The Cybersecurity Course · Episode 7
Read time ~8 min · No prior knowledge

Browser
security

Almost everything you do online passes through the browser — banking, email, shopping, social media. That makes it your most important shield and the attacker's favourite target at the same time. Here we untangle what the padlock actually means, how tracking works, which browser to use, and the one extension that's genuinely needed.

Contents
  1. What the padlock actually promises — and doesn't
  2. Three kinds of cookies — and tracking beyond them
  3. Choosing a browser — and the uBlock Origin problem
  4. The settings that matter
  5. The incognito myth and mobile
  6. Sources

What the padlock actually promises — and doesn't

HTTPS — the padlock in the address bar — means the traffic between you and the website is encrypted: nobody along the way (the café WiFi, your ISP) can read or alter what you send. That matters, and it's good.

But the padlock says nothing about who you're talking to. Certificates are free and automated (thanks to, among others, Let's Encrypt) — which is why phishing sites have padlocks too. Industry body APWG has reported for years that the large majority of phishing sites are served over HTTPS.

Remember Padlock = encrypted line. Not = the right counterpart. An encrypted connection to a fraudster is still a connection to a fraudster. What counts is the domain name — letter by letter.

Three kinds of cookies — and tracking beyond them

Tracking doesn't end with cookies though. Fingerprinting identifies you via your browser's unique combination of screen resolution, fonts, time zone and hardware — without storing anything at all. Test how unique your browser is at EFF's Cover Your Tracks.

Choosing a browser — and the uBlock Origin problem

BrowserStrengthsKeep in mind
FirefoxStrong tracking protection by default, independent of the ad giants, full uBlock Origin support.Requires the energy to switch habits from Chrome.
BraveBuilt-in ad and tracker blocking, Chrome-compatible.Its own crypto features can annoy — they can be switched off.
SafariGood tracking protection and energy-efficient — the obvious choice on Apple devices.Limited extension catalogue.
Chrome/EdgeTechnically very secure: fast security updates, strong sandbox, Safe Browsing.Built by ad companies — and Chrome's new extension system (Manifest V3) has kneecapped the full version of uBlock Origin. What remains is the weaker uBlock Origin Lite.

Our recommendation for most people: Firefox or Brave, plus uBlock Origin. A serious content blocker isn't just comfort — it blocks malvertising (episode 6) and many trackers before they even load. It's the only extension you need; every additional extension is itself a risk, so install few and only well-known ones.

The settings that matter

  1. Keep the browser updated — and restart when it asks (episode 5).
  2. Turn on HTTPS-only mode — the browser then refuses unencrypted connections. (Firefox guide; available in all major browsers.)
  3. Block third-party cookies if that isn't already the default.
  4. Let your password manager replace the browser's save feature (episode 2) — infostealers harvest browser-stored passwords first.
  5. Prune your extensions. Remove everything you don't use. Extensions have far-reaching permissions, and abandoned ones are sometimes sold to shady actors who update in tracking or worse.

The incognito myth and mobile

Private/incognito mode does one thing: the browser forgets history, cookies and form data locally when the window closes. It hides nothing from websites, your ISP, your employer's network or Google. It's a tool against people who share your computer — not anonymity.

On mobile: Safari on iPhone and Firefox or Brave on Android give the same protection as on desktop. Watch out for in-app browsers (links opened inside Instagram, Facebook, TikTok) — the app can monitor what you do there. Choose "open in browser" for anything involving logins or payments. And keep the number of browser apps down: every extra browser is another surface to keep updated.

Next time Your phone is now your most important computer — it holds your email, your e-ID and your photos. Episode 8 is devoted entirely to it: screen locks, app permissions, sideloading and what to do if it gets stolen.

Sources

Want to dig deeper? These are the sources behind this episode.

  1. Let's Encrypt — letsencrypt.org — free certificates for everyone, crooks included.
  2. APWG — Phishing Activity Trends Reports — the share of phishing sites using HTTPS.
  3. EFF — Cover Your Tracks — test your browser's fingerprint.
  4. Mozilla — Firefox — tracking protection by default.
  5. Brave — brave.com — built-in blocking.
  6. uBlock Origin — ublockorigin.com — the content blocker, incl. the Chrome/MV3 situation.
  7. Google — Safe Browsing — the warning system against known malicious sites.
  8. Mozilla — HTTPS-Only Mode — setup guide.
  9. Apple — Safari: Prevent cross-site tracking — tracking protection on Apple devices.
Next episode

Episode 8 — Phone security

Screen locks, app permissions, sideloading and Android vs iOS — plus what to do if your phone is stolen.