Skip to main content
Field notes49 articles

Blog.

Browser isolation, AI security, and privacy engineering. No fluff.

Add Legba as a preferred source

Browser isolation for law firms

Browser isolation changes where law-firm pages run. It does not decide privilege. Review credentials, files, provider access, and ethics questions.

Security Research8 min read

Browser isolation for tax and accounting firms

Browser isolation changes where tax-firm pages run. Review WISP fit, client-data flows, providers, and remaining controls.

Security Research5 min read

Six disposable browsers compared in 2026

Six disposable browsers compared by session destruction, operating model, setup requirements, and workflow fit. See the documented fit and tradeoffs for each.

Security Research13 min read

Disposable browser vs anti-detect browser: pick by problem

Anti-detect browsers maintain saved profiles. Disposable browsers optimize for temporary sessions. Compare identity count, persistence, and the right fit.

Security Research12 min read

Throwaway, burner, temporary browser: defined

Throwaway, burner, and temporary browsers serve different privacy jobs. Each label carries a distinct risk. See what delivers the clean exit you need.

Privacy Engineering11 min read

Indirect prompt injection targets browser agents

A browser agent can follow hostile instructions hidden in content. Learn how to constrain browser execution, tools, and approvals.

Security Research13 min read

MCP server security: the config nobody reads

MCP servers make agent tools easy to add and hard to audit. Learn how config files, broad scopes, and browser sessions turn integrations into trust decisions.

Security Research12 min read

Browser isolation for AI agents: why the old playbook fits the new problem

Browser isolation kept hostile pages away from human endpoints. AI agents need the same boundary around execution, identity, and session lifetime.

Security Research12 min read

The EU AI Act gets teeth. What browser-agent teams need

A practical engineering reading of the EU AI Act’s August 2, 2026 enforcement milestone for browser-agent teams: data limits, logs, and teardown proof.

Security Research11 min read

Device Code Phishing: Why Your SOC Can't See the Attack Until It's Too Late

Device code phishing kits encrypt payloads, so static URL analysis sees only ciphertext. Isolated browser execution reveals the hidden attack.

Security Research13 min read

What is browser isolation? The complete 2026 guide

Browser isolation separates web execution from a local device. This guide covers architectures, risk reduction, tradeoffs, and verification.

Security Research7 min read

What is a disposable browser? Uses and limits

A disposable browser uses a temporary session. Learn what session cleanup changes, what can persist, and how it differs from incognito mode.

Security Research3 min read

What is browser fingerprinting? How tracking persists

Browser fingerprinting combines your screen, GPU, fonts, and timezone into an identifier that tracks you across sessions, including incognito.

Security Research8 min read

What is shadow AI? Why the browser tab matters

Shadow AI is unauthorized workplace use of AI tools. See the risks, governance gaps, and where browser isolation changes one boundary.

Security Research8 min read

Legba vs SquareX after the Zscaler acquisition

SquareX is now part of Zscaler. Compare that current buyer path with Legba's independent Chrome extension and published price.

Security Research2 min read

SquareX to Legba: a step-by-step migration guide

Move from SquareX to Legba with a job-by-job plan. Map private browser routing to Ghost, off-device isolation to Shield, and review unmatched controls.

Privacy Engineering5 min read

SquareX is now part of Zscaler. Where Legba fits

Zscaler acquired SquareX in February 2026. Compare the Zscaler path with Legba's Chrome extension. See differences in buyer, deployment, and price.

Security Research3 min read

Browser Isolation vs Incognito Mode vs Private Browsing: What's Actually Private?

Incognito clears local history. Remote browser isolation changes where page code runs. Compare their distinct scopes and limits.

Security Research8 min read

VPN vs proxy vs browser isolation: How to choose

VPNs route device traffic. Proxies route selected app traffic. Browser isolation changes where web content runs. Compare scope, encryption, and fit.

Security Research8 min read

Your ISP Can See Every Site You Visit. Your State Can Subpoena That.

Since 2017, U.S. ISPs can collect and sell browsing data. Compare what an ISP can observe through a direct connection, VPN, and private browser route.

Privacy Engineering7 min read

You Paid for the Stream and Still Hit a Blackout Screen. That's the Scam.

Sports blackouts and fragmented rights still leave paying fans without a game. See why the model fails in 2026 and what to check next.

Privacy Engineering7 min read

Why is the Cardinals game blacked out? 2026 guide

A Cardinals game can be blocked by the wrong package, a national exclusive, travel, or MLB's location check. Follow the official 2026 path.

Privacy Engineering6 min read

The Show Exists. You're Paying for Netflix. You Just Can't Watch It Because You're in the Wrong State.

Netflix, BBC iPlayer, Disney+, and other streaming platforms hide content behind invisible borders. You pay full price. You get a partial library. Here's why.

Privacy Engineering6 min read

Software Companies Charge Different Prices by Country. Same Product. Different Bill.

Regional software prices vary by plan, tax, promotion, and checkout rules. Use this guide to compare equivalent offers without false savings.

Privacy Engineering5 min read

How to Run OpenClaw Safely Without Giving an AI Agent Your Laptop

OpenClaw permissions define its real blast radius. Review tools, files, credentials, browser data, network access, logs, and retention.

Security Research4 min read

Why privacy in crypto wallets matters in 2026

A crypto wallet touches public ledgers, RPC providers, browser surfaces, and identity checkpoints. Learn what each layer can reveal and how to assess privacy claims.

Privacy Engineering4 min read

The Web3 wallet privacy myth, explained

A Web3 wallet can be self-custodial and still expose public activity, RPC queries, and browser metadata. Learn which privacy claims each feature actually supports.

Privacy Engineering4 min read

Your Encrypted AI Conversations Aren't as Private as You Think: Inside the Whisper Leak Attack

Microsoft researchers reveal Whisper Leak, a side-channel attack identifying AI chatbot conversations despite encryption. See what routing and isolation change.

Security Research15 min read

The 60% small-business cyberattack claim needs context

The claim that 60% of small businesses close after a cyberattack lacks a reliable universal basis. Build continuity around tested recovery and layered controls.

Security Research3 min read

Your Data Is Already Out There: Why Even Security Experts Aren't Safe

24 billion credentials on the dark web. Learn how exposure happens and where isolated page execution changes the risk.

Security Research9 min read

The cookie conspiracy: how websites track you and what isolation changes

The truth about cookie tracking, price discrimination myths, and how isolated browser state changes cross-session tracking.

Privacy Engineering20 min read

How Legba browser isolation works

Shield runs the page in an isolated browser. That browser is off your device. See what happens when you open the tab. See what ends when you close it.

Security Research4 min read

What is remote browser isolation (RBI)?

Remote browser isolation runs websites away from your device. Your browser receives rendered output. See RBI delivery models, benefits, and limits.

Security Research12 min read

Browser isolation vs VPN: which tool fits in 2026?

VPNs protect a network path. Browser isolation changes where web content runs. Compare their scope, limits, and best uses.

Security Research8 min read

4 browser isolation and security options for Chrome in 2026

Compare four browser isolation and security options that work with Chrome by model, buying path, and fit.

Security Research6 min read

Arizona Wants Your ID Before You Can Use the Internet. Legba Doesn't.

Arizona's HB 2112 requires age verification for adult sites. That means giving websites your government ID. See how browser isolation protects your browsing.

Privacy Engineering10 min read

The VPN Ban Is Coming: Here's What You Stand to Lose

1.8 billion people rely on VPNs daily. Now governments want them gone. Here's what that means for your streaming, travel, privacy, and freedom.

Privacy Engineering12 min read

Stop Using Incognito Mode for Security. It Doesn't Work.

Incognito mode doesn't protect you from malware, phishing, or tracking. Here's what it actually does and what you need instead for real browser security.

Security Research12 min read

Exposed Secrets in the AI Era: .env Files, Hardcoded Keys, and the Breaches That Follow

How secrets leak through committed .env files, statically served config, and frontend bundles, and the real breaches that followed when attackers found them first.

Security Research13 min read

External Attack Surface Management (EASM) in 2026: The Complete Methodology

The pillar guide to EASM in 2026: the discover, enrich, validate, prioritize, report lifecycle, and why validation, not discovery, is the hard part.

Security Research13 min read

Subdomain Takeover and Dangling DNS: A Field Guide to the Forgotten-Asset Problem

How dangling CNAME and NS records become subdomain takeovers, how to detect them at scale, and how to remediate before an attacker claims your brand.

Security Research13 min read

The Supabase RLS Trap: How One Missing Toggle Exposes Your Entire Database

The Supabase anon key is public by design. Row Level Security is the only thing standing between it and every row in your database. Here is what happens when it is off.

Security Research13 min read

From Scanner Noise to Validated Findings: Killing False Positives in External Recon

Scanners over-report by design. Here is why false positives drain security teams and MSSPs, and a discipline for validating exposures before you report them.

Security Research13 min read

The Vibe-Coding Security Crisis: How AI-Generated Apps Ship Critical Vulnerabilities

AI-generated apps are shipping without RLS, rate limiting, or auth. We break down CVE-2025-48757 and the real failure patterns behind the vibe-coding wave.

Security Research13 min read

What Happened to SquareX? The Timeline of the Delisting and Zscaler Acquisition

SquareX is no longer listed on the Chrome Web Store, and Zscaler closed its acquisition on February 5, 2026. See the confirmed timeline.

Security Research8 min read

Browser Isolation Chrome Extension: What It Is, Who Needs It, and What To Look For

Choosing a Chrome browser isolation extension starts with the job: contain phishing, risky browsing, or AI and SaaS use. See what matters.

Security Research9 min read

Adobe Cheaper Price Country: Where Creative Cloud Costs Less

Adobe Creative Cloud pricing changes by country. Compare official regional pages, find lower offers, and assess checkout without a leaky VPN.

Privacy Engineering9 min read

You Drove 45 Minutes to Indiana to Place a Bet. There's a Better Way.

Sports betting access changes by state. Separate legal eligibility from geolocation errors, browser noise, and the cost of crossing state lines.

Privacy Engineering10 min read

Kalshi Blocked My State: What To Check Before You Assume It's a Geography Ban

A Kalshi state-block message can reflect jurisdiction, identity, location, or funding issues. Use official rules to diagnose access accurately.

Privacy Engineering8 min read

Try it on the next page you do not trust

Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.

Free for 30 days. No card required.

Ghost. A private route for your browser. Shield. An isolated browser, off your device. Choose the mode. Close when finished.