(Part 1 of 2)
As you all know, the first thing you need to be able to surf the Internet is a web browser. A browser (browser) is a software application used to display information stored on a web server.
The browser is often used in conjunction with a search engine(browser) that is used to search for information on the World Wide Web (WWW) or, in other words, to surf the Internet.
- Examples of browsers: Brave, Mozilla Firefox, Google Chrome, Microsoft Edge, Opera, DuckDuckGo and Safari.
- Examples of search engines (search engines): DuckDuckGo, Brave Search, Bing, StartPage, Private.sh, Qwant, MetaGer, FindX, Searx, Neeva, Mojeek and Presearch.
In order for two applications or devices to communicate with each other, there must be a communications protocol that establishes the rules that both must follow to achieve successful communication.
In the case of web content, the protocol that allows access to all this information online is Hypertext Transfer Protocol (HTTP).
Designed back in 1991, it did not take security into account from the beginning, so over time various measures have been implemented to enable encryption or authentication functions.
To overcome some of these shortcomings, digital certificates were used, giving rise to the secure variant known as HTTPS based on Transport Layer Security (TLS), recognizable by the letter “s” at the end of http.
Thanks to this, communications between the client and server can be encrypted (confidentiality) instead of being sent in plain text, as was the case with HTTP.
In addition, TLS also checks the authenticity of the connection and the integrity of the data, which prevents an attacker from modifying packets while they are in transit.
Currently, the HTTP protocol is in its HTTP/2 and HTTP/3 (QUIC, Quick UDP Internet Connections) versions.
And what does this “client-server” communication mean?
I will explain it with a simple example. From my home computer or cell phone, I open a browser (client) -for example, *Google Chrome-*to connect to a web page that is hosted on a server. It is called a server because, ultimately, it is the one that “serves” the information I was looking for.
As we have explained in previous articles, we must remember that browser security and privacy, although they go hand in hand, are different concepts.
Security is primarily concerned with technical aspects. For example, a security-conscious browser will frequently issue updates to its software to protect against the latest emerging malware. It might also automatically redirect connections from http to https whenever possible.
Browser privacy, on the other hand, is primarily concerned with user data. That is, it controls what information and activity the website can see about you, giving you the ability to manage your data.
A privacy-conscious browser might try to anonymize your information while you browse or even use a built-in VPN (Virtual Private Network) to hide your geographic location.
Except for the bill you have to pay monthly to the company that offers you Internet (e.g. Movistar), surfing the Internet is free and, as with almost everything free, there is always a hidden price: advertisers and data brokers will do everything they can to monetize the information they collect about your online habits and activity.
Fortunately, many of the same measures that result in increased security, such as blocking plug-ins and third-party trackers, also result in increased privacy when browsing.
The disadvantages associated with Internet surfing do not end there.
There is no need to mention how many times different websites ask us to register to access their content.
It could be considered acceptable to a certain extent, were it not for the fact that we leave a huge trail of private information, increasing our exposure surface as our data is found in more and more services.
These services could be attacked in the future, exposing our personal information.
๐ก To minimize this annoying practice, it is useful to resort to an online tool available at https://12ft.io/.
By prefixing 12ft.io/ to the URL of any page with a paywall, we will try to remove that barrier so that we can access the article without having to pay or register.
Let’s see an example with a news website. Its operation is based on the fact that, as news sites want to appear in Google search results, they do not show their paywall to the Google crawler.
The above technique of prefixing 12ft.io/ to the URL takes advantage of the same tactic used by the crawler to cache a copy of the site each time you visit it. In this way, the tool displays this cached version, which is freely accessible.
Have you ever read a text like this?
*We use cookies and other tracking technologies to enhance your browsing experience on our site, display personalized content and targeted advertisements, analyze site traffic and understand where our audiences are coming from. To learn more or opt out, please read our Cookie Policy. Please also read our Privacy Notice and Terms of Use, effective XX XXXXX, 20XX. By choosing I Agree, you consent to our use of cookies and other tracking technologies. *
The biggest lie on the Internet is when we hit “Accept”, which implies that:
“I have read and understand the terms of service.”
I’ll bet you 1 coffee and 3 beers that you never do.
The ineffective law concerning the use of cookies, the ePrivacy Directive, was passed in 2002 and amended in 2009. Since then, the web has become a veritable hell where, without exception, every site requires us to read a sort of contract that, in theory, we should go through carefully.
However, no one in their right mind would even think of skim-reading it, rushing to click on it as soon as possible to get it out of the way.
Many years have passed and I see that those who implemented this rule still find it hard to recognize that it is a nuisance and a failure that serves no purpose. I, as you can see, out of respect for my readers have decided to pass the rule by several places, although it is also true that, at least at the date of publication of this article, I do not track usage statistics of the blog.
I am reluctant to think that we are condemned for life to suffer the torture of cookie pop-ups on every website.
The intention of the law may have been good, but the result seems less so and the authorities should have reacted by now.
We have already seen repeatedly how companies such as Google, Meta or Amazon, which have been fined several times for this very reason, do not seem to care too much.
The profits obtained with this type of spying through cookies far exceed the millionaire fines imposed on them (cases of Google fined with 100 and 150 million euros, Facebook with 60 million, Amazon with 35 million, etc.), and there they continue…
Sometimes I wonder: is it so difficult to change that law so that websites, instead of asking everyone, are obliged to read the settings that the user has set in his browser?
If I set my browser to reject all cookies or only third-party cookies, then that would be my answer, without the need to be bothered with pop-ups.
Surely there must be some background that escapes me; otherwise, I don’t understand it.
The purpose of a cookie is to allow a website to remember things about you without having to maintain a huge database of all the users who visit it. Each cookie is a simple text file that is stored on your device (not on the site).
The website can write in the cookie information such as your preferred language, what to show each time you enter, the page you go to in an online book, what you put in your shopping cart, etc.
They are also used for logins: instead of re-entering the login credentials each time we enter a platform, after the first visit, our browser saves a session cookie that tells the site that we are already logged in and allows us to log in directly. (I will explain later what happens when hackers steal our session cookies).
So far so good. What is problematic are third-party cookies, which allow a third-party website to track your browsing habits and trends without you having visited their site directly.
Another of the problems associated with Internet browsing affects the user’s privacy.
Every time we make a connection through a web browser, a staggering amount of information is leaked from our computer.
With the right data processing tools, a user could be identified almost uniquely throughout the world.
These data include:
- the browser brand and version,
- the operating system version,
- the network,
- the type and model of device,
- language,
- the keyboard layout,
- the time zone,
- cookies enabled,
- plugins and extensions installed,
- the IP address,
- system sources,
- demographic data and much more.
The combination of all this information is what is known as the fingerprint.fingerprint), and it is what allows advertisers to recognize us when we move from one website to another.
However, not all fingerprinting is negative, as it is often used to detect possible fraud, as banks do when identifying suspicious behavior.
When it comes to surfing the Internet, there should be a “Las Vegas web rule”:
“What happens on a website stays on that website.” * * When you visit another page, it should not know exactly what you did on the previous site.
However, this is not unique to browsers.
The vast majority of the applications we install on our cell phones make numerous attempts to track us in the background, so as not to lose any detail of our activity.
That is, they can be even worse than browsers. For this reason, it is always more advisable to use a social network such as Facebook through the browser than installing its application on the cell phone.
As I mentioned at the beginning, this is part one of two on the subject of browsers. In the second part I assure you that you will discover valuable tips that you should apply, as well as other browser abuses that you will not believe.
Anyway, before finishing this first post, I leave you a few links to web pages that will help you to discover some of the information that your browser always exposes, so that you start to be aware of it:
Although we will go into more detail later (in the VPN section), by visiting the last two links you can perform a simple test to check what information your browser returns before and after connecting to a VPN.
As you will see, quality VPNs, such as the one offered by ProtonVPN, provide a higher level of protection and anonymity when connecting to the Internet.
But we will see in the next post.