Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

91–100 of 501 posts

Re: Brave, the false sensation of privacy

#91
post #80

In 2001 or so I considered entering into an encrypted email correspondence with my brother, for fun. I quickly gave up on the idea because I realized that I didn’t trust that my computer or my brother’s computer didn’t already have spyware of some kind, I didn’t trust the integrity of any encryption/decryption tools that existed, didn’t trust myself not to lose the passwords or leave them lying around, and didn’t tru…

So closing your bathroom door isn’t worth it because someone can ram it? :)

I live in a house with toddlers. This is absolutely true. I leave the door open so it doesn't bash into my leg when they come hammering on it.

Re: Brave, the false sensation of privacy

#92
post #20

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

I think your anger is misplaced - you should be angry at government who requires Brave (and eBay, and Etsy, and any company that is paying out money to people) to require this. If this wasn’t legally required they (and every other company) wouldn’t do it.

Sites like eBay would require user identity verification whether or not the government required it. Can you imagine the scale of fraud on eBay if users were allowed to set up anonymous accounts and accept irreversible currency transactions to anonymous sellers? It would be a scammer’s dream come true.

I wouldn’t have any interest in using such marketplaces.

As for Brave: Whether or not KYC or other regulations explain their behavior, any cryptocurrency rewards program has an inherent incentive to make it as difficult as possible to cash out. People who cash out almost always sell their coins, putting downward pressure on the price. If they can use dark patterns to reduce the number of people selling coins, the coin price stays higher.

The ideal cryptocurrency rewards program (for the crypto, not the users) would give people coins but almost force them to hold those coins and make it as difficult as possible to sell. This simultaneously hypes the coin by spreading awareness and removes downward price pressure by making it difficult to sell. This almost always means the company or founders have a lot of the coin that they plan to sell off as it becomes popular.

Virtually everything that comes attached with arbitrary crypto tokens or rewards is a scam to make the founders wealthy while the users chase pennies.

Re: Brave, the false sensation of privacy

#93
The only reason I use Brave is that I can type “you” + tab to directly enter YouTube search from the URL input field, and this works for gMaps and Amazon. For the life of me I cannot figure out how to configure this in Firefox.

Re: Brave, the false sensation of privacy

#94
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

Re: Brave, the false sensation of privacy

#95

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

KYC, AML, CYA, IANAL

KYC stands for "Know Your Customer" and it's a reference to laws that require businesses to have a clue who they're doing business with. It's not a legitimate response to the concern here. The concern is failure to provide adequate information about the consequences of your actions up front. They're going to benefit from the ads, and they won't necessarily have to pay for that benefit, because they didn't adequately obtain informed consent before they began by informing you that you need to pony up PII to a third party.

AML is probably Anti-Money Laundering. It again has nothing to do with informed consent. It is possible to prevent money from being laundered by telling a person up front, before they agree to sign up, that they have to give their private information to a third party.

CYA is probably "Cover Your Arse". Again, it's not a legitimate concern for the same reason as above.

IANAL is obviously not a response to the original concern but merely intended to reduce the risk of the reply. But there's no legal issues being raised. The issue is purely whether or not a business who praises their privacy credentials should clearly let their customers know that, if they choose to engage in business with them, their private information will need to be shared with a business who they may not trust.

If OP's story is true, Brave is not above engaging in distrust for dollars. That's the lesson to be learnt here. Brave doesn't care about your privacy. They just hope that by marketing privacy, they can get a few customers. And they will and apparently do engage in shady practices that compromise your privacy. No acronym can justify that, other than something that stands for "Businesses need to be responsible for their actions, not just their profits".

Re: Brave, the false sensation of privacy

#96
post #35
post #26

The people arguing that Firefox has an edge because it maintains a separate browser engine (like the writer of this article) are going to have real difficulties making their argument. Ditto the attacks on Brave for not being private enough. The people who care about privacy should be more worried about getting caught in Google's web of properties than about privacy per-se - that company is bad news. And Firefox is mo…

You may be right, and you may not be. It has to be good that there are more than exactly one engine, it means there is a discussion, some level of "forced openness". That wouldn't be possible if web developers could simply rely on undocumented quirks of a sole browser. It's possible that FF will die. But I think that would be extremely sad. For one, Manifest V3 would be forced upon the entire web => no more uOrigin.

> It has to be good that there are more than exactly one engine...

Well, that is kinda the point. No, it doesn't. It might be worse than having one great de-facto standard engine. Having 2+ splits web developers in what they choose to support.

In this instance, we literally have a young company (Brave Software, Inc) that chose to go head-to-head with Google. Their CEO is deeply entwined with the history of first Netscape then Mozilla/Firefox. They went with Chromium.

That is a pretty searing indictment of the "an independent engine is important" argument. If Eich doesn't think Firefox is up for the challenge, what exactly is the gameplan here?

Nobody is saying Mozilla has to die, whatever that means. But if there is an advantage to its existence that advantage is difficult to spot. Firefox doesn't even have the thriving extension ecosystem it could once boast about - they killed most of it off. There is nothing useful there except a different set of quirks.

Re: Brave, the false sensation of privacy

#97
post #34
post #15

So I feel as if the author is missing the point. Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a…

I feel the author is on point. Brave is all about marketing and surfing the privacy wave to make profit. Take a look at https://brave.com/brave-ads/ Brave goal is to acquire as much users as possible to sell them to advertisers. They are no different from Google. Might as well use Chrome with ublock origin and farm crypto on your own.

The privacy/tracking aspect of Braves Ads (which you don't have to use) seems to be way, way better than Google Adsense. It's like comparing the good ol' fixed "image banner + link" vs Adsense. They're both ads, but one is better than the other.

And then you have Chrome sending data directly to Google, the auto logins, dark patterns, etc, which you don't get with Brave or Vivaldi.

Re: Brave, the false sensation of privacy

#98
post #94

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

There's already a huge uproar around Comcast. But Comcast isn't losing any customers, because they have monopolies.

Re: Brave, the false sensation of privacy

#99
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.

[deleted]

Re: Brave, the false sensation of privacy

#100
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

The recommendation of _The UNIX and Linux System Administration Handbook_ is a good one.

As far as Comcast, I'm stuck with them, too. At least in my experience, they don't monkey with DNS - I run and use my own DNS servers, and have never seen interference.

They do run deep packet inspection, and if they detect you, for instance, torrenting commercial media, they'll inject scary messages in port 80 traffic. Given that nearly all web traffic is encrypted now, the main effect of this is to break things like automated `apt-get update`s.

One thing you can do to detect transparent DNS hijacking is to ask a nonexistent server a question. Something like `dig @13.14.15.16 news.ycombinator.com` should not give you an answer. If it does, someone's spying on and/or gaslighting you.

Post reply on HN