Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

51–60 of 501 posts

Re: Brave, the false sensation of privacy

#51
post #13

I don't like the crypto nonsense of Brave, and while I like Firefox in theory, its performance leaves a lot to be desired and they don't seem to know who their user base is. Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.

Does Vivaldi count?

If you trust the people behind Opera, sure?

Re: Brave, the false sensation of privacy

#52
I am currently using brave on android because it is the last latest stable browser that provides stacked Tab layout like this.

https://github.com/michael-rapp/ChromeLikeTabSwitcher

Latest chrome and it's derivatives(except brave) have removed this in favour of grid layout which i dislike(they also brought in tab groups which i despise entirely)

I know that brave has shady stuff like blockchain and ads, but they can be turned off. On desktop, i use firefox and i want to use firefox on android too but i find android firefox(fenix) janky.

Please suggest me good browser and also a suggestion to chrome developers:

Please don't remove things that we like. atleast provide option to enable it

Re: Brave, the false sensation of privacy

#53
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.

TLSv1.2 traffic contains the hostname of the site you're connecting to, and the list of ciphers. This can be fingerprinted to identify your browser, and the server-side software. [1]

TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing...

[1] https://engineering.salesforce.com/tls-fingerprinting-with-j...

//Edited to clarify that eSNI isn't default behaviour of 1.3

Re: Brave, the false sensation of privacy

#54
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

With the amount of VPNs popping out it seems that there is more than almost none worrying.

Re: Brave, the false sensation of privacy

#55
post #13

I don't like the crypto nonsense of Brave, and while I like Firefox in theory, its performance leaves a lot to be desired and they don't seem to know who their user base is. Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.

Edge has the best security of any browser on Windows

ducks

Re: Brave, the false sensation of privacy

#56
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.

TFA isn't though, for example.

Re: Brave, the false sensation of privacy

#57
post #54
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

With the amount of VPNs popping out it seems that there is more than almost none worrying.

It’s not like VPNs don’t have the exact same problem, though…

Re: Brave, the false sensation of privacy

#58
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

I don't always find it odd, but when I do I find it odd that we worry so much about applications when the entire cell telephony networking layer is completely and unpatchably hacked.

Re: Brave, the false sensation of privacy

#59

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

> you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This is the government's fault not Brave's. There are laws that enforce the requirements. We do not have the freedom to move value or money around freely any more.

It's Brave's fault if they only give you access to your BAT coins after signing up with Uphold. There should be no reason they hide access to your coins until you use a third party service to dox yourself.

Brave may not be implementing the dox'ing, but they appear to be requiring you to use someone else's implementation which is absolutely their fault.

Post reply on HN