From jameshan.net

Privacy Engineering in a Modern Browser

From October 2025 to April 2026 I interned on Firefox’s privacy team, which works on everything from anti-tracking and fingerprinting protection to privacy-preserving measurement. On this page I want to share a high-level overview of the systems we worked on, and the problems they still leave open.

Open a news article and the page also tells your browser to fetch things from other companies: tag managers, ad networks, analytics beacons. Each request tells a third party which page you’re on. A company that appears on thousands of sites and recognizes you on each can assemble where you’ve been. The browser sits between you and all of them, which makes it the natural place to defend you.

Blocking

Firefox’s Enhanced Tracking Protection keeps a list of known tracking domains, maintained by Disconnect.⁠The list is sorted into categories: advertising, analytics, social, cryptominers, and fingerprinters. ETP has been on by default since 2019. Standard mode blocks what rarely breaks sites; Strict mode blocks more and breaks more. As a page loads, every outgoing request is checked against it, and a match is dropped before it leaves the machine, so the tracker never learns the visit happened.

The hard part is breakage. Pages depend on the scripts they load, and a site that expects an analytics object can fail when it’s missing. SmartBlock fills the hole with a small local stand-in that behaves enough like the original for the page to work, while sending nothing.⁠A blocked social embed, for example, can be replaced with a placeholder that keeps its text and links, and loads the real thing only if you click. Since Firefox 142, Strict mode also ships compatibility exceptions for trackers whose absence breaks major sites. Protection is limited less by what we can detect than by what sites will tolerate.

Partitioning

Blocking only catches trackers that are already on the list, so Firefox also partitions storage for the ones that aren’t. Total Cookie Protection, on by default since 2022, gives every site its own cookie jar and storage, so a tracker embedded on two sites sees two strangers.⁠Partitioning covers more than cookies: local storage, caches, and other state trackers use as makeshift cookies. CHIPS (Cookies Having Independent Partitioned State), the one piece of Chrome’s cookie plan that survived, lets a site opt a single cookie into a partitioned jar. Firefox supports it too.

Safari partitions too. Chrome still allows third-party cookies by default, after deciding in April 2025 not to phase them out.

Partitioning pushed trackers into navigation. A tracker can route your click through its own domain for a moment, where it is first party and can read its cookies, then bounce you onward. Or it can append an identifier to the link itself. Firefox’s bounce tracking protection clears storage for sites you only ever pass through, and query stripping removes known tracking parameters from URLs.⁠Both ship in Strict mode and Private Browsing. Brave goes further and skips known bounce domains entirely.

Fingerprinting

Fingerprinting needs no storage. A script asks innocent questions: screen size, fonts, time zone, how your GPU draws an image. None of the answers identifies you on its own, but together they often do, and there’s nothing you can clear to reset them.

The two defenses pull in opposite directions. Make everyone look the same, as Tor Browser does, and you’re strong but break a lot, and it only works if enough people share the uniform. Make each person look different on every site by adding small per-site noise, and a tracker can’t match you across sites, though an attacker who sees you often can average the noise away. Firefox mostly takes the second path. Firefox 145 extended it to graphics, fonts, and hardware details, and roughly halved the share of users who look unique in Private Browsing and Strict mode.⁠Brave removed its strictest fingerprinting mode in 2024: under 0.5% of users turned it on, it broke sites, and using it made those users stand out. Uniformity only works in a crowd. Separately, Google’s ad policy has permitted fingerprinting since February 2025.

Measuring what you’ve prevented

None of this is visible. We worked on showing people what their browser does for them, and hit the problem that runs through the whole field: the thing you want to report is the thing you’ve prevented from existing. A blocked request never returns, so the browser never learns what it saved. We estimated the cost instead, with a small model trained on crawls where those requests did complete.⁠The target was strange: about 40% of tracker responses are zero bytes, and a few are 100 KB script bundles. That is the shape of insurance claims, and the loss function actuaries use for it, Tweedie, cut our error by about 23%.

Aggregating without seeing

To learn anything across users, Firefox uses Prio through ISRG’s Divvi Up: each browser splits a measurement into random-looking shares and sends one to each of two servers. Neither learns anything alone; only the sum comes out. Reports travel through an Oblivious HTTP relay, a go-between that forwards encrypted reports so that no single party sees both who sent a report and what it says.⁠The relay sees your IP address but not the report. The server behind it sees the report but not your IP address. It is a single hop, unlike Tor. Divvi Up has processed about 4.5 billion reports this way, with Firefox as its flagship deployment.

The cryptography is sound; what you are really trusting is that the two servers won’t collude, which is an organizational guarantee rather than a mathematical one. That pattern holds across the field: every technique replaces “we won’t look” with something else you have to trust. Federated learning and private cloud inference have both moved that trust onto secure hardware enclaves, which cheap physical attacks are now breaking.

Differential privacy

Differential privacy adds calibrated noise so the output barely changes whether or not any one person is in the data, and ε bounds how much.⁠Formally, for any output, its probability with you in the data is at most e^ε times its probability without you. Smaller ε, stronger guarantee. It is a precise number, but what it guarantees in practice depends on details that deployments rarely report.

Real deployments range from ε ≈ 0.15 per query at LinkedIn to nearly 50 for Census detailed tables. Google’s VaultGemma has ε ≤ 2, but per 1,024-token sequence, not per person. Models trained to the same ε can memorize very differently, and much DP training code reports ε for a sampling scheme it doesn’t use, understating the real value. An ε without its unit, its lifetime budget, and the accountant that produced it isn’t evidence of much.

Advertising

Ads are where privacy budgets meet parties who don’t trust each other. In October 2025 Chrome retired most of the Privacy Sandbox. What’s left on the standards track is the W3C Attribution API, edited by Mozilla, Google, and Meta: the browser matches ads to purchases on the device, reports go through the same two-server aggregation, and each site gets a weekly privacy budget. Big Bird, a 2025 research system prototyped in Firefox, shows those per-site budgets break when sites adapt to each other’s results.

Consent turned out to matter as much as the math. Firefox’s own Privacy-Preserving Attribution shipped on by default in Firefox 128, drew a complaint that it should have been opt-in, and was removed without ever being activated.⁠Mozilla’s support page now describes it as a historical reference: the experiment ran too late to inform the W3C work it was meant to feed.

Evaluating models you can’t watch

Browsers now ship local models. Firefox runs PDF alt-text, tab grouping, and link previews on the device. Running locally solves collection and creates an evaluation problem: if nothing leaves the device, how do you know the model works? Today the answer is mostly synthetic data. Firefox’s tab grouping was trained and evaluated on pages a larger model generated for invented users. No browser has published how it measures the real-world quality of its local models.⁠Chrome goes further and exposes its on-device model to web pages through a Prompt API. Mozilla’s standards position on it is negative, mainly because sites would come to depend on one vendor’s model.

What’s open

Fingerprinting defenses that survive an attacker who sees you often. Privacy budgets shared across parties who don’t trust each other. Trust roots that survive physical access. And knowing whether a model works when you’ve promised never to watch it.