RAJA89 home RAJA89 official siteOfficial site (opens in a new tab)
Guide 2 of 4 - Settings

Hardening Your Browser and Devices: A RAJA89 Guide

Every mainstream browser now offers tracking protection, and almost nobody knows which tier theirs is on. The difference between the default and the strictest setting is often the difference between blocking known advertising domains and blocking cross-site tracking outright.

This guide covers the settings that change what is collected, the ones that only change what you see, why partitioning beats blocking, how to audit extension permissions, and what a VPN does and does not do for you.

Last reviewed 8 October 2026Free to read, no sign-upPart of the RAJA89 guides

Visit the official RAJA89 website (opens in a new tab)Opens the official RAJA89 website in a new tab.

Tracking Protection Tiers: What Each Setting Blocks

Every mainstream browser now offers some form of tracking protection, and almost nobody knows which tier theirs is on. That is the first thing to fix, because the difference between "standard" and "strict" is often the difference between blocking known advertising domains and blocking cross-site tracking outright.

The settings live in roughly the same place everywhere: Privacy and security in Chrome, Privacy and Security then Enhanced Tracking Protection in Firefox, Privacy in Safari, and Privacy, search and services in Edge. Each browser also offers a per-site override, which is the part people miss: when a strict setting breaks a login or a payment page, the answer is to disable protection for that one site temporarily, not to weaken the global setting.

ApproachWhat it stopsWhat it does not stop
Standard or balanced tracking protectionKnown advertising and analytics domains from listsCross-site identifiers from domains not yet on a list; first-party profiling; server-side events
Strict protectionThird-party trackers, many third-party cookies and referrers, some fingerprinting surfacesFingerprinting in general; anything first-party; server-side matching
Cookie partitioning (Firefox Total Cookie Protection, Chrome CHIPS)Joining your identity across sites using a third-party cookieProfiling within one site; fingerprinting; login-based linking
A content-blocking extensionRequests to blocklisted hosts, including scripts and pixelsRequests the browser makes itself; first-party endpoints; server-side transfers
Encrypted DNS with a filtering resolverSeeing and rewriting your DNS queries; some tracker domainsEverything above the DNS layer, including the content of your traffic

The honest summary: these layers reduce collection and make cross-site linking harder. None of them makes profiling impossible, and the mechanism that most reliably defeats all of them - a server-to-server event keyed on your hashed email address - never touches your browser at all. See how online tracking works for that.

Why Partitioning Helps More Than Blocking

Blocking third-party cookies outright can break embedded content: a comment widget loses your session, a payment iframe forgets your cart, a video player refuses to start. Partitioning is the compromise that keeps sites working while removing the tracking value.

Instead of one identifier shared across every site that embeds the same network, partitioning gives each top-level site its own cookie jar for that embed. The widget still remembers you while you are on site A. When the same widget loads on site B, it receives a different jar, so it cannot tell that both visits came from the same browser. The state is preserved; the join is severed.

Firefox calls this Total Cookie Protection and has it on by default. Chrome's version, CHIPS, is opt-in for developers and applies to cookies explicitly marked as partitioned. Safari took a different route: it blocks third-party cookies and additionally restricts script-set first-party cookies to a short lifetime, on the theory that any cookie a script writes is more likely to be for tracking than for function.

What partitioning cannot do is stop a company that also sees you first-party. If you are signed into an advertising platform's own services, that account is a first-party identity, and partitioning has nothing to separate.

Content Blocking and Extension Hygiene

A content blocker is the single most effective browser-level change available, and also the most common way people accidentally hand a stranger everything they do.

Choosing one

The permission problem

Extensions run with the permissions they request, and most request the maximum. An extension that can "read and change all your data on all websites" can read your bank balance, your email and your session cookies, because it runs inside the pages where those exist. Anyone who can publish an update to it can change what it does with that access, and updates arrive automatically.

Practical rules that follow from that:

  1. Look at the list before you add anything. Most people are carrying five extensions from experiments they do not remember.
  2. Re-read permissions after major updates. A blocker that adds "read your browsing history" is not the same product it was.
  3. Set site access to on-click where the extension allows it. It then acts only when you invoke it, which is usually enough and removes its standing access to every page.
  4. Prefer one broad blocker to five narrow ones. Fewer extensions means less attack surface, fewer permissions and a less distinctive fingerprint.
  5. Remove what you do not use. An installed extension you have forgotten is still running, still updating, and still holding its permissions.

Encrypted DNS and HTTPS-Only Mode

Two settings reduce what the network between you and the site can see, and they are worth having even though neither is a privacy solution on its own.

DNS over HTTPS

Every visit begins with a DNS lookup: converting example.com into an IP address. Sent in the clear over older protocols, that query is visible to your internet provider, your employer and anyone on the same network, and it is a surprisingly complete record of where you go, because it happens for every domain you contact, including the ones embedded in pages.

DNS over HTTPS (DoH) wraps that lookup inside an encrypted HTTPS connection to a resolver you choose, so the local network cannot read or rewrite it. Browsers support it directly - in Firefox under Privacy and Security, in Chrome and Edge under Privacy and security, then Security. You can also set it at the router, which covers every device in the house including televisions and consoles that have no setting of their own.

The trade is straightforward and worth stating: your local network stops seeing your queries, and the resolver you pick sees all of them instead. Choosing a resolver with a published, audited no-logging policy moves trust rather than eliminating it. A resolver that also filters known tracker and malware domains adds a second benefit, and is what most people want in practice.

HTTPS-only mode

An unencrypted HTTP request can be read and modified in transit. HTTPS-only mode makes the browser attempt the secure version of every address and refuse to fall back silently. It is a switch in most browsers, sometimes under Privacy and security. Expect some breakage on legacy sites and captive portals; the per-site exception exists for that reason, and a captive portal is not a reason to turn the setting off globally.

Neither setting hides your IP address from the sites you visit, and neither changes what those sites do with your data once it arrives. They address the network layer only.

Profiles and Containers Beat Clearing Data

"Clear cookies" is the most common privacy habit and one of the least effective. It logs you out of everything, changes your fingerprint for the worse by making your storage state unusual, and the profile held by the company that already recognised you is not deleted - only your local copy is.

Better: keep your browsing separated so that unrelated activity never shares a cookie jar in the first place.

The benefit is not anonymity; it is containment. Data accumulated in one profile cannot be joined to the data in another, which is precisely the join that identity graphs depend on.

Phone Settings Worth Changing

A phone is a sensor platform with a payment method attached. These are the changes that make a measurable difference, roughly in order of value.

Turn off tracking requestsOn iOS: Settings, Privacy and Security, Tracking, and switch off "Allow Apps to Request to Track". This is stronger than declining prompts one by one, and apps that relied on the prompt lose the identifier entirely. On Android, delete the advertising ID under Settings, Privacy, Ads - the path varies by manufacturer - after which apps requesting it receive zeros.
Review location per appSet everything that is not navigation, transport, delivery or fitness to Approximate or While Using. Section by section, not app by app - see app permissions and data minimisation.
Limit photo accessPhoto libraries carry EXIF data: capture time, and often precise GPS coordinates. Grant selected-photos access rather than the full library, or use apps built on the system photo picker, which needs no permission at all.
Set an auto-delete window on account activityIf you hold a major platform account, its activity controls let you auto-delete web, app, location and YouTube history after three or eighteen months instead of keeping it indefinitely. This matters more than ad personalisation, because it changes what exists rather than what is shown.
Turn off ad personalisation separatelyWorth doing, and much weaker than people expect. It changes which ad you see, not whether your activity is collected or how long it is kept.
Lock the device properlyA six-digit or alphanumeric passcode, a short auto-lock, and biometrics with a strong passcode fallback. Everything else on the device is only as private as that one control.
Audit sign-in sessionsMost platform accounts list every device currently signed in, with location and last activity. Reviewing that list catches the case that matters: an account opened somewhere you have never been.

What none of this changes: an app that already has your email address, a service you signed into, and data already collected and shared before you changed the setting. Revoking a permission stops future collection; it is not retroactive. The limitation is real and worth understanding before concluding that the settings did not work.

VPNs, Honestly

A virtual private network encrypts your traffic between your device and the VPN provider's server, and makes that server's IP address the one the sites you visit see. That is what it does. Almost everything else in the marketing is aspiration.

What a VPN is genuinely good for

What a VPN does not do

The reasonable posture: use a paid VPN with a published, independently audited no-logs policy when you are on a network you do not control, or when you specifically want your address hidden from a site. Do not use one as a substitute for the settings in this guide, and do not assume that paying for a VPN makes you unidentifiable.

Questions readers ask about this page

What is the most effective browser privacy setting I can change today?

Move tracking protection to its strictest tier and install one reputable content blocker. Those two changes stop the largest volume of cross-site requests. After that, set an encrypted DNS resolver with filtering, turn on HTTPS-only mode, and keep separate browser profiles for accounts, shopping and general reading so unrelated activity never shares a cookie jar.

Will strict tracking protection break websites?

Occasionally, and usually a login, a payment iframe or a video player. The answer is the per-site exception: disable protection for that one domain while you need it, then turn it back on. Weakening the global setting because one site misbehaves is the common mistake.

Do I need a VPN?

Not for everyday browsing on your own network. A paid VPN with a published no-logs policy is genuinely useful on untrusted Wi-Fi, or when you want a site to see a different IP address. It does not stop cookies, fingerprinting, or the platform you are signed into from recognising you, and a free VPN simply moves your data to a different company.

Does clearing cookies protect my privacy?

Less than people think, and it has costs. It logs you out everywhere, makes your browser state more distinctive, and does not delete the profile the company already built. Separating your browsing into profiles or containers prevents the join from happening in the first place, which is the more durable fix.

Is a private or incognito window useful at all?

Yes, as local cleanup. It keeps the session's cookies and history off your device, logs you out of your existing accounts, and in Chrome blocks third-party cookies that ordinary windows allow. It does not hide your activity from your network, your internet provider, or the sites you visit, and it does not change your fingerprint.

Back to top ↑

Sources checked for this page

About RAJA89

RAJA89 is an independent educational project written by one person. It is not a company, an agency or a managed editorial team, and it does not pretend to be one. Edi Rahmadani writes these pages, checks them against the primary sources cited on each one, and answers corrections sent to the address on the support page.

RAJA89 is the name the site publishes under; the name above is the person accountable for what it says. Nothing here is generated and published unread: a claim either traces to a source you can open yourself, or it is marked as the author's own judgement.

How this site is funded

It is not. There is no advertising, no sponsorship, no affiliate link, no paid placement and no product for sale anywhere on this site. No company pays to be mentioned, and no page carries a commission-bearing link. Hosting is paid for out of the author's own pocket, which is the whole of the commercial relationship. If that ever changes, the change will be disclosed on this page before it appears anywhere else.

How to read this site

Editorial standards we hold ourselves to

Dates, and what they mean

The date below is the last time these pages were re-checked against the sources they cite. It is a record of what happened, not a schedule: no page here states a calendar interval for review, because a static site cannot enforce one. Pages are re-checked when something they describe actually changes — a vendor renames a setting, a standard is revised, a regulation is amended, a link breaks — and at least once a year regardless, so that nothing is left unexamined through neglect.

The date moves only when a person has re-opened the cited sources and confirmed the text still matches them. It is not the date a file was last saved. Where a passage has been left standing but is no longer certain, it is marked as uncertain rather than quietly carried forward.

If the date below looks old, that is information, not a fault. It means the pages are due for their next pass. Everything on them links its primary source precisely so you can check the current position yourself rather than relying on our copy of it.

Who is accountable for this page

Published byRAJA89, an independent educational project written and paid for by Edi Rahmadani
Written byEdi Rahmadani — an independent writer, publishing under the RAJA89 name. No employer, qualification or years of experience is claimed here, because this site asserts only what can be checked.
Reviewed byEdi Rahmadani. This site has no separate reviewer, and we do not name one to look better. Every page is self-reviewed against the sources it cites, and that is exactly what the review record below means.
CorrectionsSend a correction — specific reports are checked against a primary source and fixed or answered
First published2026-10-08
Last reviewed2026-10-08 — every page on this site carries the same review date, and each one links the sources it was checked against

Contact

Corrections, factual disputes, reports of a link that now leads somewhere harmful, and notices that a described setting has moved are all welcome at the address below. Edi Rahmadani reads them.

raja89officials@gmail.com

One person, checking messages between other work. Reports that name the passage and the source they disagree with are answered fastest — the support page sets out exactly what to include, and what we cannot help with.

We will never ask you for a password, a one-time code, a recovery code or remote access to your device, and we will never ask you to confirm account details by replying to a message. Any message claiming to come from this site and asking for any of that is not from us.

Scope and limitations

Read this before acting on anything here.

Back to top ↑