News: 1750746735

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

'Psylo' browser tries to obscure digital fingerprints by giving every tab its own IP address

(2025/06/24)


Psylo, which bills itself as a new kind of private web browser, debuted last Tuesday in Apple's App Store, one day ahead of a report warning about the widespread use of browser fingerprinting for ad tracking and targeting.

It was a fortuitous coincidence.

[1]Psylo for iOS and iPadOS was created by Mysk, a Canada-based app biz run by software developers and security researchers Talal Haj Bakry and Tommy Mysk.

[2]

"Psylo stands out as it is the only WebKit-based iOS browser that truly isolates tabs," Tommy Mysk told The Register . "It's not only about separate storage and cookies. Psylo goes beyond that.

[3]

[4]

"This is why we call tabs 'silos.' It applies unique anti-fingerprinting measures per silo, such as canvas randomization. This way two Psylo tabs opening the same website would appear as though they originated on two different devices to the opened website."

"Browser fingerprinting" sees developers use APIs in native apps and web browsers to gather information about netizens’ hardware and software configurations. The technique makes it possible to gather info on users’ screen resolution, operating system, plus browser type and version.

[5]

Marketers who analyze that info can create a reasonably accurate description of a user – their “fingerprint”. It’s worth the effort because a fingerprint is a more robust alternative than less constant identifiers, such as IP addresses and the values written to cookies.

The Electronic Frontier Foundation released [6]a paper [PDF] back in 2010 that called out risks associated with browser fingerprinting. Since then, browser API developers have tried to make fingerprinting more difficult, even as others have developed [7]libraries to simplify online fingerprinting , notionally for legitimate purposes like fighting fraud.

The latest word on the subject comes from researchers at Texas A&M University. Last week, computer scientists Zengrui Liu, Jimmy Dani, Yinzhi Cao, Shujiang Wu, and Nitesh Saxena published [8]a report titled, "The First Early Evidence of the Use of Browser Fingerprinting for Online Tracking."

[9]

Prior research, the authors claim, has shown that website publishers run fingerprinting scripts, but did not establish whether the scripts are used for privacy-invasive online tracking, or for less controversial reasons like bot detection.

The researchers contend they have established that link, based on their analysis of bids in online ad auctions.

"Our large-scale study reveals strong evidence of browser fingerprinting for ad tracking and targeting, shown by bid value disparities and reduced HTTP records after fingerprinting changes," the paper claims. "We also show fingerprinting can bypass GDPR/CCPA opt-outs, enabling privacy-invasive tracking."

To further complicate matters, some of these same researchers have shown that browser fingerprints can be [10]copied and spoofed . In other words, an attacker might be able to impersonate your browser fingerprint to make it look as if you visited a website you’ve never read.

[11]Australia finds age detection tech has many flaws but will work

[12]Google's unloved plan to fix web permissions gathers support

[13]Microsoft adds export option to Windows Recall in Europe

[14]Mozilla frets about Google's push to build AI into Chrome

Enter Psylo, which Bakry and Mysk describe in a [15]blog post as an attempt to address native app fingerprinting using software development kits, or libraries that developers add to their apps.

Apple, they observe, has tried to make it harder to create fingerprints by introducing privacy measures like App Tracking Transparency in iOS 14, App Store Privacy Nutrition Labels, and Privacy Manifests, along with limitations on using APIs for tracking. Nonetheless, they say, [16]ad tech firms have developed workarounds .

Psylo, as Tommy Mysk explained, isolates browser tabs into silos, where it can apply anti-fingerprinting mechanisms.

The browser-maker also relies on its own Mysk Private Proxy Network to mask the IP address of each silo.

"We designed the system so that the network traffic is always transferred in encrypted channels," said Mysk. "An attacker intercepting Psylo traffic at any point will only see encrypted data. Psylo uses encrypted TLS channels for communication and it blocks plain-text HTTP traffic. We can't read the data that our users send and receive."

The company claims Psylo therefore offers better privacy than a VPN because the virtual networks mask the user's IP address but generally don't alter the data used for fingerprinting. Psylo, for example, will adjust the browser's time zone and browser language to match the geolocation of each proxy, resulting in more entropy that means fingerprints created by gathering data from silos will appear to be different.

The Mysk devs’ post states that some privacy-focused browsers like Brave also [17]implement anti-fingerprinting measures like canvas randomization, but those are [18]more effective on the desktop macOS app due to Apple's iOS restrictions. They claim that they were able to achieve better results on iOS by using a client-side JavaScript solution.

Mysk designed Psylo to minimize the information available to its maker. It doesn't log personally identifiable information or browsing data that the curious could use to identify the user, the company claims, noting that it also doesn't have customer payment information, which is handled by Apple.

There are no user accounts, only randomized identifiers to indicate active subscriptions.

According to Tommy Mysk, the only subscriber data kept is bandwidth usage, which is necessary to prevent abuse.

"We aggregate bandwidth usage based on a randomly generated ID that is created when a subscription is made," Mysk said. "The randomly generated ID is associated with the Apple subscription transaction. Apple doesn't share the identity of users making App Store purchases with developers."

Asked whether Apple could identify users, Mysk said, "Theoretically and given a court order, Apple can figure out the randomly generated ID of the user in question. If we were to hand out the data associated with the randomly generated ID, it would only be the bandwidth usage of that user in the current month, and two months in the past. Older data is automatically deleted.

"We don't associate any identifiable information with the randomly generated ID. We don't store IP addresses at all in every component of our system. We don't store websites visited by our users at all."

Psylo is available for iOS and iPadOS. Mysk, the company, could create an Android version if the iOS/iPadOS version proves popular.

In the US, Psylo costs $9.99 per month or $99 per year. That's the price of privacy. ®

Get our [19]Tech Resources



[1] https://apps.apple.com/us/app/psylo-private-browser-proxy/id6741358035

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aFp3NlU4pQx-mygyLkme-wAAAck&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aFp3NlU4pQx-mygyLkme-wAAAck&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aFp3NlU4pQx-mygyLkme-wAAAck&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aFp3NlU4pQx-mygyLkme-wAAAck&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://panopticlick.eff.org/static/browser-uniqueness.pdf

[7] https://fingerprint.com/

[8] https://dl.acm.org/doi/10.1145/3696410.3714548

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aFp3NlU4pQx-mygyLkme-wAAAck&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://link.springer.com/chapter/10.1007/978-3-031-09234-3_8

[11] https://www.theregister.com/2025/06/20/australia_age_assurance_trial_findings/

[12] https://www.theregister.com/2025/06/18/googles_fix_web_permissions_mozilla/

[13] https://www.theregister.com/2025/06/16/microsoft_snapshot_export_recall/

[14] https://www.theregister.com/2025/06/11/mozilla_worries_googles_browser_ai/

[15] https://mysk.blog/2025/06/17/introducing-psylo/

[16] https://mysk.blog/2024/05/03/apple-required-reason-api/

[17] https://brave.com/privacy-updates/3-fingerprint-randomization/

[18] https://github.com/brave/brave-browser/issues/38580#issuecomment-2141107667

[19] https://whitepapers.theregister.com/



Wait a minute

Pascal Monett

" Theoretically and given a court order, Apple can figure out the randomly generated ID of the user in question. If we were to hand out the data associated with the randomly generated ID, it would only be the bandwidth usage of that user in the current month, and two months in the past. Older data is automatically deleted. "

So I understand that this so-called privacy enhancement won't keep Apple from tracing a user for up to at least three months - because sure you say you delete older data, but why should I believe you ?

I'm supposed to pay $100 (let's not quibble) per year to have my privacy depend on yet another company actually repecting its word ?

Somehow that does not inspire much confidence to me.

Plus, I note that this is only for Apple users. Non-Apple users are apparently not worth the effort.

Re: Wait a minute

FIA

What's the issue?

I'm supposed to pay $100 (let's not quibble) per year to have my privacy depend on yet another company actually repecting its word ?

If privacy is important to you then you're supposed to take whatever steps you feel apropriate.

You also need to understand that companies you deal with will have to comply with the laws in the countries they operate in. Would you prefer a company that claimed (falsely) that everything you did was private, or would you prefer a company that was honest; therefore allowing you to make a well judged choice?

Somehow that does not inspire much confidence to me.

How is this company demonstrating that they're not respecting their word? They seem to be being honest about what their product can do.

Plus, I note that this is only for Apple users. Non-Apple users are apparently not worth the effort.

I'm seeing a market opportunity for you there... ;)

Personally, I'll stick with Apple, I think they're one of the better companies when it comes to my data. (Mainly because I pay them a lot of money; and the reputational damage of this not being true is probably too great for them to risk).

It's also a question of what you actually require.

This is a privacy product, in that it allows you to minimise your PI data leakage whilst still using the internet. However, this is not the same as anonymaty, which is where you're allowed to do something completely unobserved. The software for this tends to be more used by criminals; so maybe if that's what you require look for some less legitimate solutions. (Of course these bring with them their own problems), but if you want a legitimate privacy solution that won't disclose whatever data they do have when the law comes a knocking then I think you're probably out of luck.

tl;dr...

What you're saying is 'I want to pay a small fee to have someone face down the law for me should it be required....'. That's not happening.

Depressing

Ken G

I'm fine with the technical solution and people deserve to get paid for their ingenuity but I find it dispiriting that this is needed to avoid advertising and other tracking.

Re: Depressing

SsiethAnabuki

Eh... any truly novel elements of this that work will make their way into OS browsers, given a little time.

Re: any truly novel elements of this that work...

Mentat74

Will soon be disabled, blocked or circumvented by the ad-slinging bastards...

Re: Depressing

FIA

I doubt it will appear for free.

Essentially 1 VPN per tab is not a cost zero solution.

As with all the other proposals, it's basically just a list of words.
You can deal with that... :-)
-- Larry Wall in <199709032332.QAA21669@wall.org>