Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

171–180 of 501 posts

Re: Brave, the false sensation of privacy

#171

Earlier quoted context omitted.

do we need randomized dom nodes ?

I guess I'd have to hear more details to know exactly what you're thinking, but my first instinct is to say that doing something like that would break CSS and accessibility without actually offering any significant impediment to tracking.

The cohort concerned about tracking, one would think, would not be deterred by broken CSS considering they already live in a JS-free world and might be used to some visual-compromise when browsing.

Re: Brave, the false sensation of privacy

#172
post #100

Earlier quoted context omitted.

The recommendation of _The UNIX and Linux System Administration Handbook_ is a good one. As far as Comcast, I'm stuck with them, too. At least in my experience, they don't monkey with DNS - I run and use my own DNS servers, and have never seen interference. They do run deep packet inspection, and if they detect you, for instance, torrenting commercial media, they'll inject scary messages in port 80 traffic. Given tha…

Curious: how can they detect whether you're torrenting commercial media if you've enabled Bittorrent protocol encryption? Surely all they can see then is the outer (envelope) of the packets...?

This is a bit of a misconception. Copyright holders have always gone after seeders based on people connecting to swarms, tracker info, and crawling DHT. There’s no reason to use DPI when the list of uploaders is just given out by trackers and DHT for free. See: https://www.usenix.org/legacy/event/woot10/tech/full_papers/...

Re: Brave, the false sensation of privacy

#173

Another shady practice: you could donate to any website, but Brave itself received the amount if not claimed by the website creator. Users did not know. ( https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br... , https://redd.it/a8g1i9 ) Don't use Brave. Tell others not to use it.

Relevant part;

>What happens if you send a tip to an unverified creator?

I click “tip” for my YouTube channel, and the screen below comes up. The “Learn more” link goes to the Brave FAQ, which says that no funds leave the browser until the creator verifies — but admits that previous versions of Brave worked differently, and sent the tokens to Brave in the hope that the creator would sign up at some point.

It would seem this is possibly no longer the case, I'd love an update on it.

Re: Brave, the false sensation of privacy

#174

Another shady practice: you could donate to any website, but Brave itself received the amount if not claimed by the website creator. Users did not know. ( https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br... , https://redd.it/a8g1i9 ) Don't use Brave. Tell others not to use it.

Did any lawsuits come out of this? That seems like actual fraud, and Eich or others in the company should be in prison.

Re: Brave, the false sensation of privacy

#175
post #168
post #16

> Their adblocker is just a fork of uBlock Origin, This does not appear to be true. Here is the github repo for their open source adblock engine written in rust: https://github.com/brave/adblock-rust Here is a (somewhat dated) article describing it by the authors: https://brave.com/improved-ad-blocker-performance/ > Google will take decisions that benefit their advertisement business, like making impossible to use ad…

Why not just use Ungoogled-Chromium?

It doesn't seem to include an automatic updater.

Re: Brave, the false sensation of privacy

#176

Earlier quoted context omitted.

If you turn on your VPN, they can do exactly that. You’re just trading one for the other and that new one might not even have to follow the same laws.

except that if a VPN provider is caught selling your data, they are toast. any VPN worth its salt has a business model built around not logging data and not selling data. Your ISP on the other hand, is in the business of selling you internet access. Your data is a secondary revenue stream for them. They two are not equivalent.

As long as you also clarify that their consumers must be following the news where that's announced.

With us technical people it's more likely, but not necessary for others that may have just heard 'use a vpn' and went to the App Store, searched for 'vpn' and prepaid 3 years.

Hide my ass VPN is still up - https://www.hidemyass.com/en-us/index

Re: Brave, the false sensation of privacy

#177
post #152
post #123

Earlier quoted context omitted.

There is no risk of everything being controlled by one company. That is why it is acceptable for there to only be one browser engine. Observe that Brave, inc is using the chromium engine in a way that opposes Google. Mozilla has developed a bunch of great features in the last few years. If they were developing on Chromium, most of the internet would have access to them. Instead, only a minor subset do. This is a bad…

I don't think you understand how Chromium works. Google makes all the important decisions. People have advocated for independent governance (e.g. some kind of Chromium Foundation) but Google isn't interested. E.g. Brave opposes Google in some ways but they have no say in the development of Web standards implemented by Chromium.

It is open source. If someone doesn't like a decision they can fork the codebase.

Mozilla's Gecko has been beaten down to sub-double-digit market share, they're less relevant right now than when IE6 was >75% of the market. They have no power to influence the direction the web moves in. And yet life is going on better than ever.

If you want a counterbalance to stop Google making the important decisions, Firefox has failed spectacularly. And yet Google doesn't have any power to move the web in a direction it doesn't want to go - because their engine is open source and that is what actually matters here.

Re: Brave, the false sensation of privacy

#178
post #33

Earlier quoted context omitted.

FF now does DNS over HTTPS by default (Preferences > General > Network Settings), it defaults to using NextDNS and is configurable. Some people will be uncomfortable with this default, but it's a step up from consumer ISPs who _will_ track you, to a 3rd party who Mozilla says wont. I add Mullvad VPN (because wiregaurd is frickin awesome), which also allows you to use their DNS servers, but for this you actually have…

The other great thing is, in case you wanted to support Mozilla, the MozillaVPN is using Mullvad's service, and routinely provides great service. I will add though, if you're a huge privacy advocate, and don't want to supply your email or card details to Mozilla but want to use a VPN, Mullvad directly is still the best choice imo.

I use Mozilla VPN, but the program (Ubuntu 20.04) 1+ times per day just closes and it does not have a network kill switch.

So I have to continue to use Firefox's DoH to prevent my university to occasionally take a peek at my traffic. Assuming they don't bother reversing IPs to domain names.

Re: Brave, the false sensation of privacy

#179
post #61

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

>I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.

I agree with you that comcast is incompetent, but everything becomes cheaper and easier over time and network hardware/software products that perform "deep" packet inspection at line rate as well as provide analytics on that returned data are now trivial and pretty much table stakes for Cisco, Juniper, Palo Alto et al.

Specifically for detecting if a user is not using their DNS, yes you could correlate a user's http requests (unless you are using ESNI the requested domain is in plaintext by design) with traffic logs on their DNS server and observe that there was no DNS request to the ISP DNS server before a request was made, I don't think that would be necessary. Most users use the ISP default DNS - that's your baseline. If most customers hit your DNS X times per Mb of web traffic, then someone using a custom DNS is going to stand out like a sore thumb.

Again, 100% agree that ISPs are not very technically competent (to put it mildly), but as time marches on the ability to both capture and more importantly analyze and report on that data is becoming cheaper and easier. ISPs want to get value from (sell) your data and vendors want to sell ISPs subscriptions to analytics and other platforms that bring them reoccurring revenue. Data from customer DNS is one of the most valuable sources of information an ISP has and I would be surprised if there was not at least an attempt to know how many customers did not use it.

Re: Brave, the false sensation of privacy

#180
post #20

Earlier quoted context omitted.

I think your anger is misplaced - you should be angry at government who requires Brave (and eBay, and Etsy, and any company that is paying out money to people) to require this. If this wasn’t legally required they (and every other company) wouldn’t do it.

Sites like eBay would require user identity verification whether or not the government required it. Can you imagine the scale of fraud on eBay if users were allowed to set up anonymous accounts and accept irreversible currency transactions to anonymous sellers? It would be a scammer’s dream come true. I wouldn’t have any interest in using such marketplaces. As for Brave: Whether or not KYC or other regulations explai…

Using this dark pattern is probably necessary, as it is the only robust way to protect them from being click-frauded. You can earn only small rewards by watching ads in a single browser, so there is a big incentive to run as many automated brave instances as possible. Then send it all to one wallet and cash out. But one would need to complete KYC for each instance. You can't move the tokens without it, so it can't be scaled up.
Post reply on HN