Threat model
A privacy tool that won’t state its limits is asking you to take its word. Here are ours, written before release rather than after the first critique.
What Spurio works against — and what it doesn’t
| Adversary | Effect of Spurio |
|---|---|
| Behavioural ad targeting | Degraded. This is the primary target. |
| Data brokers and profile inferences | Degraded, to the extent their inferences rest on browsing. |
| Cross-site trackers | Degraded — they see real visits that match no real person. |
| Your internet provider | No useful effect. It still sees your DNS lookups and connections. |
| Government surveillance, warrants, lawful interception | No effect. Do not use it for this. |
| Browser fingerprinting | No effect. Your fingerprint is unchanged. |
| Sites you are logged into | No effect. They identify you by your account, not by inference. |
| Malware, phishing, password leaks | No effect. This is not an antivirus. |
| Native mobile apps | No effect. An extension cannot reach them. |
Why obfuscation instead of blocking
Blocking takes data away from a tracker. Obfuscation adds data: it costs the other side confidence in what it thinks it knows. A profile that can’t be trusted has no commercial value. It’s the same strategy as TrackMeNot and AdNauseam, and it composes well with a blocker — block what you can, drown the rest.
What we can’t promise
- Effectiveness isn’t guaranteed and isn’t fixed. Ad platforms can learn to filter a noise pattern. This is a race, not a settled win.
- We will measure it, and publish the result. The roadmap includes a before/after test against a real ad-preferences profile. If it shows nothing, we’ll say so here.
- Decoy searches land in your real history. That is exactly why the topic list contains nothing political, medical, legal or financially sensitive — planting an awkward trace would invert the point of the tool.
- No illegal, adult or incriminating targets, ever. The exclusions live in the repo and are enforced.
- A visited site sees real traffic from your browser and your IP, as though you had opened it — because you did.
What we ask you to take on trust
As little as possible. The code is public under GPLv3, there is no server to trust, the site list is a file you can read, and reproducible builds will let you confirm the published extension matches the source. When a claim on this page stops being true, it gets corrected here.
Last updated: 18 August 2026.