely add that. [43:44.280 --> 43:54.810] Um, so, everything that you, your, everything, everything that leaks when you're using a browser is via an HTTP request, right? [43:56.440 --> 44:00.080] Um, well, there are some, yeah, mostly, yeah. [44:00.420 --> 44:02.680] Like, DNS is not, but a lot of it is. [44:02.860 --> 44:03.120] Right. [44:03.340 --> 44:14.500] So, um, I mean, behind the scenes, like, if you look at the network tab in your dev tools, uh, you can see, you know, hundreds of requests sometimes for one site. [44:14.900 --> 44:15.380] Right. [44:15.380 --> 44:24.360] Um, is that, is, is what's happening when you use, like, Privacy Badger or an ad blocker, that they're just, like, familiar with those and blocking them? [44:25.340 --> 44:31.480] Yeah, so the, like, the ad blockers and, and, um, are just blocking individual third-party requests. [44:31.860 --> 44:32.020] Yeah. [44:32.020 --> 44:41.020] That are, it's, it's usually, like, some kind of domain matching or regex that says, like, don't allow these particular kinds of requests through. [44:41.200 --> 44:45.460] And there's, there's a, I mean, that is a very powerful contribution to privacy. [44:45.740 --> 44:53.980] But there are, some of those requests can't be blocked, even though they're tracking, because they're also essential for the, the functioning of the site. [44:54.100 --> 45:00.260] So there needs to be other things besides just blocking those, those requests to, to, to have a comprehensive protection. [45:00.820 --> 45:02.700] Oh, and thank you for what you're doing. [45:05.080 --> 45:11.520] Um, uh, phones seem like they would have a lot more, like, privacy issues, because you have such limited control over the phone. [45:11.760 --> 45:15.420] Do you, are there any differences, or are you tracking more, like, the browsers themselves? [45:15.820 --> 45:21.600] So are there any instances where you see things that only happen in phone-based browsers that don't happen in desktop browsers? [45:23.420 --> 45:31.140] Um, mostly it's similar to what the desktop, like, the, the counterpart desktop browser has similar results. [45:31.380 --> 45:36.720] Usually the phone, uh, versions of those browsers are lagging behind a bit, in terms of the protections. [45:37.380 --> 45:43.340] Um, you're totally right that the phones themselves are full of leaks as well, and I haven't worked on that at all. [45:43.440 --> 45:44.760] I just focused on the browser, so. [45:47.500 --> 45:48.260] Yeah. [45:48.820 --> 46:03.980] Um, do you have any insight into the, the maintenance and update process for, uh, a browser like LibreWolf, for instance, which is a forked, or a forked Firefox, rather? [46:04.740 --> 46:12.100] Um, and, and whether or not that is viable as a, as a daily driver for grandma? [46:13.180 --> 46:17.040] Um, I haven't looked at it recently. [46:17.340 --> 46:26.460] I remember that the updating in LibreWolf was a bit more difficult than some other browsers, but it might have changed, so I'm, I'm not sure. [46:29.060 --> 46:29.520] Yeah. [46:30.080 --> 46:49.480] I mean, I, I guess in general, um, yeah, the, the popular browsers are, are, are, are ones that are just, like, completely, uh, hands-free updating, and I think you kind of have to reach that level for that to be a popular thing. [46:49.780 --> 46:50.040] Okay. [46:50.860 --> 47:02.200] Um, are you only evaluating, uh, default browser configurations, or are you also assessing some, like, custom configurations, or unusual usage patterns that could enhance privacy? [47:02.920 --> 47:06.300] Right now, I'm focused only on default, and I'm not looking at different settings. [47:06.820 --> 47:08.820] Um, and there's a couple reasons for that. [47:08.940 --> 47:18.840] One is that, um, that kind of allows me to make a fair comparison, because there's many options, and, and so it's difficult to know, like, what, what setting on what browser I should test. [47:19.200 --> 47:28.060] Um, and the other thing is that I feel like everybody should have privacy, so we should really be focused on what's on by default, because many people don't tweak settings in their browser. [47:31.400 --> 47:32.880] I think we have time for one question. [47:33.120 --> 47:38.700] Um, quickly, looking at that grid, calls to mind that XKCD, we have too many standards. [47:38.940 --> 47:40.660] We need one standard that unifies them all. [47:40.920 --> 47:42.040] Now there are 11 standards. [47:42.760 --> 47:49.760] Um, from your perspective, is there anything you could do between the three browser engines and the numerous browsers themselves? [47:50.060 --> 48:03.140] Are there any incentive structures that a community or, I don't know, a government could apply to to encourage, you know, that number to double less and shrink in a meaningful way, as opposed to, I, an N plus one browser or browser engine? [48:03.780 --> 48:05.160] To shrink the number of browsers? [48:05.460 --> 48:10.680] Yeah, to, to converge everybody's development efforts so that we're not repeating the same process that we're in. [48:13.020 --> 48:14.180] Uh, I don't know. [48:14.320 --> 48:18.440] Yeah, I mean, I guess my feeling is competition is, is good in this sense. [48:18.820 --> 48:31.200] Uh, although risky, but it could, it could be helpful to have, you know, these weird browsers that, um, like, that are, you know, saying, well, look what could be done if Firefox would actually, you know, take privacy seriously. [48:31.460 --> 48:31.540] Right? [48:31.700 --> 48:34.380] So, um, yeah, I don't know. [48:34.520 --> 48:41.020] I, I think, uh, what the, the other, uh, thing that I've experienced is going to, like, the standards committees. [48:41.740 --> 48:45.180] Um, and it feels to me like that's if we're probably supposed to die. [48:45.940 --> 48:58.440] So, I, I feel like what we really need is more grassroots efforts that are outside these, these sort of big tech committees that are kind of fixing the, the situation. [49:00.780 --> 49:02.480] So, um, that's all the time. [49:02.680 --> 49:05.520] But, uh, I would love to talk after a few minutes.