Firefox user here. I've looked into Brave, but decided I didn't really want it. This article is incredibly slanted. It takes every single possible fact it can and spins it into "Brave Bad." Something like this: > Brave is just another Chromium skin. So at the end, when using Brave or any other Chromium based browser, you’re giving marketshare to Google and supporting their evil web empire. Is simply not true. Every b…
Brave, the false sensation of privacy
71–80 of 501 posts
Re: Brave, the false sensation of privacy
#72So I feel as if the author is missing the point. Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a…
I feel the author is on point. Brave is all about marketing and surfing the privacy wave to make profit. Take a look at https://brave.com/brave-ads/ Brave goal is to acquire as much users as possible to sell them to advertisers. They are no different from Google. Might as well use Chrome with ublock origin and farm crypto on your own.
Re: Brave, the false sensation of privacy
#73Earlier quoted context omitted.
With the amount of VPNs popping out it seems that there is more than almost none worrying.
It’s not like VPNs don’t have the exact same problem, though…
Re: Brave, the false sensation of privacy
#74Earlier quoted context omitted.
Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.
TLSv1.2 traffic contains the hostname of the site you're connecting to, and the list of ciphers. This can be fingerprinted to identify your browser, and the server-side software. [1] TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing... [1] https://engineering.salesforce.com/tls-…
Re: Brave, the false sensation of privacy
#75Earlier quoted context omitted.
With the amount of VPNs popping out it seems that there is more than almost none worrying.
It’s not like VPNs don’t have the exact same problem, though…
Depending on where you live the likelihood of your ISP doing something exceptionally nefarious might be way lower than some random VPN client someone finds on an appstore.
Re: Brave, the false sensation of privacy
#76Earlier quoted context omitted.
Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.
TLSv1.2 traffic contains the hostname of the site you're connecting to, and the list of ciphers. This can be fingerprinted to identify your browser, and the server-side software. [1] TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing... [1] https://engineering.salesforce.com/tls-…
eSNI is not the default behavior, and has few deployments at scale. TLSv1.3 transmits SNI in the clear.
eSNI is being replaced with ECH[1], but in many cases, there is a 1:1 relation between the IP address and the site being served. ESNI and ECH are only one layer of obfuscation - a middleman (such as an ISP) could still snoop your DNS (unless DoH/DoT) and/or correlate the IP addresses you connect to against the hostname(s) presented on that server.
Attackers already do that today with nmap - scan publicly addressable ranges on port 443 and see what names are on the certificate presented by the server.
Re: Brave, the false sensation of privacy
#77A competitor maybe? Someone with an agenda against Eich because of the donation debacle?
Privacy-wise, either Firefox or Brave are better than Chrome.
Ads are annoying but they do fund the net.
Re: Brave, the false sensation of privacy
#78Earlier quoted context omitted.
Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.
TLSv1.2 traffic contains the hostname of the site you're connecting to, and the list of ciphers. This can be fingerprinted to identify your browser, and the server-side software. [1] TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing... [1] https://engineering.salesforce.com/tls-…
That's supported in supported in tls 1.3, but actual deployment/usage is spotty (it's an extension, not mandatory). AFAIK it also requires your DNS to cooperate, since that's how it gets the keys for the initial handshake.
Re: Brave, the false sensation of privacy
#79I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…
To add to this, Brave appears to force you to use Uphold in order to "verify" your wallet. So this is absolutely Brave hiding your coins from you until you dox yourself with a third-party. It's entirely possible to trade bat for many other coins on exchanges without KYC, but Brave forces you to be unable to do that (regardless of your local laws it seems?) This is something Brave could easily fix by just exposing an…
If you want to get real BAT that you could send to any address, send to Uniswap, or cash out, you must create an account on Uphold and complete full KYC before you can withdraw. That's when, invisibly, the IOU BAT becomes functional, cryptocurrency-like BAT.
It's like there are 2 BATs in reality despite the marketing. FakeBAT and RealBAT. FakeBAT only works within Brave's approved creators and is what you receive in your browser, and you can convert it to RealBAT which is on Ethereum and ERC20 compliant but only if you do KYC.
Re: Brave, the false sensation of privacy
#80In 2001 or so I considered entering into an encrypted email correspondence with my brother, for fun. I quickly gave up on the idea because I realized that I didn’t trust that my computer or my brother’s computer didn’t already have spyware of some kind, I didn’t trust the integrity of any encryption/decryption tools that existed, didn’t trust myself not to lose the passwords or leave them lying around, and didn’t tru…