Incognito mode was never private — it hides your history from the family laptop, not from your ISP, your employer or the site you just logged into

Incognito mode was never private — it hides your history from the family laptop, not from your ISP, your employer or the site you just logged into

The most successful piece of security theater on the modern internet is a small icon of a hat and glasses. Click it, and a black-themed window opens with a reassuring paragraph explaining that you’re now browsing “privately.” Two decades of users have taken that at face value. Two decades of users have been wrong — not because the feature is broken, but because the name is a lie that Google and its competitors have been remarkably slow to correct.

Incognito mode does exactly one useful thing: it prevents the browser on the machine in front of you from saving your history, cookies, and form data after you close the window. That’s it. That’s the entire feature. It is a local housekeeping tool designed for the specific scenario of sharing a family laptop, using a hotel business center, or shopping for a gift you don’t want your partner to see in the autocomplete bar. In that narrow context, it works fine. In every other context in which people actually use it, it protects nothing.

Consider what Incognito does not hide. It does not hide your traffic from your internet service provider, which still sees every domain you connect to. It does not hide your activity from a school or workplace network administrator, who is often the exact person users are trying to evade. It does not hide you from the websites you visit, which continue to log your IP address, browser fingerprint, and — the moment you sign in — your identity. It does not hide you from advertisers who fingerprint your device across sessions. And, as Google was recently forced to admit in court, it doesn’t even fully hide you from Google.

That court case is worth dwelling on, because it is the closest thing we have to a formal admission that the feature’s name was misleading. In late 2023, Google agreed to settle a class-action lawsuit that had sought $5 billion in damages on behalf of users who believed Incognito mode kept their browsing private from Google itself. As part of the settlement, Google agreed to destroy billions of data records collected from Incognito sessions and to update the disclosure language shown when users open a new private window. The plaintiffs’ argument, in essence, was that a reasonable person reading the word “Incognito” would assume they were, in fact, incognito. The court found that argument credible enough to force a settlement.

The mechanics of why Incognito fails are almost embarrassingly simple once you understand how a web request actually travels. When you type a URL, your computer first asks a DNS server to translate that domain name into an IP address. That DNS query is, by default, unencrypted, and it goes to a server operated by your ISP or your network’s administrator. It doesn’t matter whether your browser is in private mode or not — the DNS lookup happens at the operating system level, well below anything the browser controls. I’ve written before about this specific gap: HTTPS encrypts the contents of the pages you load, but the list of domains you visit still gets broadcast in plain text to whoever runs your network. Incognito changes none of that.

Then there’s the destination itself. When you visit a website in Incognito mode, that site receives the same IP address, the same User-Agent string, the same screen resolution, the same installed font list, and the same subtle timing quirks it would receive from a normal browser session. Researchers at the Electronic Frontier Foundation have demonstrated for years that this combination — browser fingerprinting — uniquely identifies most users even without any cookies at all. Incognito mode, by design, does not touch fingerprinting. It cannot, because the whole point of a functional browser is to send information about itself so pages render correctly.

What actually protects the things people think Incognito protects is a different stack of tools entirely, and it’s worth being specific about which tool solves which problem. If you want to hide your browsing from your ISP or a network administrator, you need a VPN or Tor, which route your traffic through an encrypted tunnel to a different exit point. If you want to reduce fingerprinting, you need a browser like Tor Browser or hardened Firefox with resistFingerprinting enabled. If you want to prevent websites from linking your sessions, you need to not log in — Incognito is helpless the moment you type your Gmail password, because at that point you have voluntarily told Google exactly who you are. Mozilla is fairly blunt about this in its own documentation on private browsing myths, where the first misconception it knocks down is the belief that the mode makes you anonymous online: it does not hide you from the websites you visit, your ISP, your employer, or your search engine.

None of this is a secret. It’s in the fine print of the disclosure screen. But the fine print is doing work that the feature’s name and iconography actively undermine. Chrome’s original Incognito splash showed a stylized spy in a fedora. Firefox uses a purple mask. Safari darkens the URL bar. The visual language is unambiguous: you are now a shadowy figure, unseen. The paragraph of text below that graphic — the one saying your activity “might still be visible to websites you visit, your employer or school, or your internet service provider” — is doing all of the honesty and none of the branding. A 2017 Pew Research survey found that only 39% of internet users knew that their ISP can still see the sites they visit while they are in private browsing mode, and other studies have consistently shown that people overestimate its protections.

The generous reading is that Incognito was designed in a simpler era, before browser fingerprinting was industrialized and before ISPs began monetizing browsing data at scale. Chrome introduced Incognito in 2008, back when third-party cookies were still the dominant tracking mechanism and clearing them at session end genuinely did meaningful work. In that world, the feature’s promises roughly matched its capabilities. The tracking ecosystem has evolved dramatically since; the feature, and more importantly its name, has not.

The less generous reading is that the ambiguity is useful to the companies shipping the feature. A browser vendor that also runs an advertising business has an obvious interest in users feeling protected without actually being protected in ways that would interfere with ad targeting. The $5 billion lawsuit was, at its core, an accusation that Google understood this misalignment perfectly well and shipped the feature anyway.

I’m not arguing that Incognito mode should be removed. It solves the shared-device problem cleanly and it’s genuinely useful for logging into a second account, testing a website as an anonymous visitor, or breaking out of a paywall’s cookie-based counter. What I’m arguing is that we should stop calling it privacy. The honest name for the feature is something like “Don’t Save This Session,” which is exactly what it does and exactly nothing more. Ephemeral local state is a useful primitive. It is not anonymity, it is not encryption, and it is not protection from anyone whose computer isn’t currently sitting on your desk.

The next time you open a private window before searching for something you’d rather your ISP, your employer, or the site itself didn’t know about, take the extra two seconds to ask which of those three you’re actually hiding from. If the answer is any of them, Incognito is the wrong tool. The right tool exists — it’s just not the one with the fedora on it.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Read next

HTTPS doesn’t encrypt which sites you visit — it hides the page contents, but your DNS lookups still broadcast every domain you open in plain text to your internet provider
In 1947, Harvard’s Mark II ran on roughly 13,000 electromechanical relays, stored numbers across 100 registers, and read instructions from punched paper tape, turning thousands of clicking metal switches into a Navy calculator vulnerable to dust, loose contacts, and one famously misplaced moth
In 1971, engineer Ray Tomlinson sent the first networked email between two computers sitting side by side in the same room — he chose the @ symbol to separate user from machine because it was the only punctuation on the keyboard nobody was using
How did a single computer worm written by a Cornell graduate student in November 1988 crash roughly 6,000 machines and force the internet to invent security?
When you tilt a smartphone, gravity shifts microscopic silicon fingers inside its accelerometer by only a few nanometres, changing the capacitance between them and producing the electrical imbalance the phone reads as a new direction for down
A microwave oven works because water molecules have a slight positive and negative end — the magnetron flips an electric field 2.45 billion times a second, and the molecules twist back and forth so fast the friction becomes heat
The retina of the mantis shrimp carries twelve types of colour receptor to the human eye’s three — and yet experiments suggest it sees colour worse than we do, using the extra channels for speed instead of subtlety
When a lightning return stroke heats a channel only centimetres wide to roughly 30,000 kelvin, about five times the temperature of the Sun’s visible surface, the air expands so violently that the pressure wave rolls across the ground as thunder