In the paper, Leith wrote:
From a privacy perspective Microsoft Edge and Yandex are qualitatively different from the other browsers studied. Both send persistent identifiers that can be used to link requests (and associated IP address/location) to backend servers. Edge also sends the hardware UUID of the device to Microsoft and Yandex similarly transmits a hashed hardware identifier to back end servers. As far as we can tell this behaviour cannot be disabled by users. In addition to the search autocomplete functionality that shares details of web pages visited, both transmit web page information to servers that appear unrelated to search autocomplete.
Strong, Enduring IdentifiersBoth Edge and Yandex send identifiers that are tied to device hardware, the study found. These unique strings, which can also link various apps running on the same device, remain the same even after fresh installs of the browsers. Edge sends the universally unique identifier of a device to a Microsoft server located at self.events.data.microsoft.com. This identifier can’t easily be changed or deleted. What’s more, the Edge feature that autocompletes website requests—and in so doing, sends details of typed sites to a backend server—can’t be disabled. The researcher said that he was unaware of any way users could disable the data collection.ARS TECHNICAThis story originally appeared on Ars Technica, a trusted source for technology news, tech policy analysis, reviews, and more. Ars is owned by WIRED's parent company, Condé Nast.Yandex, meanwhile, collected a cryptographic hash of the hardware MAC address and details of visited websites through the autocomplete function, although the latter could be disabled. Because Edge and Yandex collect identifiers that are linked to the hardware running the browsers, the data persists across fresh browser installs and can also be used to link various apps running on the same device. These identifiers can then be used to track IP addresses over time.
“Transmission of device identifiers to backend servers is obviously the most worrisome since it is a strong, enduring identifier of a user device that can be regenerated at will, including by other apps (so allowing linking of data across apps from the same manufacturer) and cannot be easily changed or reset by users,” the paper warned.