Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

111–120 of 501 posts

Re: Brave, the false sensation of privacy

#111
post #34

Earlier quoted context omitted.

I feel the author is on point. Brave is all about marketing and surfing the privacy wave to make profit. Take a look at https://brave.com/brave-ads/ Brave goal is to acquire as much users as possible to sell them to advertisers. They are no different from Google. Might as well use Chrome with ublock origin and farm crypto on your own.

The privacy/tracking aspect of Braves Ads (which you don't have to use) seems to be way, way better than Google Adsense. It's like comparing the good ol' fixed "image banner + link" vs Adsense. They're both ads, but one is better than the other. And then you have Chrome sending data directly to Google, the auto logins, dark patterns, etc, which you don't get with Brave or Vivaldi.

I find it funny that people say this when this is pretty much exactly what FLOC is - the browser choosing your interests and deciding which interests to send to the ad server - but without the "show ads on every website and hold the profits from website owners until they claim it".

Re: Brave, the false sensation of privacy

#112
post #33
post #27

FF + uorigin + a dns blocker like pihole seems to be where it’s at right now. Maybe EFF privacy badger on top Any better options out there? Been thinking of adding protonvpn

FF now does DNS over HTTPS by default (Preferences > General > Network Settings), it defaults to using NextDNS and is configurable. Some people will be uncomfortable with this default, but it's a step up from consumer ISPs who _will_ track you, to a 3rd party who Mozilla says wont. I add Mullvad VPN (because wiregaurd is frickin awesome), which also allows you to use their DNS servers, but for this you actually have…

The other great thing is, in case you wanted to support Mozilla, the MozillaVPN is using Mullvad's service, and routinely provides great service. I will add though, if you're a huge privacy advocate, and don't want to supply your email or card details to Mozilla but want to use a VPN, Mullvad directly is still the best choice imo.

Re: Brave, the false sensation of privacy

#113
post #108

Earlier quoted context omitted.

I have a feeling that you mean "easily" in the same sense the infamous Dropbox demo comment did. EDIT: I wasn't thinking, OP is completely right. Sorry for the snark.

You can just use whatsapp or whatever. The phone network with SIP/SS7 etc. is hopeless, but you don't have to use it, and most people I know prefer other forms of communication anyway.

Ah right, sorry understood. You're completely right...I wasn't thinking in terms of IP-based services.

Re: Brave, the false sensation of privacy

#114
post #15

So I feel as if the author is missing the point. Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a…

Not sure if I'm fully behind that comment, but it kind of raises an important point. If you want a freer web based on some kind of business, and not a non-profit/charity (and often a shaky one like Mozilla, financed mainly by Google)... this business has to function in some realistic way. (This is largely orthogonal to the open source/free - proprietary axis (which doesn't really exist in web browsers anymore). You should be able to sell/monetize free software.)

I, for one, wouldn't complain if some financially solvent (self-sustaining, money-making), reasonably ethical and non-exploitative web browser existed (the same for search engine, OS etc.). In the economic system that we have it could be more efficient in marketing -> market share among privacy-unaware people and so on.

So maybe we should strive to have a reasonable, analytic discussion what business practices are acceptable (rationally, if not emotionally at first glance) and which are not. This does not mean that we should just eat up whatever "privacy entrepreneurs" think of. But the tone of TFA feels a little less convincing because of the sprinkling of phrases like "their shitty program", like expecting you've already made up your mind.

Re: Brave, the false sensation of privacy

#116
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

do we need randomized dom nodes ?

Re: Brave, the false sensation of privacy

#118
post #103
post #94

Earlier quoted context omitted.

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

"Come on, what are you worried about? I'm sure it's fine, somebody must have inspected it."

Well, I can tell you that I'm a Comcast customer who doesn't use their DNS, and I have no issues. If I did have issues, I also have the expertise to figure out what's going on.

Re: Brave, the false sensation of privacy

#120
post #108

Earlier quoted context omitted.

I have a feeling that you mean "easily" in the same sense the infamous Dropbox demo comment did. EDIT: I wasn't thinking, OP is completely right. Sorry for the snark.

You can just use whatsapp or whatever. The phone network with SIP/SS7 etc. is hopeless, but you don't have to use it, and most people I know prefer other forms of communication anyway.

I mean more like not just the data transfer layer, but the whole cell telephony baseband firmware enables privileged access to your phone. This can be the entry vector for multiple exploits that go way below the application layer. E2E encrypt is meaningless at this level.
Post reply on HN