SRWare Iron
SRWare Iron is a free web browser, and an implementation of Chromium by SRWare of Germany.
Spyware Level: EXTREMELY HIGH
SRWare Iron claims to be a privacy respecting web browser that is an alternative to Google Chrome's spyware, and specifically brands itself as a privacy respecting web browser that aims to give users the Chrome experience without Google's spyware. However when examining this program, these claims instantly melt away. SRWare Iron connects to an absolutely incredible amount of trackers and opens connections to an enormous amount of servers on it's first run. It racks up a rough estimate of ~400-500 unsolicited connections, and it actually took several minitues for it to stop making new requests and connections. SRWare Iron uses the spyware search engine Bing as it's default search engine, however it goes beyond that and routes your requests to Bing through it's own servers so that it can spy on your internet searches as well. The bottom line is that this browser is just another false privacy initiative and is really no better than Chrome.
Version 69.0.3600.0 of SRWare Iron was tested on Windows 7 64-bit. MITMproxy, Microsoft Network Montior 3.4, and Sysinternals ProcMon were used to monitor the behavior of this program.
False Privacy Initiative
SRWare Iron claims on it's website that it is:
"Chrome thrilled with an extremely fast site rendering, a sleek design and innovative features. But it also gets critic from data protection specialists , for reasons such as creating a unique user ID or the submission of entries to Google to generate suggestions. SRWare Iron is a real alternative. The browser is based on the Chromium-source and offers the same features as Chrome - but without the critical points that the privacy concern." [1]
The reality is that you are merely trading in one spyware product for another. Where Chrome's spyware has been removed, Iron's spyware is there to replace it. Which poision are you going to pick? The worst part is that people will read what is claimed on SRWare's website and beleive it without doing any tests for themselves. Like this article [web.archive.org] that just copies the comparison-list from Iron's website without any real investegation before delcaring it a privacy alterantive to Chrome. The most audacious thing about it is this incredible quote on the FAQ section for the Iron browser:
"Can i really check that Iron doesn't submit any private data, how you say? Yes, you can. There are tools like Wireshark, which scan the whole network-traffic. We could not recognize any obvious activity. But you can proof this by yourself." [2]
Which is just an amazing gem in the context of what is actually found when running tests on the software.
Massive amount of connections on first startup
When you first start SRWare Iron, it will immediately open the following two pages: https://iron.start.me/us
and
https://www.srware.net/en/software_srware_iron.php
. The most offensive page is the start.me
domain
which begins loading in an enormous amount of spyware from all over the internet. I did not count the specific amount of requests
but it was somewhere in the 400-500 range (my software doesn't provide a great amount of automation... or maybe i'm not using it
as well as I could). This image (at 1.06 MB- almost 1/4 of the size of the entire site as of writing!)
should give you an idea of the amount of requests I was swamped by. It took a while for it to die down. On subsequent runs the
amount of requests it sent was far less. It connected to spyware platforms like Google Analytics and Piwik, and executed their JavaScript payloads.
There were a lot of redundant connections to Google Analytics so it's probable that multiple companies are able to send their own
analytics payloads through this homescreen. Thus throughly fingerprinting and profiling your web browser and computer the moment you
begin browsing the internet with your new "privacy respecting" browser- so that all of these advertising companies can track you
everywhere you go!
When checking the browser's connections in Network Monitor 3.4, you could see that it connected to a huge amount of servers, even though only two domains were ever contacted.This screenshot doesn't caputre all of the IP addresses that it connected, but should give you an idea.
And just so that there is no ambiguity, this notice is shown when you load this homepage:
"We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information you’ve provided to them or they’ve collected from your use of their services."
Just so that there is no doubt- you are being served tracking cookies by advertising companies.
Redirecting of internet searches through developer's domain
After you've finished identifying your web browser to just about every single spyware company on the internet, you can begin making internet searches with your new SRWare Iron browser. The default search engine is the spyware search engine Bing. However it's not enough to just point you at a spyware search engine... when you try and actually run a search on Bing, this is what happens:
Basically, every time you make a search with this browser, your searches are sent through the developer's servers.
So, the developer can know exactly what your internet history is, in this way. Your searches are also being sent through
wisesearches.com
, but I don't know who they are. So now instead of giving up your search history to one
spyware company, Google, you can give it to three spyware companies, by switching to this browser. This is a very similar
tactic to the one that the spyware browser Slimjet uses, where it routes searches to
Bing through it's own domains.
Motivations of the SRWare Iron developer?
If you dig deeper into how SRWare Iron was created, you can find some interesting information from some of the developers of Chrome about the motivations behind the creation of this fork. More specifically this very interesting conversation:[3]
So, this could explain a lot... the motivation for this web browser to exist was to monetize privacy concerns by generating traffic to his website, where he could make money by serving spyware to the very users that wanted to escape from it. Then his fork gets loaded up with all sorts of spyware from all sorts of other companies... which he probably makes some amount of money from as well. (why else would he take the time to integrate these things into his browser? we can only speculate.) At the end of the day it's pretty clear that this browser is a huge scam and you shouldn't use it.