Key Takeaways
- Built-in browser settings provide a stable, low-maintenance privacy baseline that most users underestimate.
- Extensions offer granular control but introduce their own risks, including data access and supply-chain vulnerabilities.
- The most effective approach combines strong native settings with a small number of well-vetted extensions.
- Extensions require ongoing vetting — an extension that's safe today can be sold or compromised tomorrow.
- Private browsing mode is a browser setting, not a privacy shield — it has real limits.
Option A
Browser Extensions
The customisable, add-on approach to privacy control.
Best for: Users who want targeted, granular control over specific privacy threats like trackers, ads, or scripts.
Option B
Built-In Browser Settings
The native, maintenance-free foundation for everyday privacy.
Best for: Users who want reliable baseline privacy protection without installing third-party software.
If you want reliable privacy protection with minimal upkeep
Built-In Browser Settings
Native settings are maintained by the browser vendor, require no installation, and can't be compromised by a third-party developer. Configuring them once provides lasting protection.
If you need to block specific trackers or ads that native settings miss
Browser Extensions
Well-vetted extensions like content blockers can intercept tracking scripts and ad networks that browsers don't block by default, offering a meaningful additional layer.
If you're concerned about software supply-chain risks
Built-In Browser Settings
Extensions are third-party software with broad permissions. Browser vendors control their own native features, removing one significant attack surface.
If you want both strong baseline and enhanced tracker blocking
Browser Extensions
Start with native settings fully configured, then add one or two reputable, open-source extensions to handle what the browser misses — this layered approach covers the most ground.
What Built-In Browser Settings Actually Do
Most people open their browser's privacy settings once and never return. That's a missed opportunity. Modern browsers — including Chrome, Firefox, Safari, and Edge — have expanded their built-in privacy controls considerably in recent years.
Key native features to review and enable include:
- Enhanced Tracking Protection (Firefox) or Tracking Prevention (Edge): blocks known third-party trackers by default.
- Safe Browsing: warns you before you visit sites flagged for phishing or malware.
- HTTPS-Only Mode: forces encrypted connections wherever available, protecting data in transit.
- Cookie controls: most browsers let you block third-party cookies entirely without an extension.
- DNS-over-HTTPS: encrypts your domain name lookups so your internet provider can't easily log which sites you visit.
These settings operate at the browser engine level — they're integrated, regularly updated by the vendor, and don't require you to trust a third party. See what your browser stores about you to understand the full scope of data worth managing here.
| Criterion | Browser Extensions | Built-In Browser Settings |
|---|---|---|
| Setup required | Install, configure, review permissions | Navigate settings menu, toggle options |
| Ongoing maintenance | Monitor for ownership changes, updates | Minimal — vendor maintains automatically |
| Tracker blocking depth | High — filter lists updated frequently | Moderate — varies by browser |
| Third-party trust required | Yes — extension developer and updater | No — controlled by browser vendor |
| Risk of data exposure | Higher — broad page permissions | Lower — no added software layer |
| Customisation range | High — granular per-site controls | Moderate — global or category-level |
| Best used for | Filling specific gaps in native protection | Establishing a reliable privacy baseline |
Where Extensions Add Genuine Value
Despite strong native controls, there are gaps extensions can legitimately fill. Content-blocking extensions maintain frequently updated filter lists that catch ad networks and trackers faster than browser vendors can integrate them natively. Script-blocking tools let you selectively allow JavaScript only from sites you trust, which meaningfully reduces your attack surface on unfamiliar pages.
Extensions also add capabilities browsers simply don't offer built-in, such as automatically redirecting you to privacy-respecting front-ends for popular services, or flagging sites with poor data practices.
However, every extension you install is software granted significant permissions — often the ability to read and modify content on every page you visit. That's a real trust decision, not a trivial one.
A Note on Extension Permissions
When you install an extension, your browser presents a permissions prompt describing what the extension can access. It's worth reading these carefully — not as a formality, but as a genuine signal of risk. An extension requesting access to all sites you visit has the technical ability to log everything you do in the browser. Reputable tools earn that access for legitimate reasons, but the permission itself is significant.
For context on how much data can be collected passively during everyday browsing, see our article on what private browsing actually hides.
The Real Risks Extensions Carry
Extensions introduce risks that are easy to overlook. Because the browser extension ecosystem is large and lightly moderated, extensions can be:
- Sold to new owners who monetise them through data collection after you've already installed them.
- Compromised via supply-chain attacks, where a developer's account is hijacked and a malicious update is pushed to all users.
- Deceptively named to mimic reputable tools.
Minimising your extension count reduces exposure. Stick to open-source extensions with active maintenance histories and transparent privacy policies. Review the permissions each extension requests — an extension that needs access to all websites to block ads is expected; one that also requests access to your clipboard or microphone is not.
79%
Users concerned about online data use
According to Pew Research Center survey data, roughly 79% of US adults reported being concerned about how companies use their data online.
~280,000
Extensions available in Chrome Web Store
The Chrome Web Store hosts hundreds of thousands of extensions, making independent vetting a practical challenge for everyday users.
Overlooked settings on your devices can compound browser-level risks — it's worth reviewing phone security settings that often go unnoticed alongside your browser audit.
Building a Practical Privacy Stack
The most effective approach isn't choosing one over the other — it's sequencing them correctly. Start with native settings as your foundation, then layer extensions only where there's a clear gap.
- Open your browser's privacy or security settings and enable stricter tracking protection, HTTPS-only mode, and third-party cookie blocking.
- Enable DNS-over-HTTPS if your browser supports it (most do).
- Audit existing extensions: remove anything unused or unrecognised.
- Add one content-blocking extension only if native tracking protection leaves gaps you can verify.
This approach keeps your attack surface small while covering the majority of common privacy concerns. You might also find that other underused browser features complement your setup in practical ways. And if you're thinking about data collection more broadly, our piece on what smart home devices actually collect extends the same thinking to your home network.
