Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

181–190 of 501 posts

Re: Brave, the false sensation of privacy

#181

In 2001 or so I considered entering into an encrypted email correspondence with my brother, for fun. I quickly gave up on the idea because I realized that I didn’t trust that my computer or my brother’s computer didn’t already have spyware of some kind, I didn’t trust the integrity of any encryption/decryption tools that existed, didn’t trust myself not to lose the passwords or leave them lying around, and didn’t tru…

Do you lock the doors on your house? Why bother? Someone could break a window?

Security is about identifying and mitigating threat models.

For example, if you're concerned with mass surveillance an encrypted messenger will stop that.

Just because something doesn't protect against CIA 0days doesn't make it worthless.

Re: Brave, the false sensation of privacy

#182
Can someone explain the point in the article that Facebook can still track you if the script is loaded from an edge cache and the browser doesn't send cookies?

I can think of unique script URLs, but if it's coming from an edge cache, presumably it's not that unique.

And maybe some sort of JS-based fingerprinting? But since Brave controls the browser, it's within their control to try to make the browser environment homogenous across users. I think Tor Browser does something like that, not sure about Brave.

Any other attacks I'm not thinking of?

edit: oh, if the script makes a request back to FB, then I suppose your IP address is available...

Re: Brave, the false sensation of privacy

#183
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

I guess there are feasible attacks if the ISP is sufficiently motivated. They can't read the data transmitted, but they know how many bytes is in it, and with a cross reference on page sizes in the domain you're on, they might be able to narrow it down considerably.(maybe even to 1 possible page)

A more far-fetched attack is a sort of timing attack: if you first visit arstechnica.com and then shortly afterwards visit Amazon.com, one could look for links to Amazon on arstechnica and from there have a decent guess what product you viewed on Amazon. This becomes a lot more feasible when paired with the first attack mentioned above.

Re: Brave, the false sensation of privacy

#184
>Brave has built-in telemetry. Brave will make a ton of requests to the domain p3a.brave.com as telemetry

So does Firefox, yet this blog post suggests it as a replacement.

>Brave isn’t more than Chromium with another skin and a built-in adblocker with reduced functionality.

As far as I know it includes additional functionality such as build-in support for tor and ipfs. (and while it might not be the best choice if you want privacy, it at least makes onion sites accessible for normal people)

>This means that you need to update the entire browser to fix a bug in the adblocker

Just like for bugs in the firefox tracking protection and the dev tools in most browsers? It is like they are trying to include as much nitpicking as possible.

>However, it seems to have a contrary effect, since it sends requests to fetch the information required

Just like firefox.

>Brave uses Google’s gstatic, which is btw using Cloudflare.

Firefox uses Google analytics in about:addons.

>Hostility towards forks

looks at iceweasel

>The only browser that does not use Google’s web engine (blink) is Firefox

I would include Safari, at least from the popular ones.

(disclaimer: I am a Firefox user)

Re: Brave, the false sensation of privacy

#185

> brave-core-ext.s3.brave.com fetches 5 extensions and installs them. It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities. Okay, so which 5 extensions? There has to be more information on this somewhere. Article seems kind of lazy and definitely loses steam after the second half.

That part in particular set the tone for this entire post for me. It convinced me that I could not trust the author to be intellectually or rhetorically honest, at which point I no longer see any value in this write-up. It also helped me read the rest of this post in the correct context.

"Many people are saying this. Note that I'm not saying it, I only say true things. But I want you to think it anyway."

Really?

Re: Brave, the false sensation of privacy

#186

Earlier quoted context omitted.

The privacy/tracking aspect of Braves Ads (which you don't have to use) seems to be way, way better than Google Adsense. It's like comparing the good ol' fixed "image banner + link" vs Adsense. They're both ads, but one is better than the other. And then you have Chrome sending data directly to Google, the auto logins, dark patterns, etc, which you don't get with Brave or Vivaldi.

I find it funny that people say this when this is pretty much exactly what FLOC is - the browser choosing your interests and deciding which interests to send to the ad server - but without the "show ads on every website and hold the profits from website owners until they claim it".

> deciding which interests to send to the ad server

I was looking at their media kit[0]. They link to a presentation[1] which mentions that the ads are sent to the browser and then the browser itself picks the ones that should be shown to the user.

If this is really the case, then the browser isn't sending that information to the ad server.

[0] https://brave.com/brave-ads/assets/Brave_Media_Kit.pdf

[1] https://www.youtube.com/watch?v=qEj5ZiQohJc

Re: Brave, the false sensation of privacy

#187
post #161
post #61

Earlier quoted context omitted.

>I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.

On my home network I just run a transparent proxy and direct all outbound traffic bound to port 53 to my local dns server, it’s not hard.

Interestingly enough, this is almost exactly how ISPs do it when they really want to get your attention. A couple years ago I forgot to update an expired credit card that I used to pay my spectrum cable bill. One morning every DNS request resolved to their "your account is about to be closed due to nonpayment" page. As I also use my own DNS sever I was surprised by this, and sure enough everything going out of my network on 53 was being grabbed up by their CGNAT and sent to their DNS server.

Re: Brave, the false sensation of privacy

#188
post #19
post #13

I don't like the crypto nonsense of Brave, and while I like Firefox in theory, its performance leaves a lot to be desired and they don't seem to know who their user base is. Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.

> its performance leaves a lot to be desired I'm not sure what you're talking about; this may be the case several times in the past, but you should check again because this is a thing that constantly changes. Firefox performance today doesn't really leave a lot to be desired IMO > Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! Tree Style Tabs has been around since like… 2007?. Or d…

> Firefox performance today doesn't really leave a lot to be desired IMO

Sadly I recently left Firefox after having used it for 20 years (Phoenix/Firebird days).

The performance degradation was becoming too noticeable. I switched to Brave (of all things), but that's only because I could no longer fight the real performance that a Chromium-based browser has.

I hate doing this, because the last thing I want is a browser engine monopoly. That's why I started using Firefox in the first place, to help get rid of IE.

Re: Brave, the false sensation of privacy

#189
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs right now are freaking out that their very expensive solutions like Nokia Deepfield are seeing less and less.

Ten years ago you’d be right, but right now that business is dying rapidly.

Re: Brave, the false sensation of privacy

#190

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

So... I dunno... Just ignore the whole BAT/Rewards nonsense? I use none of that shit, though I do use Brave for a (very) few things that require a Chrome-like browser (i.e. Won't work in Firefox with my battery of plugins). I don't regard it primarily as a high-privacy tool (FF is better at that, though far from perfect) but it's better than using Chrome on non-Goog sites. Ah, the world has become a strange place. I…

Isn’t this only an issue if you actually want to cash out your $2 or whatever. The bigger benefit of Brave is that you can contribute money to websites or content creators that your prefer. This is like the “old” internet where ads didn’t care what content they were shown next to, giving much more freedom of expression on the net. Say YouTube thought your video joking about COVID meant they thought you deserved to demonetize your whole channel, we’ll now brave donations still allows you to make some sort of ad profit. That actually ads up for people from pennies from millions of people together. Cashing out for a few dollars a year is not really the intent of the system.
Post reply on HN