Google Chrome fails the Google incognito test

There’s been a lot of talk about Google’s new Chrome browser. If you haven’t checked it out I’d recommend it from a “neat” factor but it’s less practical then upgrading to Firefox 3.

Chrome is fast and has some great features and one which I was excited about was an ability to go “incognito“. Going incognito will prevent the browser from storing cookies or you browsing history and is supposed to isolate the window as a completely separate “island” of web presence which is then “thrown away” when you close the window.

Google’s example was that when shopping you don’t want your significant other to stumble across your surprise. Although I saw suggestions of *cough* other places you could browse where less repercussions might be welcome. You can recognize this mode by the little White Spy icon from the “spy vs spy” series.

However, the site I most wanted to visit with completely private windows was Gmail! I don’t think I’m rare in having multiple email accounts and the challenge with Google is that they only let you be logged in to one account across all your sessions. While there are techniques which can mitigate this, I end up letting email languish because I don’t want to go through the – log out, log in, log out, and log back in as my primary ID – dance.

So having multiple concurrently active Gmail tabs seemed like an obvious use of incognito mode!

Alas, it’s of course not to be;

First, I created an incognito window and then logged into Gmail. So far so good, however when you open a second tab and log in with a different ID it logs you out of the first tab! That doesn’t seem to “isolated” does it?

My second thought was to create a second incognito window (since Google hasn’t been clear about the level of isolation). I noticed that this option is grayed out in the incognito window. If you go to your original “public” window and select “New incognito window” the options exists but simply opens another tab on the original incognito window (which still fails the “multiple login” test).

Obviously, this lack of true isolation surprises to me. Cookies appear to be shared across tabs and it appears you’re forced into having only one private window at time! This would be awful if you were browsing multiple sites looking for a great shopping deal, but didn’t want them to know about other sites or if you were a web tester trying to isolate cookies from test runs.

Chrome’s a work in progress and Google’s opensourceed the project, so I can only hope someone will address these concerns. However, in the meantime it pays to test your expectations and if Google really wants to make webapps more like desktop apps I think this needs to be addressed.

About jay

I'm trying to build something interactive where I can learn from others and hopefully share useful knowledge too. thecapacity@gmail.com
This entry was posted in frustration, Google, security. Bookmark the permalink.

7 Responses to Google Chrome fails the Google incognito test

  1. Please let me know if you’re looking for a article writer for your site. You have some really good posts and I think I would be a good asset. If you ever want to take some of the load off, I’d love to write some articles for your blog in exchange for a link back to mine. Please blast me an e-mail if interested. Regards!

  2. Donte Goza says:

    Thanks for an interesting article. After looking through different websites I finally found something worth reading.

  3. Pingback: thecapacity : Google’s Unspoken Security Vulnerability

  4. a says:

    um it might be that Google doesn’t allow 1 IP address to open 2 accounts. If you were looking at two different websites it wont be an issue.

    • jay says:

      A
      You may be right but I know that you can have two accounts open if one is gmail and the other is a “domain app” account (it appears to be a cookie path thing) so I don’t believe it’s IP limited (which probably wouldn’t work well for corporations behind firewalls either).

  5. J W says:

    You can open a brand new incognito window by dragging a New Tab from incognito mode off the tab bar. I do believe this would let you be logged in two times at once, as well.

    • jay says:

      Thanks JW I’ll have to check this out. I think the greying of the UI box is unintuitive (though obviously not critical) but Chrome should definitely be more specific about the layer of “protection” between tabs and windows.

Comments are closed.