Summary

The most successful piece of security theater on the modern internet is a small icon of a hat and glasses. Click it, and a black-themed window opens with a reassuring paragraph explaining that you’re now browsing “privately.” Two decades of users have taken that at face value. Two decades of users have been wrong — not because the feature is broken, but because the name is a lie that Google and its competitors have been remarkably slow to correct. Incognito mode does exactly one useful thing: it prevents the browser on the machine in front of you from saving your history, cookies, and form data after you close the window. That’s it. That’s the entire feature. It is a local housekeeping tool designed for the specific scenario of sharing a family laptop, using a hotel business center, or shopping for a gift you don’t want your partner to see in the autocomplete bar. In that narrow context, it works fine. In every other context in which people actually use it, it protects nothing. Consider what Incognito does not hide. It does not hide your traffic from your internet service provider, which still sees every domain you connect to. It does not hide your activity from a school or workplace network administrator, who is often the exact person users are trying to evade. It does not hide you from the websites you visit, which continue to log your IP address, browser fingerprint, and — the moment you sign in — your identity. It does not hide you from advertisers who fingerprint your device across sessions. And, as Google was recently forced to admit in court, it doesn’t even fully hide you from Google. That court case is worth dwelling on, because it is the closest thing we have to a formal admission that the feature’s name was misleading. In late 2023, Google agreed to settle a class-action lawsuit that had sought 5 billion lawsuit was, at its core, an accusation that Google understood this misalignment perfectly well and shipped the feature anyway. I’m not arguing that Incognito mode should be removed. It solves the shared-device problem cleanly and it’s genuinely useful for logging into a second account, testing a website as an anonymous visitor, or breaking out of a paywall’s cookie-based counter. What I’m arguing is that we should stop calling it privacy. The honest name for the feature is something like “Don’t Save This Session,” which is exactly what it does and exactly nothing more. Ephemeral local state is a useful primitive. It is not anonymity, it is not encryption, and it is not protection from anyone whose computer isn’t currently sitting on your desk. The next time you open a private window before searching for something you’d rather your ISP, your employer, or the site itself didn’t know about, take the extra two seconds to ask which of those three you’re actually hiding from. If the answer is any of them, Incognito is the wrong tool. The right tool exists — it’s just not the one with the fedora on it.

By Justin Brown

Original Article