FINDING · EVALUATION

Of the four Chinese browsers offering incognito mode (Baidu Searchbox, UC Browser, QQ Browser, Redmi/Mi), all four continue to leak PII and three continue to transmit full browsing activity including URLs; UC Browser specifically sends data during incognito sessions encrypted with hardcoded AES/CBC key "Ine34@32b#jeRs2h" and a zero initialization vector to crash-upload endpoints. Incognito mode in these browsers provides no protection against vendor-side or on-path surveillance and creates false privacy expectations for circumvention tool users.

From 2025-rodriguez-revisitingRevisiting BAT Browsers: Protecting At-Risk Populations from Surveillance, Censorship, and Targeted Attacks · §4.2 · 2025 · Free and Open Communications on the Internet

Implications

Tags

censors
cn
techniques
dpi
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.