Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

141–150 of 501 posts

Re: Brave, the false sensation of privacy

#141
post #94

Earlier quoted context omitted.

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

I find Comcast’s fuckery to be limited to their business practices. Their actual IP network seems to be very solid.

100% agreed. And I've been a Comcast customer long enough to have seen the days when that certainly wasn't the case. They've made some pretty big mistakes in the past, but they seem to have learned their lesson.

Re: Brave, the false sensation of privacy

#142
post #73

Earlier quoted context omitted.

There's still an element of trust involved, but it's better than the status quo of "we'll monitor your internet, take it of leave it" from the ISPs.

If you turn on your VPN, they can do exactly that. You’re just trading one for the other and that new one might not even have to follow the same laws.

except that if a VPN provider is caught selling your data, they are toast.

any VPN worth its salt has a business model built around not logging data and not selling data. Your ISP on the other hand, is in the business of selling you internet access. Your data is a secondary revenue stream for them.

They two are not equivalent.

Re: Brave, the false sensation of privacy

#144
post #77

Fear mongering. A competitor maybe? Someone with an agenda against Eich because of the donation debacle? Privacy-wise, either Firefox or Brave are better than Chrome. Ads are annoying but they do fund the net.

If you've visited /g/ lately you know how much Brave is pumping threads that are basically just ads for Brave. I wouldn't immediately jump to competitor conclusion (and even they were they have good points) To be Brave's model has always been bat shit insane.

>Ads are annoying but they do fund the net. This is a complete lie. If your website can not survive without ads then it shouldn't exist. Running a website takes almost no capital. Only people who are afraid about ad insdustry being destroyed (expect of course the people running the industry) are shitty blogs and useless news sites, because the truth is their content is so sub par that no one in their right minds would pay anything for it, but at least they can scam people into being sold onwards to advertisers.

Everyone should be running uBlock Origin. Everyone should be running ad blocking DNS. Websites that don't allow adblocks aren't worth visiting in the first place.

Re: Brave, the false sensation of privacy

#145
post #96
post #35

Earlier quoted context omitted.

You may be right, and you may not be. It has to be good that there are more than exactly one engine, it means there is a discussion, some level of "forced openness". That wouldn't be possible if web developers could simply rely on undocumented quirks of a sole browser. It's possible that FF will die. But I think that would be extremely sad. For one, Manifest V3 would be forced upon the entire web => no more uOrigin.

> It has to be good that there are more than exactly one engine... Well, that is kinda the point. No, it doesn't. It might be worse than having one great de-facto standard engine. Having 2+ splits web developers in what they choose to support. In this instance, we literally have a young company (Brave Software, Inc) that chose to go head-to-head with Google. Their CEO is deeply entwined with the history of first Nets…

Using Gecko (or Webkit) would have added extra risk for Brave. When you're starting a company, especially a browser company that's going to take on Google at some level, you need to minimize all unnecessary risks. I don't blame Brendan for doing that.

Plus, when Brendan started Brave, Firefox was further behind in performance and architecture than it is now.

Plus, Brendan's departure from Mozilla was somewhat messy and I don't blame him for not wanting to keep a Mozilla dependency.

> Having 2+ splits web developers in what they choose to support.

Having one engine, Chromium, would mean Google gets a completely free hand to make almost all decisions about how the Web works. Also, Web sites would have no chance of noticing they depend on Chromium bugs --- very bad for the future of the Web (and for Chromium).

Now, Webkit is also a very viable engine. The problem with relying on Apple is that they have a powerful disincentive to let the Web platform be a viable competitor to iOS.

This is why Mozilla matters.

Re: Brave, the false sensation of privacy

#146
post #59

Earlier quoted context omitted.

> you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This is the government's fault not Brave's. There are laws that enforce the requirements. We do not have the freedom to move value or money around freely any more.

It's Brave's fault if they only give you access to your BAT coins after signing up with Uphold. There should be no reason they hide access to your coins until you use a third party service to dox yourself. Brave may not be implementing the dox'ing, but they appear to be requiring you to use someone else's implementation which is absolutely their fault.

I am guessing that the parent comment has it right. This is admittedly outside my area of expertise, but I would assume that the system they have for managing BATs is subject to the US's Know Your Customer laws, which require financial institutions (including crypto exchanges) to, well, know their customer. Personally.

They have to figure all that out before they give you access to your account. Which means, yeah, there may well be a good reason for them to require you personally identify yourself before giving you access to the tokens: if they didn't, they'd risk getting into serious trouble with the authorities.

They didn't technically need to contract that stuff out to a third-party company, of course. But, from a practical perspective, they did. They're a small browser company and financial regulation compliance would be a huge and burdensome departure from their core skill set. I don't think they could have afforded to do it themselves.

Re: Brave, the false sensation of privacy

#147
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

If it bother's you there's TOR and you can ssh to a vps. Most stuff is encrypted now and there are 3 different DNS encryption standards (one of which is actually good.)

IMO: what's left of that issue is getting solved.

Re: Brave, the false sensation of privacy

#148
post #100

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

The recommendation of _The UNIX and Linux System Administration Handbook_ is a good one. As far as Comcast, I'm stuck with them, too. At least in my experience, they don't monkey with DNS - I run and use my own DNS servers, and have never seen interference. They do run deep packet inspection, and if they detect you, for instance, torrenting commercial media, they'll inject scary messages in port 80 traffic. Given tha…

Curious: how can they detect whether you're torrenting commercial media if you've enabled Bittorrent protocol encryption? Surely all they can see then is the outer (envelope) of the packets...?

Re: Brave, the false sensation of privacy

#149
post #94

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

Weren't they the ones who pioneered DNS hijacking of unknown domains to serve their own recommendations and ads?

Re: Brave, the false sensation of privacy

#150
Notes about some of the points made:

- The built-in blocker, just like the blocker on Firefox, Edge or Opera, isn't that good. That's why you should install something like uBlock Origin on top.

- If all scripts from Facebook and Twitter are blocked, you'll end up with broken pages. Some pages have Facebook comments, which won't load if you block all Facebook domains. Embeded tweets also won't work if Twitter is blocked. Not everyone is an advanced user, so I understand why they decided not to block everything (they give you the option to block this - check your settings).

- Brave Rewards... for users: you don't have to use it. Independently of the DNS queries, you won't see any ads if you don't opt-in. If you decide to join, you'll get some BAT at the end of the month. It's not 100%, but it's more than the 0% you receive from Google Adsense.

- Brave Rewards... for website operators, youtubers, etc: I think this is where we sometimes miss the point. Users are already blocking your ads! Even if they don't use an extension for that, the built-in blocker in Brave, Opera and Firefox already block some or all of your ads. That revenue is gone.

So, and if users opt-in, you'll be able to make some money via Brave Rewards (we just have to confirm that we own the site, like a Google Webmaster Tools verification). Again, users already block your ads. Between no revenue and some revenue, what's better?

We should also keep in mind that by default, the money users receive is then shared among the sites they visited. In practice, users are sending you a small monthly payment/donation for using your site, viewing your videos, etc.

- "You may have seen in the past a fork of Brave which removed telemetry and other shady practices from Brave. It was called Braver."

Not sure what's the surprise here. We can't create a Firefoxer or Edgier without getting in trouble with Mozilla or Microsoft. Being able to fork doesn't mean that we can use the same name.

Post reply on HN