Disposable browsers for security researchers.
A disposable browser can support authorized research. It separates one temporary browsing session. It never creates testing permission.
Read the target's disclosure policy first. Define scope, methods, data handling, and stop rules. Choose the environment afterward.
Legba Shield suits narrow visual inspection. It is not a complete research laboratory. Its session ends when the tab closes.
The short version
Authorization comes first. The browser comes second.
Free for 30 days. No card required. $10 a month, or $100 a year.
Testing authority must exist before tooling.
Security research changes system behavior. Even careful testing can affect others. Tool selection cannot answer permission questions. Authorization needs a documented authorizing party.
NIST defines rules of engagement. Those rules exist before testing starts. They define constraints and detailed guidelines. They also provide authority for defined activities.
CISA's disclosure directive emphasizes published policies. Those policies identify authorized systems and testing. They also describe expected communications. Scope should remain readable and current.
DOJ provides one concrete policy example. Authorization depends upon policy compliance there. Activities outside that policy remain unauthorized. Other organizations publish different terms.
Read the policy as an authorization boundary.
A vulnerability disclosure policy can define authorization boundaries. It may list included systems. It may exclude vendors and subdomains. It may prohibit disruptive methods.
Read every scope statement literally. Similar domains may have different owners. Related applications may remain excluded. Shared infrastructure may introduce third parties.
Find the reporting channel next. RFC 9116 defines a standard disclosure file. That file can publish contacts and policies. Its scope follows the retrieved domain.
A missing policy needs clarification. Silence never means broad permission. Contact an authorized representative before active testing. Preserve that written exchange.
- Confirm the authorizing party.
- List every included hostname.
- List every excluded hostname.
- Record permitted testing methods.
- Record prohibited testing methods.
- Record data-handling requirements.
- Record the reporting deadline.
- Record the emergency contact.
Pass this authorization gate first.
The gate converts policy language into operations. Every row needs a written answer. Unknowns should block active testing. Assumptions should never fill legal gaps.
Internal testing needs the same discipline. A manager's informal request may lack authority. System representatives and data owners may differ. Third-party services need separate review.
Update the gate before each engagement. Scope changes can happen quickly. Infrastructure can move between providers. Contacts and reporting systems can also change.
Store the approved gate with project records. Give every researcher the same version. Record changes and effective dates. Retire superseded instructions clearly.
| Factor | Required evidence | Blocking unknown | Owner |
|---|---|---|---|
| Authorizing party | Documented authority from an authorized representative | Whether the requester controls the target | Engagement sponsor and legal reviewer |
| Technical scope | Exact hosts, applications, accounts, and environments | Whether related subdomains or vendors qualify | Authorized representative and test lead |
| Allowed methods | Permitted techniques, rates, tools, and test windows | Whether active validation exceeds policy | Test lead and authorized representative |
| Data handling | Collection, storage, encryption, and deletion rules | How sensitive data should be handled | Data owner and security lead |
| Stop conditions | Events requiring immediate testing suspension | Who decides whether testing resumes | Test lead and emergency contact |
| Reporting path | Approved channel, encryption, timing, and recipients | Where sensitive reports should be sent | Disclosure coordinator |
Every active test begins with documented authorization answers.
SourcesNISTUnited States Department of JusticeCISARFC EditorNIST
Choose the environment from the task.
Disposable browsing serves a limited research job. It can separate temporary web observation. It can reduce normal profile exposure. It also removes session state afterward.
Other jobs need persistent evidence. Some need network captures or instrumentation. Some require owner-provided test accounts. Others require dedicated analysis environments.
Choose from required capabilities first. Then consider convenience and speed. Never force every test through one tool. That shortcut can damage evidence quality.
The matrix favors safer escalation. It keeps Shield inside documented claims. It also gives stronger tools their proper role. Authorization remains mandatory everywhere.
| Factor | Likely starting environment | Required evidence | Disposable-browser fit |
|---|---|---|---|
| Visual page inspection | Approved off-device browser without personal state | Screenshots or notes allowed by policy | Good when temporary observation answers the question |
| Client-side behavior review | Instrumented browser inside a controlled environment | Console, network, storage, and reproducible steps | Limited unless required instrumentation is documented |
| Authenticated validation | Dedicated testing profile with approved accounts | Account scope, state, actions, and cleanup records | Poor without explicit account and state controls |
| Exploit reproduction | Explicitly authorized staging or dedicated research laboratory | Exact versions, controls, evidence, and rollback | Poor for uncontrolled active validation |
| Unknown file analysis | Purpose-built file or malware analysis environment | Artifact hashes, behavior records, and containment evidence | Poor because Shield is not that laboratory |
| Long-running investigation | Persistent workspace with approved evidence storage | Chain, timestamps, retention, and researcher access | Poor when closing destroys required session state |
Match the research task with its required environment properties.
SourcesLegbaUnited States Department of JusticeOWASP FoundationNISTChromium
Know exactly where Shield fits.
Legba Shield opens pages off-device. The browser session stays separate. The user still controls navigation. Closing the tab ends the session.
That model fits temporary visual inspection. It also fits basic page confirmation. It can keep personal browser state separate. These remain meaningful workflow advantages.
The public page promises no research instrumentation. It promises no packet capture. It promises no evidence archive. It promises no exploit containment benchmark.
Session destruction can become a disadvantage. Required evidence may disappear with state. Reproduction may require stable tooling. Long engagements may need persistent environments.
- Use Shield for narrow observation.
- Keep personal profiles outside research.
- Use only approved test data.
- Avoid credentials without explicit authorization.
- Record findings through approved systems.
- Close after the question is answered.
- Choose another tool when evidence must persist.
SourcesLegba
Plan the session before opening it.
A narrow session needs one research question. Write that question first. Define the minimum actions required. Avoid expanding scope during browsing.
Remove unrelated state before testing. Use no personal profile. Use no production credentials. Keep unrelated customer data elsewhere.
Define allowed observations and exports. Screenshots can contain sensitive data. Notes can reveal private identifiers. URLs can include tokens.
Define an explicit ending. Close after answering the question. Stop earlier when policy triggers occur. Record the closure and remaining artifacts.
- 01
Write the research question.
State one narrow fact requiring browser observation. Exclude curiosity-driven exploration.
- 02
Attach the authorization evidence.
Link scope, rules, contacts, test window, and permitted methods.
- 03
Prepare controlled inputs.
Use approved test accounts and synthetic data. Exclude personal secrets.
- 04
Define evidence handling.
Choose approved screenshots, notes, timestamps, storage, encryption, and retention.
- 05
Define immediate stop rules.
Stop on sensitive data, instability, scope drift, or unexpected impact.
- 06
Select the environment.
Choose Shield only when its public boundary meets requirements.
Preserve evidence without overcollecting data.
Useful reports need reproducible evidence. They do not need unrestricted data collection. Capture the minimum facts proving the issue. Follow every policy restriction.
DOJ's policy demonstrates strict minimization. Researchers should stop after confirming vulnerabilities there. Sensitive data triggers immediate notification. Other programs may define different rules.
Record timestamps and exact scoped assets. Record the approved test account. Record observable behavior and expected behavior. Avoid unnecessary personal data.
Store evidence through approved systems. Encrypt reports when required. Restrict access to assigned participants. Delete retained data according to policy.
| Factor | Useful record | Minimization rule | Shield consideration |
|---|---|---|---|
| Target identity | Exact approved hostname and path | Exclude unrelated hosts and user identifiers | Record before session closure |
| Reproduction sequence | Minimum authorized steps confirming behavior | Stop before unnecessary impact or data access | Write steps outside the temporary session |
| Visual evidence | Approved screenshot showing relevant behavior | Redact unrelated identities and confidential values | Export only through approved procedures |
| Timing evidence | Time zone, request time, and observed response | Avoid excessive repeat testing | Capture before ending the session |
| Researcher environment | Approved browser mode, versions, and relevant settings | Exclude unrelated device and account details | Legba publishes no automatic evidence archive |
Collect only evidence required for authorized reporting.
SourcesUnited States Department of JusticeNISTOWASP FoundationLegba
Stop early and report clearly.
Stop rules protect targets and researchers. Trigger them before material impact. Sensitive data should halt further exploration. Service instability should also halt testing.
Do not pivot beyond approved scope. Do not test unrelated accounts. Do not increase load casually. Do not collect extra proof.
Contact the program through its official channel. RFC 9116 can help locate that channel. Verify any redirect carefully. The current policy defines that program's boundary.
Send a concise reproducible report. Describe impact without exaggeration. Separate observation from inference. Mark untested theories clearly.
- 01
Stop the test.
Cease activity after sufficient evidence. Preserve approved records only.
- 02
Protect encountered data.
Avoid further access or copying. Follow immediate notification requirements.
- 03
Use the official channel.
Follow the published policy or disclosure file. Use its authorized contact or portal.
- 04
Report reproducible facts.
Include scope, environment, steps, impact, evidence, and safe remediation ideas.
- 05
Coordinate later disclosure.
Follow program timelines and written disclosure rules. Keep communications documented.
Use one final preflight checklist.
The final decision should feel boring. Authorization is documented. Scope is exact. Evidence handling is already arranged.
The chosen tool should match requirements. Shield should cover temporary browsing only. Dedicated labs should cover deeper analysis. Persistent workspaces should preserve required evidence.
Review browser protections too. Chromium uses operating-system sandbox controls. Exact assurances vary by platform. Off-device placement remains a separate property.
Repeat this review for every engagement. Policies can expire or change. Systems can leave scope. Reporting contacts can also change.
- Authorization evidence is current.
- Every target remains in scope.
- Every planned method remains allowed.
- Test accounts are explicitly approved.
- Data rules cover expected evidence.
- Stop conditions have named owners.
- The environment matches required tooling.
- The reporting path remains current.
FAQs.
References
- 01
- 02
- 03
- 04
- 05Department of Justice Vulnerability Disclosure PolicyUnited States Department of Justice
- 06OWASP Web Security Testing GuideOWASP Foundation
- 07
- 08Chromium sandbox designChromium