Safari (macOS)

Website

Short description

Safari brings powerful privacy protections, per-site Lockdown Mode, and optimizes battery life.

Why I think this tool should be added

Nothing beats Safari on macOS when it comes to private browsing and fingerprinting protection, especially when combined with iCloud Private Relay and Lockdown Mode.

For fingerprinting protection to be effective, it helps to have a large pool of users with similar browser configurations. According to Cloudflare’s Browser Market Share report for Q4 2025, this is the market share of macOS browsers:

Google Chrome: 60%
Safari: 33%
Firefox: 4.1%
Brave: 1.3%

Google Chrome does have a larger market share, but it does not offer the same level of privacy and fingerprinting protection as Safari. Safari offers protections such as:

  • Advanced fingerprinting protection in normal browsing, enabled by default.

  • Safari aggressively limits persistent first party tracking storage.

  • Safari deliberately exposes fewer hardware fingerprinting surfaces.

  • Safari has aggressive tracker and network handling in Private Browsing.

Blockers:

Must be open-source software.

I think this criterion could be moved to Best-Case.

Safari provides significantly more than its competitors when it comes to privacy and fingerprinting, just as 1Password allegedly provides superior UI/UX compared to its competitors, which allowed it to be the only proprietary password manager recommendation.

Section on Privacy Guides

Desktop Browsers

Very true. It’s a pity that there’s no JITless WASM and fine-grained control of Safari lockdown mode (only on/off). And updates are much slower than Chrome.

Actually Tor browser offers the best anti-fingerprinting protection…

Tor Browser has a smaller crowd to blend in with and is less secure than WebKit and Chromium, which is amplified by the fact that Tor Browser users are specifically targeted.

If you want anonymity, then yes, Tor Browser is the best option. But for regular private browsing, Safari wins here.

I feel like I compared safari vs brave, both out of the box, on macOS and Brave was better, though I was very surprised and impressed with Safari. I used creep.js

Test Sites

To reiterate from above

  • Not only is what is tested, how it’s tested, and how robust it’s tested important for quality … but also how it’s collected and how much is collected is also critical
  • In testing there are two dataset outcomes that are useful: buckets (values) and entropy (uniformity).

Test sites are an example of what NOT to use.

BUCKETS (values)

  • tests are not robust: therefore they do not show potential leaks or entropy
  • tests are not comprehensive; i.e not measuring enough metrics
  • tests may have bugs: e.g not stable, not reproducible, not accurate
  • tests are not universal between sites (so you can’t compare)

For example, one site may report canvas as randomized, another site will report a hash (and claim it’s unique). Who do you believe? What did they test (offscreenCanvas, toDataURL, and a hundred other parameters)?

Not sure what you are trying to imply by copying parts of the article, but test sites are still useful if you know how to correctly interpret what they can actually provide. You can pretty much discard anything related to how often some fingerprint/value has been seen by them, or what % of users share this specific setup. They are still useful when you are testing the actual protection itself.

I think this is a reasonable suggestion and use Safari quite a lot myself for casual browsing. I think it is a good choice for most people on MacOS for all the reasons listed by the OP.

However there is a difference between a decent choice and being actively recommended by PG. Along those lines I have a few reasons to push back on this being added to the site.

  1. Brave already meets the criteria as is and with minor configuration changes is as or better than Safari on privacy/security. The only “win” for Safari is the usability improvement in lockdown mode of per site restrictions.

  2. Private Relay should not be used as part of the recommendation. It is a paid add on and not available without an iCloud paid subscription. Additionally it has its own serious flaws that are yet to be patched (leaking IP via WebAuth, DNS).

  3. Safari is not open source and while I understand that isn’t a universal PG show stopper, I don’t see why that can of worms should be reopened over this.

As a heavy Safari user, I don’t believe it should be added.

  • From a privacy perspective, Mullvad Browser or configured Firefox is superior.
  • From a security perspective, the Chromium engine is better.

It is my understanding that PG generally focuses on suggestions for “extreme privacy”. Safari is certainly better than Google Chrome but there are also more private options.

Now if PG opened its focus a bit and began to add middle-of-the-road recommendations (with a big warning) for people that don’t want to go all the way, Safari would be great. But that’s another topic.

That being said, I run Safari in private browsing at all times. In fact, the very first option in Settings is to open a private window by default or whether private windows should be restored on startup. The tab-level isolation is an excellent feature. Additionally, I run a content blocker with some pretty extreme lists. Javascript extensions are used sparingly and only on specific sites. They are too easy to hijack to let run on every page. On desktop I use Little Snitch to block local connections. I use a separate browser to access LAN stuff.

Mullvad Browser is also better when paired with the paid Mullvad VPN. And iCloud Private Relay has a better architecture than any of the VPN providers we recommend on PG, with ODoH and MASQUE, etc. The number of flaws doesn’t break its overall security model. The only issue is that Apple patches everything too late.

Safari is better, Apple devices have more consistent fingerprint and more users.

Care to explain how Brave is better than Safari for privacy?

The win here is that Safari has a large pool of users to blend in with, combined with strong fingerprinting protections out of the box. Most users will pretty much only need to change two things: change the default search engine and disable Privacy Preserving Ad Measurement.

Then PG should decide whether open source is something that is valued or not. Either require open source and acknowledge that it’s important, or don’t require it and focus only on technicalities, not the license.

Safari has Google by default and only has one privacyguides recommended search engine available. It also has “privacy preserving” ad measurement on by default.

Firefox and Brave have a bunch of nonsense you need to disable by default, too. Firefox also uses Google as the default search engine.

One underrated selling point over Chromium is how macOS handles Safari web apps.

When you use “Add to Dock,” the web app gets its own sandboxed data container. Safari copies your existing cookies when you create it so you stay logged in, but from then on its cookies, local storage, IndexedDB, cache, and session are separate from Safari.

So you get the convenience of a standalone app without sharing one big browser data store, while still keeping things like Keychain autofill and Safari integration.

I used creep.js on Brave and Safari out of the box on MacOS. I was using Mullvad VPN. I put the results both into Claude Opus 5 for comparison and the summary of the results were as follows (directly copied output):



The verdict

Brave, because per-site randomization means there’s no stable identifier to accumulate, and that beats Safari’s honest-but-consistent fingerprint. Safari’s approach only works if your configuration is common enough to blend into the herd, and 18 enumerable fonts plus an exact disk quota argue it isn’t.

Two things neither fixed: both leaked [LOCATION] and both surfaced the same public IP through STUN. Local IPs were mDNS-obfuscated in both, so that part is fine — but timezone plus IP is often enough to narrow you down regardless of what the canvas says.



I encourage you to run the test on both browsers yourself using any fingerprinter and see what you find. From my testing, Mullvad Browser with Mullvad VPN is the strongest I have tested, apart from the Tor Browser of course.

The AI seems to have hallucinated quite a bit. I would avoid asking AI for this stuff, we have a helpful forum here just for that.

Safari also randomizes your fingerprint per website as well as trying to make Safari users look as similar as possible, so it’s using both strategies just like Brave and Tor browser and Firefox.

Safari is the second most used browser in the world and it only runs on Apple devices, so there’s a very limited set of possible hardware configurations compared to any other browser. Safari also restricts fonts to the ones that come pre-installed with the OS, so font fingerprinting is non-existent.

For the disk quota thing, that’s to do with the Storage API and navigator.storage.estimate(). When I tested it it gave me very small amounts like 7 Gb, the Mozilla page says it can vary based on some things like whether a site is bookmarked, how often you visit etc so I don’t think it’s really something to be very concerned about, it seems like they put measures in place to stop every random website from seeing how much storage space you actually have.

Location is protected behind a permission so I’m not sure what they’re getting at unless it’s the timezone? When I tested for WebRTC leaks, it gave me two different Private Relay IPs, not sure what the situation is with a standard VPN though. If you want to be safe you can turn on Lockdown Mode which I believe disables WebRTC.

I’m also interested in how Safari’s anti-fingerprinting behavior compares with the open-source browsers already listed, especially when Lockdown Mode and Private Relay are enabled. The large macOS user base makes the fingerprinting discussion more nuanced than a simple open-source versus proprietary comparison.

Out of the box, Brave provides built in ad blocking. Safari does not.

Safari has Intelligent Tracking Prevention and blocker behind Privacy Report