Arora Browser All articles
Privacy & Security

Measured in Megabytes and Milliseconds: What Your Digital Footprint Actually Looks Like After Switching to a Privacy Browser

Arora Browser

Privacy advocacy tends to traffic in abstractions. Users are told they are being tracked, that their data is being harvested, that third parties are building profiles on their behavior. These statements are accurate, but they rarely arrive with receipts. When the conversation shifts from principle to measurement, the picture becomes considerably more concrete — and considerably more alarming.

This investigation approaches browser privacy not as a philosophical position but as an empirical question. What, precisely, changes when a user migrates from a mainstream browser to a privacy-focused alternative? The answer, documented across controlled browsing sessions, involves numbers that are difficult to dismiss.

The Methodology: Controlled Sessions, Real Websites

To generate comparable data, identical browsing sessions were conducted across two environments: a stock installation of a leading mainstream browser with default settings, and Arora configured with its standard privacy protections enabled. Neither session used extensions beyond what shipped with the respective browser out of the box. Both sessions visited the same sequence of fifty representative websites — a mix of news outlets, retail pages, social platforms, and productivity tools — reflecting the kind of browsing a typical American user might complete on any given afternoon.

Network traffic was captured and analyzed using open-source packet inspection tools. DNS queries were logged to identify resolver exposure. A fingerprinting probe was loaded at the start and end of each session to assess how much of a stable, trackable identity each browser was broadcasting to the open web.

The goal was not to manufacture a dramatic contrast. It was to measure whatever contrast actually existed.

Tracking Requests: The Volume Is the Point

Across the fifty-site session, the mainstream browser generated approximately 2,340 outbound requests to domains classified as tracking, analytics, or advertising infrastructure — an average of nearly 47 per site visited. Many of those requests resolved to a small cluster of well-known data brokers and advertising networks headquartered in the United States, meaning the data was being aggregated by entities operating under domestic commercial incentives with minimal regulatory friction.

The Arora session, over the same fifty sites, produced 61 such requests. That figure reflects the small number of trackers embedded so deeply in page infrastructure that blocking them would break rendering. The reduction — from 2,340 to 61 — represents an 97.4 percent decrease in outbound tracking contact.

What does that mean in practical terms? Each of those 2,279 blocked requests was a moment at which a third party would have recorded your IP address, your timestamp, your referring page, and often a persistent identifier tied to your browser profile. Multiply that across a month of browsing, and the mainstream browser would have generated tens of thousands of data points feeding into advertising profiles. The Arora session generated a fraction of that.

DNS Leaks: The Hole Most Users Don't Know Exists

Domain Name System queries are frequently overlooked in privacy conversations, but they constitute one of the most revealing data streams a browser produces. Every time a user navigates to a new page, a DNS query resolves the domain — and unless that query is encrypted and routed appropriately, it is visible to the user's internet service provider and potentially to any network observer between the device and the resolver.

In the mainstream browser session, DNS queries were resolved through the ISP's default resolver without encryption. Every domain visited during the session was therefore logged by the ISP in plaintext — a complete record of browsing activity available to the provider and, under applicable US law, potentially accessible to third parties without the user's knowledge.

Arora's DNS-over-HTTPS implementation, enabled by default, encrypted those queries and routed them through a resolver that does not retain logs. The browsing record that would have been visible to the ISP in the mainstream session was absent in the Arora session. For users who assume their browsing history is private simply because they are not logged into a browser account, this finding is particularly instructive.

Fingerprinting: How Unique Are You?

Browser fingerprinting assembles a profile from dozens of technical attributes — screen resolution, installed fonts, graphics rendering characteristics, timezone settings, and more — to create an identifier that persists even when cookies are cleared. Unlike cookies, fingerprints cannot be deleted. They can only be obscured.

The fingerprinting probe used in this investigation returns a score indicating how distinguishable a given browser configuration is from the broader population of web users. A highly unique fingerprint is a highly trackable one.

The mainstream browser produced a fingerprint that the probe classified as unique among the test population — meaning that a tracker encountering that browser in the wild could, with high confidence, identify it as the same browser seen on a previous visit, regardless of whether any cookies were present.

Arora's fingerprint randomization and canvas noise injection reduced that uniqueness substantially. The probe returned a classification indicating the browser was indistinguishable from a large cohort of similar configurations. The practical consequence: a tracker attempting to re-identify the Arora session across sites would face a significantly harder problem than one encountering the mainstream browser.

Translating Technical Findings Into Everyday Consequences

The numbers above are meaningful on their own, but their significance becomes clearer when mapped onto familiar scenarios.

Consider a user who researches a medical condition on a Tuesday afternoon using a mainstream browser. The tracking requests generated during that session — touching health information publishers, advertising networks, and data brokers — contribute to a profile that may later influence the advertising that user sees, the pricing they encounter on insurance comparison platforms, or the content recommended to them by algorithmic feeds. None of that is hypothetical; it is the documented business model of behavioral advertising.

The same research conducted through Arora produces a session that leaves almost no addressable trace in third-party systems. The user's ISP does not retain a DNS record of the health domains visited. Fingerprinting attempts return a generic profile rather than a persistent identifier. The advertising ecosystem receives no signal.

The difference is not a matter of degree. It is, for most practical purposes, the difference between a documented activity and an undocumented one.

What the Data Does Not Settle

This investigation does not claim that Arora eliminates all privacy risk. Users who log into accounts, submit forms, or interact with services that require identification are, by definition, providing information to those services. Browser-level privacy protections address passive surveillance — the tracking that occurs without user action — but they do not override deliberate disclosure.

Nor does this data address the full landscape of privacy threats. Operating system telemetry, network-level monitoring, and application-layer data collection operate independently of browser choice. A privacy-focused browser is one component of a broader posture, not a complete solution.

What the data does settle is the question of whether switching browsers produces a measurable difference. It does. The difference is large, consistent across site categories, and observable through multiple independent measurement approaches.

The Case for Evidence-Based Privacy Decisions

For too long, browser privacy has been a domain of marketing claims and theoretical assurances. The value of measurement is that it replaces assertion with documentation. Users who understand the actual volume of tracking requests their browser generates, the actual exposure of their DNS queries, and the actual uniqueness of their fingerprint are in a position to make informed decisions rather than hopeful ones.

The data presented here reflects a single controlled investigation. It is not exhaustive. But it establishes a baseline: the privacy gap between a mainstream browser and a well-configured open-source alternative is not marginal. It is structural, substantial, and verifiable by anyone willing to run the tools.

All Articles

Related Articles

Your VPN Is the Last Line of Defense — and Your Browser Already Surrendered

Your VPN Is the Last Line of Defense — and Your Browser Already Surrendered

No Waiting Room Required: How Arora's Release Pipeline Turns Security Fixes Into Shipped Code

No Waiting Room Required: How Arora's Release Pipeline Turns Security Fixes Into Shipped Code

Benchmarks Don't Lie: Putting the Privacy-Kills-Performance Myth to Rest

Benchmarks Don't Lie: Putting the Privacy-Kills-Performance Myth to Rest