Skip to content

What your browser quietly leaks, and the four settings that stop it

You typed the search at 1am, alone. A health worry, a secret question, a private curiosity. You closed the tab. But by breakfast, three companies you’ve never heard of knew. The ad for that exact thing followed you to your news app, then to your social feed. It felt like your screen was reading your mind. It wasn’t. It was just your browser, quietly telling them everything.

The short version: Your browser leaks a constant stream of data points—its version, your screen size, installed fonts—that create a unique “fingerprint” to track you, even without cookies. To stop this, you need to go beyond clearing your history and use four specific settings: block JavaScript by default, encrypt your DNS, block all third-party cookies, and aggressively audit your browser extensions.

What is browser fingerprinting? The Unseen Emissions that track you without cookies

That feeling of being watched isn’t paranoia. It’s the business model of the modern web, and your browser is an unwilling accomplice. Every time you visit a site, your browser sends out a cloud of data, a plume of Unseen Emissions. Some of this is necessary, like telling a site how to format itself for your screen. But most of it is a quiet betrayal.

Free download: The Sovereign Toolkit Blueprint 2026

The 12-point setup for a private, secure, high-output digital life — in one afternoon. No spam, unsubscribe anytime.

This is the engine of browser fingerprinting. Forget cookies, which you can delete. Fingerprinting is more insidious. Trackers collect dozens of seemingly harmless signals your browser emits:

  • Your User Agent String, a technical signature like `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36`.
  • Your screen resolution and colour depth.
  • The specific list of fonts installed on your computer.
  • The number of processor cores your machine has (Hardware Concurrency).
  • Tiny variations in how your graphics card draws a hidden image (Canvas fingerprinting) or processes a silent sound (Web Audio fingerprinting).

Individually, these are just specs. But combined, they create a portrait of your device so unique it can identify you in a crowd of millions. This isn’t about knowing your name. It’s about assigning a permanent ID to your browser, a digital ghost that follows you from site to site, building a profile of your life, one click at a time. The villain isn’t you for being “careless”; it’s a system designed to make your browser overshare by default.

Why clearing cookies and incognito mode don’t work: The great privacy misunderstanding

For years, you’ve been told the same two things: if you’re worried about privacy, clear your cookies and use “Incognito Mode.” This advice is not just incomplete; it’s the reason you still feel tracked. It’s like locking your front door while leaving all the windows wide open.

Here is the turn, the one idea that changes the game: True browser privacy has almost nothing to do with your history file and everything to do with the live signals your browser broadcasts in real-time.

Incognito mode only does one thing: it stops your browser from saving your history and cookies on your local machine when you close the window. It does nothing to stop trackers from fingerprinting you during that session. Your IP address is still visible. Your activity is still visible to your Internet Service Provider (ISP), your employer, and every website you visit.

Here’s the twist most people never catch: incognito mode was built to hide your history from someone standing over your shoulder later—not from the internet watching you right now. It isn’t the problem it feels like it’s solving. The real problem lives in a completely different layer, the live signals your browser hands out in real time, and no amount of “private” browsing touches that layer at all.

Clearing cookies is a temporary fix for a permanent problem. Trackers simply use your browser’s unique fingerprint to re-identify you and place a new cookie, sometimes in a matter of seconds. You are fighting a battle you cannot win with the tools you’ve been given. The real path to digital sovereignty isn’t about cleaning up the past; it’s about silencing the present.

The 4 browser settings that reclaim your privacy: A step-by-step guide

This isn’t a long list of homework. It’s a short, high-use checklist. These four changes are the foundation of a browser that works for you, not for the surveillance machine. They move you from a state of being constantly exposed to one of deliberate control.

1. Disable JavaScript by Default

JavaScript is the engine of the interactive web. It’s also the primary weapon used for advanced fingerprinting.

  • Why it leaks: JavaScript is how a website can query your fonts, run Canvas and Web Audio tests, and access the browser APIs that reveal your hardware. Blocking it is like cutting the spy’s communication line.
  • The trade-off: Disabling it everywhere will break many modern websites. The solution is not to turn it off, but to control it.
  • The solution: Use an extension that blocks JavaScript by default and allows you to enable it only for sites you trust. This one change neuters the vast majority of fingerprinting techniques.
  • Action (5-minute fix):
  • Install a script-blocker like NoScript (for Firefox) or the still-functional uMatrix (for Chrome/Firefox).
  • Set its default to BLOCK all scripts.
  • When a trusted site needs it to function (like your bank), click the extension icon and temporarily allow the main script. You are now in control, granting permission instead of having it taken.

2. Encrypt Your DNS Requests

Even with a VPN, your browser might be leaking every website you visit to your ISP. This happens through unencrypted DNS requests—the internet’s phonebook.

  • Why it leaks: When your browser asks, “What IP address is theunhacked.com?” your ISP can see the question and log it, even if the rest of your traffic is hidden inside a VPN. This is called a DNS leak.
  • The trade-off: You’ll be routing your DNS requests through a third party like Cloudflare or Quad9. This means trusting their privacy policy, but it’s a far better bet than trusting your ISP, which has a financial incentive to monetize your data.
  • The solution: Enable DNS-over-HTTPS (TLS) in your browser settings. This encrypts the “phonebook” lookup, hiding it from your ISP.
  • Action (2-minute fix):
  • Firefox: Go to `Settings > General > Network Settings > Enable DNS over HTTPS`. Choose a provider.
  • Chrome/Edge: Go to `Settings > Privacy and security > Security > Use secure DNS`. Select a provider.
  • Verify it’s working at a site like dnsleaktest.com. The servers listed should no longer belong to your ISP.

3. Block All Third-Party Cookies and Trackers

First-party cookies are useful; they keep you logged in. Third-party cookies are spies. They are set by ad networks and data brokers to follow you across the web.

  • Why it leaks: A third-party cookie from an ad network on Site A can identify you when you later visit Site B, which has a tracker from the same network. This is how the ad for the shoes you looked at on one site follows you to another.
  • The trade-off: Very occasionally, blocking third-party cookies can break “Login with Google/Facebook” buttons or some embedded media. You can easily make a temporary exception for that site. It’s a tiny price for immense privacy gain.
  • The solution: Set your browser’s privacy settings to “Strict” and explicitly block all third-party cookies. Then, install a robust content blocker to catch what the browser misses.
  • Action (1-minute fix):
  • Firefox: Go to `Settings > Privacy & Security > Enhanced Tracking Protection`. Set it to “Strict.”
  • Chrome/Edge: Go to `Settings > Privacy and security > Third-party cookies` and select “Block third-party cookies.”
  • For everyone: Install uBlock Origin. It’s more than an ad-blocker; it’s a wide-spectrum tracker blocker and one of the most effective privacy tools available.

4. Aggressively Audit Your Extensions

Browser extensions are like houseguests. Some are helpful. Others rifle through your drawers when you’re not looking. Each one is a potential privacy backdoor.

  • Why it leaks: An extension with permission to “read and change all your data on all websites” can do exactly that. It can log your passwords, inject trackers, and sell your browsing history. Even a legitimate extension can be sold to a new owner who turns it into harmful software.
  • The trade-off: You might lose some convenience. But the security you gain is worth more than a pop-up grammar checker.
  • The solution: Adopt a zero-trust policy. Remove every extension you don’t absolutely need and deeply trust. For those you keep, scrutinize their permissions.
  • Action (10-minute audit):
  • Go to your browser’s extensions page (`chrome://extensions` or `about:addons`).
  • For each extension, ask: “Do I use this daily? Who made it? Does it need access to every site I visit?”
  • Remove, don’t just disable. If you don’t need it, uninstall it. Be ruthless. Your privacy depends on it.

Frequently asked questions

My browser has a built-in “anti-tracking” feature. Is that enough?

Built-in tools like Firefox’s Enhanced Tracking Protection are an excellent starting point and far better than nothing. They block known trackers and some fingerprinting. However, they are often less aggressive than a dedicated tool like uBlock Origin and can be outmaneuvered by new tracking techniques. Think of them as a good lock on your door, but you still want the advanced alarm system. For robust protection, combine the browser’s strongest native settings with a powerful content blocker.

Will these settings make my browser slower?

It’s a mixed bag, but the net effect is often positive. Disabling JavaScript (Setting 1) can make pages load faster because they aren’t bogged down with scripts. Blocking trackers and third-party cookies (Setting 3) almost always improves speed. Using a secure DNS resolver (Setting 2) might add a few milliseconds of latency, but it’s usually imperceptible. The only friction comes from manually enabling scripts on a new site, a small price for taking back control.

What about using a privacy-focused browser like Tor Browser or Brave?

They are an excellent choice. Tor Browser is the gold standard for anonymity, but it’s slow and can break sites, making it impractical for daily use. Brave is a great middle ground, blocking ads and trackers by default. But even with these browsers, the principles remain the same. They give you a better starting point, but they are not magic bullets. You still need to manage extensions and understand the trade-offs.

If I use a VPN, do I still need to worry about DNS leaks?

Yes, absolutely. This is a critical point many users miss. A VPN encrypts your main traffic, but your browser or OS can still send DNS queries “outside” the VPN tunnel directly to your ISP. This is a DNS leak. That’s why Setting 2—configuring DNS-over-HTTPS in the browser itself—is so important. It forces the DNS request to be encrypted and routed correctly, closing a major loophole in your privacy setup.

What does an unhacked browser feel like? From tracked product to sovereign user

After you make these changes, the web feels different. Quieter. The ad that followed you for a week is gone. The clickbait headlines seem less manipulative because the algorithms have less data to work with. You’ve stopped shouting your every intention into the void and started whispering.

This isn’t about becoming an anonymous ghost. It’s about restoring the proper relationship between you and your tools. Your browser is your agent, not a spy for the highest bidder. By taking these steps, you change your status from “product” to “owner.” You’re no longer a resource to be mined for a few cents of ad revenue, a profile to be sold, or a digital footprint to be misuseed.

You’ve taken the first, most important step. You understand the game. Now, you can browse on your own terms.

Recommended: If you want a vetted, powerful DNS service that blocks harmful software and trackers at the network level, we use and recommend NextDNS (private DNS). Affiliate link — we may earn a commission; our verdict is not for sale.

DrAshR · Founder & Editor, The Unhacked

DrAshR is the founder and editor of The Unhacked, an independent publication on digital sovereignty — privacy, self-custody, health, and money. The Unhacked publishes disclosure-first, independently-tested guidance and never lets a commercial link change a verdict. More about our methodology →

The Signal - free dispatch

One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.

Free. No spam. Unsubscribe any time.

Affiliate disclosure. The Unhacked may earn a commission when you use some links on this page. Recommendations remain editorially independent.
📡

Join the Inner Circle

Weekly dispatches. No algorithms. No surveillance. Just sovereign intelligence.

Zero spam · Fully private · Sovereign by design.