15 KiB
meta_title | title | icon | description | cover | schema | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Privacy Respecting Mobile Web Browsers for Android and iOS - Privacy Guides | Mobile Browsers | material/cellphone-information | These browsers are what we currently recommend for standard/non-anonymous internet browsing on your phone. | mobile-browsers.webp |
|
These are our currently recommended mobile web browsers and configurations for standard/non-anonymous internet browsing. If you need to browse the internet anonymously, you should use Tor instead. In general, we recommend keeping extensions to a minimum; they have privileged access within your browser, require you to trust the developer, can make you stand out, and weaken site isolation.
Android
On Android, Firefox is still less secure than Chromium-based alternatives: Mozilla's engine, GeckoView, has yet to support site isolation or enable isolatedProcess.
Brave
Brave Browser includes a built-in content blocker and privacy features, many of which are enabled by default.
Brave is built upon the Chromium web browser project, so it should feel familiar and have minimal website compatibility issues.
:octicons-home-16: Homepage{ .md-button .md-button--primary } :simple-torbrowser:{ .card-link title="Onion Service" } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation} :octicons-code-16:{ .card-link title="Source Code" }
Recommended Configuration
Tor Browser is the only way to truly browse the internet anonymously. When you use Brave, we recommend changing the following settings to protect your privacy from certain parties, but all browsers other than the Tor Browser will be traceable by somebody in some regard or another.
These options can be found in :material-menu: → Settings → Brave Shields & privacy
Shields
Brave includes some anti-fingerprinting measures in its Shields feature. We suggest configuring these options globally across all pages that you visit.
Brave shields global defaults
Shields' options can be downgraded on a per-site basis as needed, but by default we recommend setting the following:
- Select Aggressive under Block trackers & ads
Use default filter lists
Brave allows you to select additional content filters within the internal brave://adblock
page. We advise against using this feature; instead, keep the default filter lists. Using extra lists will make you stand out from other Brave users and may also increase attack surface if there is an exploit in Brave and a malicious rule is added to one of the lists you use.
- Select Upgrade connections to HTTPS
- Select Always use secure connections
- (Optional) Select Block Scripts (1)
- Select Strict, may break sites under Block fingerprinting
- This option provides functionality similar to uBlock Origin's advanced blocking modes or the NoScript extension.
Clear browsing data
- Select Clear data on exit
Social Media Blocking
- Uncheck all social media components
Other privacy settings
- Select Disable non-proxied UDP under WebRTC IP handling policy
- Uncheck Allow sites to check if you have payment methods saved
- Uncheck IPFS Gateway (1)
- Select Close tabs on exit
- Uncheck Allow privacy-preserving product analytics (P3A)
- Uncheck Automatically send diagnostic reports
- Uncheck Automatically send daily usage ping to Brave
- InterPlanetary File System (IPFS) is a decentralized, peer-to-peer network for storing and sharing data in a distributed filesystem. Unless you use the feature, disable it.
Brave Sync
Brave Sync allows your browsing data (history, bookmarks, etc.) to be accessible on all your devices without requiring an account and protects it with E2EE.
Cromite
!!! recommendation
![Cromite logo](assets/img/browsers/cromite.svg){ align=right }
**Cromite** is a Chromium-based browser with privacy and security enhancements, built-in ad blocking, and some fingerprinting randomization. It is the continuation of Bromite.
[:octicons-code-16:](https://github.com/uazo/cromite){ .card-link title="Source Code" }
??? downloads annotate
- [:pg-f-droid: F-Droid](https://www.cromite.org/fdroid/repo/?fingerprint=49F37E74DEE483DCA2B991334FB5A0200787430D0B5F9A783DD5F13695E9517B)
These options can be found in :material-menu: → ⚙️ Settings → Privacy and security.
Recommended Configuration
HTTPS-Only Mode
- Select Always use secure connections
This prevents you from unintentionally connecting to a website in plain-text HTTP. The HTTP protocol is extremely uncommon nowadays, so this should have little to no impact on your day to day browsing.
Always-on Incognito Mode
- Select Always open links in incognito in the Always incognito mode menu
- Select Close all open tabs on exit
- Select Open external links in incognito
Disable legacy adblock
- Uncheck autoupdate
Adblock Plus
Cromite contains a customized version of Adblock Plus. You may select the appropriate filter lists, or add custom ones in Custom ad filtering settings.
- Select Enable anti-circumvention and snippets
iOS
On iOS, any app that can browse the web is restricted to using an Apple-provided WebKit framework, so there is little reason to use a third-party web browser.
Safari
Safari is the default browser in iOS. It includes privacy features such as Intelligent Tracking Prevention, Privacy Report, isolated and ephemeral Private Browsing tabs, iCloud Private Relay, fingerprinting protection by randomizing and presenting a simplified version of the system configuration to websites so more devices look identical, and the ability to lock private tabs with your biometrics/PIN. It also allows you to separate your browsing with different profiles.
:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation}
Recommended Configuration
These options can be found in ⚙️ Settings → Safari
Profiles
All of your cookies, history, and website data will be separate for each profile. You should use different profiles for different purposes e.g. Shopping, Work, or School.
Privacy & Security
-
Enable Prevent Cross-Site Tracking
This enables WebKit's Intelligent Tracking Protection. The feature helps protect against unwanted tracking by using on-device machine learning to stop trackers. ITP protects against many common threats, but it does not block all tracking avenues because it is designed to not interfere with website usability.
-
Enable Require Face ID to Unlock Private Browsing
This setting allows you to lock your private tabs behind biometrics/PIN when not in use.
Advanced → Privacy
The Advanced Tracking and Fingerprinting Protection setting will randomize certain values so that it's more difficult to fingerprint you:
- Select All Browsing or Private Browsing
Privacy Report
Privacy Report provides a snapshot of cross-site trackers currently prevented from profiling you on the website you're visiting. It can also display a weekly report to show which trackers have been blocked over time.
Privacy Report is accessible via the Page Settings menu.
Privacy Preserving Ad Measurement
- Disable Privacy Preserving Ad Measurement
Ad click measurement has traditionally used tracking technology that infringes on user privacy. Private Click Measurement is a WebKit feature and proposed web standard aimed towards allowing advertisers to measure the effectiveness of web campaigns without compromising on user privacy.
The feature has little privacy concerns on its own, so while you can choose to leave it on, we consider the fact that it's automatically disabled in Private Browsing to be an indicator for disabling the feature.
Always-on Private Browsing
Open Safari and tap the Tabs button, located in the bottom right. Then, expand the Tab Groups list.
- Select Private
Safari's Private Browsing mode offers additional privacy protections. Private Browsing uses a new ephemeral session for each tab, meaning tabs are isolated from one another. There are also other smaller privacy benefits with Private Browsing, such as not sending a webpage’s address to Apple when using Safari's translation feature.
Do note that Private Browsing does not save cookies and website data, so it won't be possible to remain signed into sites. This may be an inconvenience.
iCloud Sync
Synchronization of Safari History, Tab Groups, iCloud Tabs and saved passwords are E2EE. However, by default, bookmarks are not. Apple can decrypt and access them in accordance with their privacy policy.
You can enable E2EE for your Safari bookmarks and downloads by enabling Advanced Data Protection. Go to your Apple ID name → iCloud → Advanced Data Protection.
- Turn On Advanced Data Protection
If you use iCloud with Advanced Data Protection disabled, we also recommend checking to ensure Safari's default download location is set to locally on your device. This option can be found in ⚙️ Settings → Safari → General → Downloads.
AdGuard
AdGuard for iOS is a free and open-source content-blocking extension for Safari that uses the native Content Blocker API.
AdGuard for iOS has some premium features; however, standard Safari content blocking is free of charge.
:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation} :octicons-code-16:{ .card-link title="Source Code" }
Downloads
Additional filter lists do slow things down and may increase your attack surface, so only apply what you need.
Criteria
Please note we are not affiliated with any of the projects we recommend. In addition to our standard criteria, we have developed a clear set of requirements to allow us to provide objective recommendations. We suggest you familiarize yourself with this list before choosing to use a project, and conduct your own research to ensure it's the right choice for you.
This section is new
We are working on establishing defined criteria for every section of our site, and this may be subject to change. If you have any questions about our criteria, please ask on our forum and don't assume we didn't consider something when making our recommendations if it is not listed here. There are many factors considered and discussed when we recommend a project, and documenting every single one is a work-in-progress.
Minimum Requirements
- Must support automatic updates.
- Must receive engine updates in 0-1 days from upstream release.
- Any changes required to make the browser more privacy-respecting should not negatively impact user experience.
- Android browsers must use the Chromium engine.
- Unfortunately, Mozilla GeckoView is still less secure than Chromium on Android.
- iOS browsers are limited to WebKit.
Extension Criteria
- Must not replicate built-in browser or OS functionality.
- Must directly impact user privacy, i.e. must not simply provide information.