Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

161–170 of 501 posts

Re: Brave, the false sensation of privacy

#161
post #61

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

>I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.

On my home network I just run a transparent proxy and direct all outbound traffic bound to port 53 to my local dns server, it’s not hard.

Re: Brave, the false sensation of privacy

#162
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

I don't always find it odd, but when I do I find it odd that we worry so much about applications when the entire cell telephony networking layer is completely and unpatchably hacked.

It’s always been known that your carrier has access to your unencrypted cell traffic (including voice and text) and that carriers are slimy. You’re also protected by using secure services over IP. I think that the set of people for whom this will cause a threat model change is really small.

Re: Brave, the false sensation of privacy

#163
post #20

Earlier quoted context omitted.

I think your anger is misplaced - you should be angry at government who requires Brave (and eBay, and Etsy, and any company that is paying out money to people) to require this. If this wasn’t legally required they (and every other company) wouldn’t do it.

Let's presume this were true - that the Government was also at fault (I don't agree) - why does that excuse Brave's behavior? If I go look at any other service which requires that kind of information, it's always right up front. Want a Robinhood account? Great, you have to provide the info when you open an acocunt.

I use brave and rewards but have never cashed out so didn’t provide any KYC info.

I just donate BAT to sites.

Brave does “request info up front” for users who want to use the wallet. Requesting it from users who won’t need it is a waste of time.

All Robinhood users perform financial transactions, very few Brave users do.

Re: Brave, the false sensation of privacy

#164

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

So... I dunno... Just ignore the whole BAT/Rewards nonsense? I use none of that shit, though I do use Brave for a (very) few things that require a Chrome-like browser (i.e. Won't work in Firefox with my battery of plugins). I don't regard it primarily as a high-privacy tool (FF is better at that, though far from perfect) but it's better than using Chrome on non-Goog sites.

Ah, the world has become a strange place. I currently use no less than 5 different browsers for different contexts, but mainly Chrome for Goog properties on the seldom occasion I have to go there, FF for almost everything else. Then the corner cases...

Re: Brave, the false sensation of privacy

#165
post #77

Fear mongering. A competitor maybe? Someone with an agenda against Eich because of the donation debacle? Privacy-wise, either Firefox or Brave are better than Chrome. Ads are annoying but they do fund the net.

Disagree. Brave's approach to funding is at odds with privacy. The concept of warming up to ads to get paid is capitulating to the advertising industry.

While I did not appreciate the tone of the article, there are some valid points there. Brave may be better than Chrome but there are still better options. It might be better to get a common cold virus than it is to get covid-19, but I'd still rather not get any virus. Sites that don't work right when you block all of the tracking lose me, I won't capitulate.

Re: Brave, the false sensation of privacy

#166

Earlier quoted context omitted.

I am guessing that the parent comment has it right. This is admittedly outside my area of expertise, but I would assume that the system they have for managing BATs is subject to the US's Know Your Customer laws, which require financial institutions (including crypto exchanges) to, well, know their customer. Personally. They have to figure all that out before they give you access to your account. Which means, yeah, th…

And that's all right and good, I'm actually OK with this being the requirement for a system like this if a browser that rewards you with crypto is available. What I'm not OK with is that Brave isn't upfront about this.

Indeed. It's weird to see an organization whose entire sales pitch is, "Trust us, we're trustworthy," that persists in acting unnecessarily skeezy at seemingly every turn. Like, you half expect their next blog post to be, "We've been trying to reach you about your car's warranty..."

Re: Brave, the false sensation of privacy

#167
post #61

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

>I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.

I should think they just detect traffic from your IP address on port 53 to any IP address that's not one of their nameservers.

Re: Brave, the false sensation of privacy

#168
post #16

> Their adblocker is just a fork of uBlock Origin, This does not appear to be true. Here is the github repo for their open source adblock engine written in rust: https://github.com/brave/adblock-rust Here is a (somewhat dated) article describing it by the authors: https://brave.com/improved-ad-blocker-performance/ > Google will take decisions that benefit their advertisement business, like making impossible to use ad…

Why not just use Ungoogled-Chromium?

Re: Brave, the false sensation of privacy

#169
post #34
post #15

So I feel as if the author is missing the point. Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a…

I feel the author is on point. Brave is all about marketing and surfing the privacy wave to make profit. Take a look at https://brave.com/brave-ads/ Brave goal is to acquire as much users as possible to sell them to advertisers. They are no different from Google. Might as well use Chrome with ublock origin and farm crypto on your own.

I think the key difference is that user data are never shared with a third party, not even Brave. All the ad matching logic is done in client so data doesn’t leave my machine.

This is a big difference so using Brave vs Chrome doesn’t result in a company having a record of every site browsed.

Re: Brave, the false sensation of privacy

#170

Earlier quoted context omitted.

The privacy/tracking aspect of Braves Ads (which you don't have to use) seems to be way, way better than Google Adsense. It's like comparing the good ol' fixed "image banner + link" vs Adsense. They're both ads, but one is better than the other. And then you have Chrome sending data directly to Google, the auto logins, dark patterns, etc, which you don't get with Brave or Vivaldi.

>The privacy/tracking aspect of Braves Ads (which you don't have to use) seems to be way, way better than Google Adsense Exactly, "seems". Once again, good marketing from the Brave team. Heck, they even sponsored chess grandmaster Hikaru Nakamura on his Twitch stream.

Can you target users via Brave Ads like you can with Adwords/Adsense? If I understood correctly (I might be wrong - hence the "seems"), you can't because they're not doing anything close to what Google does.

I guess my point is that not all tracking or ads are the same. You can track clicks and views of a banner without profiling users across multiple sites and apps, learn all you can, and then let advertisers target them.

Post reply on HN