Is Private Browsing Really Private?(spreadprivacy.com)
spreadprivacy.com
Is Private Browsing Really Private?
https://spreadprivacy.com/private-browsing-9276d6d16ea4#.vmexmv7rb
58 comments
"I feel going so far as to say it does not stop websites from collecting info on you is maybe a bit too far."
This is not a personal attack. Just have to address this. If you think that you cannot be identified because you use a "private" window in a browser when you were using a logged in browser 30 minutes before from the same IP with the same OS and the same screen size, with the same background apps making the same http requests, you are mistaken. Your entire search history is fingerprinted, associated, shared, and sold. And this is just scratching the surface. As a mild example, Facebook associates IP's with Facebook accounts, then tracks Chromecast requests from those IP addresses to sell that information to media streaming companies. Everything you do, everything you like, everywhere you visit, is one metadata search away. Duck Duck Go cant fix all that, but they can keep no IP correlated search history. And that says alot considering that in todays market that information is worth millions.
This is not a personal attack. Just have to address this. If you think that you cannot be identified because you use a "private" window in a browser when you were using a logged in browser 30 minutes before from the same IP with the same OS and the same screen size, with the same background apps making the same http requests, you are mistaken. Your entire search history is fingerprinted, associated, shared, and sold. And this is just scratching the surface. As a mild example, Facebook associates IP's with Facebook accounts, then tracks Chromecast requests from those IP addresses to sell that information to media streaming companies. Everything you do, everything you like, everywhere you visit, is one metadata search away. Duck Duck Go cant fix all that, but they can keep no IP correlated search history. And that says alot considering that in todays market that information is worth millions.
Do you have a source for "Facebook associates IP's with Facebook accounts, then tracks Chromecast requests from those IP addresses"
That's not really possible for a webpage or mobile app to do (at least not on iOS, anything goes on Android I guess).
That's not really possible for a webpage or mobile app to do (at least not on iOS, anything goes on Android I guess).
I wish I could find the article. I read it about a year ago. It was a pretty lengthy write up on Facebook's offline tracking habits... just disregard until I can prove it!
> Your entire search history is fingerprinted, associated, shared, and sold.
I've often been curious about this. I've heard this sentiment many times, but I've never heard of where/how anyone could actually buy a search history. Surely there must be some accounts of how the other side of the equation works.
Also, how much does it cost? All the facebook/google help pages I've seen focus on ads, where no personal information is shared.
I've often been curious about this. I've heard this sentiment many times, but I've never heard of where/how anyone could actually buy a search history. Surely there must be some accounts of how the other side of the equation works.
Also, how much does it cost? All the facebook/google help pages I've seen focus on ads, where no personal information is shared.
I was not specific enough with that. I should have said something like, when everything that is collected by different companies and agencies is combined, your entire search history is fingerprinted, associated, shared, and sold. Most are not combining. But some are, and they seem to be getting better at it.
I can see my origional point was too broad to be defensible. But I was trying to explicitly talk about fingerprinting when I said...
> unless you sign in while in private browsing or the site is using some sort of user-agent / IP trickery it won't be automatically tied to your accounts
I am aware fingerprinting exists. I have done fingerprinting.
I am also aware that for advertisers fingerprinted data is not as valuable as login keyed data and a lot of places don't bother to do it. Acting on fingerprinted data often triggers the "creepy factor" and actually turns off the consumer from the product. I know several advertisers that will not allow using it for that reason.
I was not saying it can't be done. I didn't imply it did. In fact I believe a study a few years ago showed that fingerprinting is something like 99% accurate if you can execute javascript code to read things like screen resolution.
I was taking objection to assuming it is absolute that it does not prevent tracking and that it is automatically useless.
Does it stop Google? No way. Facebook, doubtful. But does it stop some sites? Absolutely. On many sites it is very effective.
> unless you sign in while in private browsing or the site is using some sort of user-agent / IP trickery it won't be automatically tied to your accounts
I am aware fingerprinting exists. I have done fingerprinting.
I am also aware that for advertisers fingerprinted data is not as valuable as login keyed data and a lot of places don't bother to do it. Acting on fingerprinted data often triggers the "creepy factor" and actually turns off the consumer from the product. I know several advertisers that will not allow using it for that reason.
I was not saying it can't be done. I didn't imply it did. In fact I believe a study a few years ago showed that fingerprinting is something like 99% accurate if you can execute javascript code to read things like screen resolution.
I was taking objection to assuming it is absolute that it does not prevent tracking and that it is automatically useless.
Does it stop Google? No way. Facebook, doubtful. But does it stop some sites? Absolutely. On many sites it is very effective.
Thanks for that perspective. As a web user, I'm aware of fingerprinting techniques but I've been wondering how prevalent the practice actually is.
There are plenty of things a browser can see without being logged in.
Consider checking this page: http://webkay.robinlinus.com/
Private Browsing simply prevents cookies and nothing else, and for the average person we find that is not what's expected from something defined as "private" browsing.
Consider checking this page: http://webkay.robinlinus.com/
Private Browsing simply prevents cookies and nothing else, and for the average person we find that is not what's expected from something defined as "private" browsing.
> Private Browsing simply prevents cookies and nothing else
Not true, at least for Firefox. In Private Browsing mode, Firefox will avoid saving temporary files and other data to disk, keeping everything in RAM instead, which is wiped when Private Browsing mode is exited. This includes history, cookies, and cache data. I believe localStorage behaves differently as well.
Firefox also makes an effort to block tracking scripts/servers in Private Browsing mode, using Disconnect's filter list.
The Private Browsing new tab page explains this all pretty succinctly: https://i.imgur.com/MGp53eP.png
Not true, at least for Firefox. In Private Browsing mode, Firefox will avoid saving temporary files and other data to disk, keeping everything in RAM instead, which is wiped when Private Browsing mode is exited. This includes history, cookies, and cache data. I believe localStorage behaves differently as well.
Firefox also makes an effort to block tracking scripts/servers in Private Browsing mode, using Disconnect's filter list.
The Private Browsing new tab page explains this all pretty succinctly: https://i.imgur.com/MGp53eP.png
You're right there. In this whitepaper we had different questions for each of the browsers to make sure this distinction was noted.
However, users still in general think that private browsing modes do things like prevent their IP address from being seen, or prevent a search engine from recording their searches. So there is still a gap in their expectations.
However, users still in general think that private browsing modes do things like prevent their IP address from being seen, or prevent a search engine from recording their searches. So there is still a gap in their expectations.
> I believe localStorage behaves differently as well.
My recollection is that the browser claims to support localStorage, but attempts to use it fail. I don't know why it couldn't just be backed by non-persistent storage.
My recollection is that the browser claims to support localStorage, but attempts to use it fail. I don't know why it couldn't just be backed by non-persistent storage.
[deleted]
I'm a full stack web developer. I'm well aware of what the HTTP headers and Javascript methods can expose even while in private. I was oversimplifying fingerprinting a bit.
> so obviously this article has marketing lean.
The domain belongs to the DuckDuckGo blog.
The domain belongs to the DuckDuckGo blog.
Yup! I think we were pretty clear about that from the get-go. Giant duck at the top and everything.
It's part of our overall mission to raise the standard of trust online. We're nothing if not transparent on this!
It's part of our overall mission to raise the standard of trust online. We're nothing if not transparent on this!
To be clear, I assumed everyone knew it was DuckDuckGo's blog because of the logo and everything. I didn't see it as safe to assume everyone knows what they do.
For what it's worth I applaud their efforts and their product. I just think this article is biased (and that's OK).
For what it's worth I applaud their efforts and their product. I just think this article is biased (and that's OK).
Not really private, just keeps your local machine clean. Despite TeMPOraL's labeling it "porn mode" my most common use case is if I need to log into my Google account from my wife's laptop I'll use an Incognito mode window in Chrome so that I don't have to log her out of her Google account.
That's the problem we tried to outline in this paper. If you ask the average person what "private" should mean in this context it turns out they believe it is a large set of features providing total protection.
To a tech-savvy audience its more obvious that private browsing modes don't offer that.
This discrepancy is something that people have genuine concerns about and want to see either more features to protect their privacy, or better transparency in naming/explaining/disclaiming these modes.
To a tech-savvy audience its more obvious that private browsing modes don't offer that.
This discrepancy is something that people have genuine concerns about and want to see either more features to protect their privacy, or better transparency in naming/explaining/disclaiming these modes.
I do not see results broken-down by different browsers. I am not sure about FF's privacy mode but Chrome's incognito mode clearly says: "However, you aren’t invisible. Going incognito doesn’t hide your browsing from your employer, your internet service provider, or the websites you visit."
This warning appears on every tab in the incognito mode, so it is pretty visible.
This warning appears on every tab in the incognito mode, so it is pretty visible.
This is a great point. As I've noted a few times, our surveys were conducted with different question sets for every browser that made note of different features and warnings. We also took that into consideration when aggregating the results into one whitepaper.
We wanted the whitepaper to be browser agnostic, this isn't about blaming specific browsers or actions. We wanted to highlight the larger issue that there is a gap in privacy education for a mainstream user and that it is something that members of technical communities can all step up and help with.
As for a special note for the warnings, I would say it is akin to the Terms of Service for websites. Perfectly visible, but never really read and understood.
We wanted the whitepaper to be browser agnostic, this isn't about blaming specific browsers or actions. We wanted to highlight the larger issue that there is a gap in privacy education for a mainstream user and that it is something that members of technical communities can all step up and help with.
As for a special note for the warnings, I would say it is akin to the Terms of Service for websites. Perfectly visible, but never really read and understood.
> If you ask the average person
Did you actually interview her for this paper? Where'd you find her? Can I ask her a few questions when you're done? I have so much I need to know from the average person.
Did you actually interview her for this paper? Where'd you find her? Can I ask her a few questions when you're done? I have so much I need to know from the average person.
Is there a reason you don't use the people switcher? https://support.google.com/chrome/answer/2364824?co=GENIE.Pl...
I don't use it because it requires that I switch back. My wife won't be bothered to deal with learning the people-switcher (there's no reason she should, it's really her laptop in question), so using incognito means that once I close the window, it's clean again. It's a lot easier to remember to close the window than it is to remember to switch back to her account.
The option I finally chose to go with, is to install firefox on her computer as well. Firefox is for me, Chrome is for her. I'm an FF guy anyway. The main UX problem stands, though, it's too easy to be the wrong person.
The option I finally chose to go with, is to install firefox on her computer as well. Firefox is for me, Chrome is for her. I'm an FF guy anyway. The main UX problem stands, though, it's too easy to be the wrong person.
I'm in the same boat, well aware of chrome option to switch accounts, but the simplicity of dual browsers wins when two people use the same login regularly.
Also I get to keep up to date with changes in firefox.
Also I get to keep up to date with changes in firefox.
There's no need to "Switch back" unless... oh my, your wife closes all her browser windows sometimes?!
I see you do UX at Google. Thank you for asking users questions like this (I really hope you were asking sincerely, not rhetorically). Please talk to users more.
Certainly. I don't work on Chrome, but I'm being sincere and I'm curious of the use case. There may be a better solution here.
I use the people switcher on computers I "control". It is convenient to have two accounts which stay logged in to various services. I do not like staying logged in, and might forget to log out of, computers that aren't mine.
Because that leaves your SO in the position of being able, even accidentally, to log in to your account.
Further, I'd guess that even if you absolutely trust your SO not to violate your privacy, you might still reasonably distrust the platform they're working on, and you might not want to expose your account credentials on a platform that you don't directly control.
Further, I'd guess that even if you absolutely trust your SO not to violate your privacy, you might still reasonably distrust the platform they're working on, and you might not want to expose your account credentials on a platform that you don't directly control.
I use people switcher on my laptop to switch between my two google accounts, but on my wife's laptop I see no reason to leave crumbs of my presence behind.
For me its easier to use a different browser. Chrome for her, Edge for me, Firefox for the kids.
Exactly how I manage online personas. Firefox for my normal browsing, IE for accessing my spam accounts and anything I'd prefer not to easily link back to me. Wife uses chrome.
The icons and applications look sufficiently different that there's no confusion about what persona I am in which browser. And I can have all of them up at the same time.
The icons and applications look sufficiently different that there's no confusion about what persona I am in which browser. And I can have all of them up at the same time.
The people switcher is a godsend for web dev work. I have one for my normal work window (email, ticketing, etc), and two for various types of test accounts. It's SO useful to not have to constantly log in and out. Thank you!
Probably relevant: "Google removes secret agent warning from Chrome’s incognito mode" https://src.chromium.org/viewvc/chrome/trunk/src/chrome/app/...
“Pages you view in this tab won’t appear in your browser history
or search history, and they won’t leave other traces, like cookies,
on your device after you close all incognito tabs.
Any files you download or bookmarks you create will be preserved,
however. Going incognito doesn’t affect the behavior of other people,
servers, or software. Be wary of surveillance by secret agents
or people standing behind you.”
The new version is: Pages you view in incognito tabs won’t stick around in your browser’s
history, cookie store, or search history after you’ve closed all of your
incognito tabs. Any files you download or bookmarks you create will be kept.
Going incognito doesn’t affect the behavior of other people, servers, software,
or people standing behind you.I love to know what prompted that change, whether it was due to user feedback, or a management decision, or even just the personal preferences of the individual responsible for rewording the warning.
sigh nobody has a sense of humor anymore.
It's not humor. Secret agents are a real problem.
So are people standing behind you.
Personally I always believed the porn mode browsing gives two benefits:
- sites don't get recorded in browser history
- by not exposing your regular browsing cookies, it significantly reduces the likelihood an "embarrassing" site will somehow end up on your Facebook wall
I hope I'm not wrong about the second one.
- sites don't get recorded in browser history
- by not exposing your regular browsing cookies, it significantly reduces the likelihood an "embarrassing" site will somehow end up on your Facebook wall
I hope I'm not wrong about the second one.
This is correct at least for Firefox.
The new Container Tabs feature works similarly: it splits cookies.
The new Container Tabs feature works similarly: it splits cookies.
I really don't understand why anyone would expect private browsing to be completely anonymous. I suppose they could change the name to something better but seeing as how I only use it to browse khm websites which I don't want in my browsing history and I know other people use it only for the same reason as whell. In any case I suppose that anyone who really needs anonymity is aware what browsers mean by "private browsing". I even have to block Firefoxes tracking protection to browse my favorite "website"
Of course you understand, you know as well as any of us that the average user knows next to nothing about how the Internet, their computer, or their browser works, either physically or conceptually.
It's not unreasonable for a user to take Google or Mozilla or whoever at their word when they call the feature "incognito mode", or "private browsing" etc. They don't know the first thing about how their privacy is breached in the first place, so why would they know how their browser mitigates potential breaches?
It's not unreasonable for a user to take Google or Mozilla or whoever at their word when they call the feature "incognito mode", or "private browsing" etc. They don't know the first thing about how their privacy is breached in the first place, so why would they know how their browser mitigates potential breaches?
The "Most common misconceptions about Private Browsing" part is actually misleading for Firefox users, because that does apply Tracking Protection in private browsing mode. So some of the top misconceptions aren't, at least not if you use Firefox.
(Yes, yes, it can never be perfect, but I don't believe that invalidates the point)
(Yes, yes, it can never be perfect, but I don't believe that invalidates the point)
DuckDuckGo employee here - I ran the survey we used in this.
We had a separate question for users who noted that they used Firefox that spoke to the specific cases for that browser.
The final whitepaper is browser agnostic, and these are the top misconceptions overall, but results were split out in the research phase to account for this.
We had a separate question for users who noted that they used Firefox that spoke to the specific cases for that browser.
The final whitepaper is browser agnostic, and these are the top misconceptions overall, but results were split out in the research phase to account for this.
FF tracking protection helps.
Disabling JS from iffy marketing companies mostly solves the problem. (From a legal standpoint, not a security standpoint). It's illegal under wiretapping rules to share communication with a third party. (but if the user's browser hits a third-party data collection endpoint, that's somehow okay. See 'in re doubleclick'). Firefox tracking protection uses the disconnect.me list https://disconnect.me/trackerprotection/blocked to get rid of all of these it can.
If the adversary isn't a marketing firm that has to comply with the law, ignore the above. Then you're looking at browser flaws (canvas fingerprinting) and session inference (using client IP, URL, browser-agent, & timestamps to reconstruct identity from behavior).
Disabling JS from iffy marketing companies mostly solves the problem. (From a legal standpoint, not a security standpoint). It's illegal under wiretapping rules to share communication with a third party. (but if the user's browser hits a third-party data collection endpoint, that's somehow okay. See 'in re doubleclick'). Firefox tracking protection uses the disconnect.me list https://disconnect.me/trackerprotection/blocked to get rid of all of these it can.
If the adversary isn't a marketing firm that has to comply with the law, ignore the above. Then you're looking at browser flaws (canvas fingerprinting) and session inference (using client IP, URL, browser-agent, & timestamps to reconstruct identity from behavior).
Is it actually a misconception that private browsing prevents search engines from knowing my searches?
I do search for some nasty stuff in private mode and it never pops up in ads for my main account.
I do understand there might be conspiracy in Google to gather that data and link it to my account but never use it in the way I notice, but that looks like conspiracy theory to me.
I do search for some nasty stuff in private mode and it never pops up in ads for my main account.
I do understand there might be conspiracy in Google to gather that data and link it to my account but never use it in the way I notice, but that looks like conspiracy theory to me.
> Is it actually a misconception that private browsing prevents search engines from knowing my searches?
Of course the search engine knows what you searched for! You sent the search string from your computer to one of their servers.
You'd need a way to prevent the search engine from knowing your IP address, like a proxy or Tor, in order to hide your identity.
Of course the search engine knows what you searched for! You sent the search string from your computer to one of their servers.
You'd need a way to prevent the search engine from knowing your IP address, like a proxy or Tor, in order to hide your identity.
Your private mode searches may not be ones that have ads for them, those sites may not use Google's re-marketing offers, the re-marketing may be offered via cookies or if they fall into an 'adult' category then you are going to see them in less locations anyway.
Despite that a search engine is still able to see what you search in private browsing modes as none of it's protection change, hide or obscure your identity.
If you perform a search from your IP address (or any other information that can be fingerprinted from your browser) and then do the same in private browsing mode, Google would know that it is the same user committing both searches.
Despite that a search engine is still able to see what you search in private browsing modes as none of it's protection change, hide or obscure your identity.
If you perform a search from your IP address (or any other information that can be fingerprinted from your browser) and then do the same in private browsing mode, Google would know that it is the same user committing both searches.
Title is a little misleading but a good article.
"Surveys done on users perceptions of private browsing" or at they titled the paper "A Study on Private Browsing: Consumer Usage, Knowledge, and Thoughts"
"Surveys done on users perceptions of private browsing" or at they titled the paper "A Study on Private Browsing: Consumer Usage, Knowledge, and Thoughts"
This all seems likely to be true, but the source being Duck Duck Go calls the results & methodology into question. I'd love to see an independent researcher confirm these findings.
Hey there, DuckDuckGo employee here.
Would love to know why you feel our affiliation calls that into question?
In the the whitepaper we disclose the full methodology, and each statistic has a margin of error calculated and added in. Feel free to review it - we're happy to answer questions!
Would love to know why you feel our affiliation calls that into question?
In the the whitepaper we disclose the full methodology, and each statistic has a margin of error calculated and added in. Feel free to review it - we're happy to answer questions!
I have to confess I didn't see the link to the whitepaper in my first read through - shame on me for commenting before I did :) I think you all did a pretty good job putting this together overall after reading through it, and I applaud the effort. That said, the critical HNer in me sees some bias in the questions and answers. Specifics:
* The results on page 17 jumped out at me the most. There are 4 specific options for negative emotional reactions, and one generic positive option. It's easy to underestimate the powerful effect this has on pushing the responder to a specific answer. Imagine if your answer options were only "content, secure, informed, protected, neutral, misled" and how different your results might be.
* The question for the above, specifically the tone of "[...] does not offer any additional protection [...]" is also a form of leading the responder to an answer. While the statement is mostly true, there's some contention on the point esp. regarding cookies (see the other comments on this thread). Either way, you'd get a more honest answer if you strictly list the things private browsing does, and the things it does not do in a way that's as objective and incontrovertible as possible.
* It would be useful to see the benefits underlying the "correctly identified" category on page 13. I couldn't find those anywhere which was a bit suspicious.
In consulting, I used to survey users on their personal security practices (password strength, adherence to policies, secure disposal, etc.) and gained a huge appreciation for how powerful bias and misinterpretation can be in surveys, and how hard it is to control. But to reiterate, I think this is overall pretty well done and has some really interesting results, esp. the usage data in the first few sections.
* The results on page 17 jumped out at me the most. There are 4 specific options for negative emotional reactions, and one generic positive option. It's easy to underestimate the powerful effect this has on pushing the responder to a specific answer. Imagine if your answer options were only "content, secure, informed, protected, neutral, misled" and how different your results might be.
* The question for the above, specifically the tone of "[...] does not offer any additional protection [...]" is also a form of leading the responder to an answer. While the statement is mostly true, there's some contention on the point esp. regarding cookies (see the other comments on this thread). Either way, you'd get a more honest answer if you strictly list the things private browsing does, and the things it does not do in a way that's as objective and incontrovertible as possible.
* It would be useful to see the benefits underlying the "correctly identified" category on page 13. I couldn't find those anywhere which was a bit suspicious.
In consulting, I used to survey users on their personal security practices (password strength, adherence to policies, secure disposal, etc.) and gained a huge appreciation for how powerful bias and misinterpretation can be in surveys, and how hard it is to control. But to reiterate, I think this is overall pretty well done and has some really interesting results, esp. the usage data in the first few sections.
Great questions and valid points. Every bit of data should be taken with a great of salt as no study is perfect. We've done the best possible to be statistically sound and disclose anything that may bias that.
Initially we started this survey out of our own interest so a few of those decisions are rooted from there.
1) Agreed, however we've already divided out the people who previously learned about private browsing. This leaves us with a cohort of users who have used private browsing, thought it protected them more and learned that it was wrong. It's very unlikely in any case that there would be positive emotions experienced. In our background research before the final survey we were only focusing on if users had a positive or negative experience. In this final major survey we wanted to get a better understanding of what those negative emotions were and so teased it out more.
I agree that a skewed set of options can bias a question but it is case-by-case. Example if I ask "how do you feel when your ice cream falls on the floor?" and the options are "Happy, Joyful, Amazing, Wonderful, Excited, Sad" you'll still likely pick sad.
2) A good point. This question is one that is linguistically challenging. We want to use phrases like "it only does X" to stress limits, but those can be misinterpreted. I agree you may see some shift if you ask the question as a feature list, but I think in the question we're looking at it would still fall well within the margin of error. I'm curious to run some tests on it either way!
3) We didn't release those in the whitepaper as they were broken down by browser since each browser has different feature sets. We wanted to keep this report agnostic of browser. We're not looking to shame anyone, we're trying to support the conversation around the education gap for the average non-technical internet user. They are telling us they want more privacy, and don't feel that it is being provided or explained well enough.
Overall, I really appreciate the feedback - it is more important than ever to question and discuss the things we see online. Hope this sheds some light on why we made the various decisions we did! :)
Initially we started this survey out of our own interest so a few of those decisions are rooted from there.
1) Agreed, however we've already divided out the people who previously learned about private browsing. This leaves us with a cohort of users who have used private browsing, thought it protected them more and learned that it was wrong. It's very unlikely in any case that there would be positive emotions experienced. In our background research before the final survey we were only focusing on if users had a positive or negative experience. In this final major survey we wanted to get a better understanding of what those negative emotions were and so teased it out more.
I agree that a skewed set of options can bias a question but it is case-by-case. Example if I ask "how do you feel when your ice cream falls on the floor?" and the options are "Happy, Joyful, Amazing, Wonderful, Excited, Sad" you'll still likely pick sad.
2) A good point. This question is one that is linguistically challenging. We want to use phrases like "it only does X" to stress limits, but those can be misinterpreted. I agree you may see some shift if you ask the question as a feature list, but I think in the question we're looking at it would still fall well within the margin of error. I'm curious to run some tests on it either way!
3) We didn't release those in the whitepaper as they were broken down by browser since each browser has different feature sets. We wanted to keep this report agnostic of browser. We're not looking to shame anyone, we're trying to support the conversation around the education gap for the average non-technical internet user. They are telling us they want more privacy, and don't feel that it is being provided or explained well enough.
Overall, I really appreciate the feedback - it is more important than ever to question and discuss the things we see online. Hope this sheds some light on why we made the various decisions we did! :)
As an attorney who does digital forensics, it's most certainly not
Can the use of private browsing + a 3rd-party VPN at the same time be considered reasonably private?
Sad that a DDG blog is on medium.com :/
What's wrong with Medium? I used to run my own blog software. I don't recommend it unless you really need to micromanage the implementation. Most people do not. This is why I let Medium handle all the intricacies of publishing my blog so I can just write.
While private browsing is not actually private I feel going so far as to say it does not stop websites from collecting info on you is maybe a bit too far.
The site can still collect information about you, yes. But unless you sign in while in private browsing or the site is using some sort of user-agent / IP trickery it won't be automatically tied to your accounts. None of the cookies or local storage are shared across private/non private browsing.
Personally, I use it mostly to see what websites look like when I'm not logged in or if I want to access something that can only be accessed while logged out without actually logging out which is surprisingly common.