Threat model

A privacy tool that won’t state its limits is asking you to take its word. Here are ours, written before release rather than after the first critique.

What Spurio works against — and what it doesn’t

AdversaryEffect of Spurio
Behavioural ad targetingDegraded. This is the primary target.
Data brokers and profile inferencesDegraded, to the extent their inferences rest on browsing.
Cross-site trackersDegraded — they see real visits that match no real person.
Your internet providerNo useful effect. It still sees your DNS lookups and connections.
Government surveillance, warrants, lawful interceptionNo effect. Do not use it for this.
Browser fingerprintingNo effect. Your fingerprint is unchanged.
Sites you are logged intoNo effect. They identify you by your account, not by inference.
Malware, phishing, password leaksNo effect. This is not an antivirus.
Native mobile appsNo effect. An extension cannot reach them.

Why obfuscation instead of blocking

Blocking takes data away from a tracker. Obfuscation adds data: it costs the other side confidence in what it thinks it knows. A profile that can’t be trusted has no commercial value. It’s the same strategy as TrackMeNot and AdNauseam, and it composes well with a blocker — block what you can, drown the rest.

What we can’t promise

What we ask you to take on trust

As little as possible. The code is public under GPLv3, there is no server to trust, the site list is a file you can read, and reproducible builds will let you confirm the published extension matches the source. When a claim on this page stops being true, it gets corrected here.

Last updated: 18 August 2026.