Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

191–200 of 501 posts

Re: Brave, the false sensation of privacy

#191
post #161
post #61

Earlier quoted context omitted.

>I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.

On my home network I just run a transparent proxy and direct all outbound traffic bound to port 53 to my local dns server, it’s not hard.

I just block all outbound port 53 traffic, any device or app that doesn't honor my DHCP-provided DNS resolver can suck it.

Looking at you, Chromecast that tries 8.8.8.8 40 times an hour even though you know perfectly damn well that 10.10.10.1 is working

Re: Brave, the false sensation of privacy

#192

Earlier quoted context omitted.

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

I guess there are feasible attacks if the ISP is sufficiently motivated. They can't read the data transmitted, but they know how many bytes is in it, and with a cross reference on page sizes in the domain you're on, they might be able to narrow it down considerably.(maybe even to 1 possible page) A more far-fetched attack is a sort of timing attack: if you first visit arstechnica.com and then shortly afterwards visit…

These are all smart thoughts but you’ve clearly never worked for or with an ISP. As business entities in general they don’t have that kind of technical sophistication. They are more on the level of “we have to hire these vendor consultant groups to install VMs for us” than “we build a crawler so that we can use domain plus byte count to drink-anonymize visited pages.”

Re: Brave, the false sensation of privacy

#193
Is the saying "storm in a teacup" or "tempest in a teapot" or something like that?

Anyway, I don't really find any of this that egregious tbh.

Personally, I'm layering with nextdns to drop all the crap, and vpn over that, maybe solely depending on any one solution is the failure?

Also the "use Firefox" would be awesome if we could rely on Mozilla! I have always wanted them to succeed but recently they've been stumbling so hard and it doesn't look so promising.

Re: Brave, the false sensation of privacy

#194
post #67

I understand Eich has been controversial and Brave gets a lot of flak in return, regardless of issues like the ones raised in the article. Yet, I remain a fan of Brave because of Brave Rewards. I love being rewarded based on my usage, even if the amount is worthless and the ads are random crypto shit. The idea of a company actually spreading revenue based on my attention back to me makes me happy and I wouldn't mind…

> even if the amount is worthless and the ads are random crypto shit.

Maybe you are not valuing your own resources enough. Ads draw time, concentration and other mental resources. So i can only believe that it will be a net-negative in the end. It can feel rewarding, but financially, the advertiser can't pay you enough.

Re: Brave, the false sensation of privacy

#195
post #174

Another shady practice: you could donate to any website, but Brave itself received the amount if not claimed by the website creator. Users did not know. ( https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br... , https://redd.it/a8g1i9 ) Don't use Brave. Tell others not to use it.

Did any lawsuits come out of this? That seems like actual fraud, and Eich or others in the company should be in prison.

The money goes back to the wallet that sent it after a period of time if no one claims it.

Re: Brave, the false sensation of privacy

#196

Earlier quoted context omitted.

I guess there are feasible attacks if the ISP is sufficiently motivated. They can't read the data transmitted, but they know how many bytes is in it, and with a cross reference on page sizes in the domain you're on, they might be able to narrow it down considerably.(maybe even to 1 possible page) A more far-fetched attack is a sort of timing attack: if you first visit arstechnica.com and then shortly afterwards visit…

These are all smart thoughts but you’ve clearly never worked for or with an ISP. As business entities in general they don’t have that kind of technical sophistication. They are more on the level of “we have to hire these vendor consultant groups to install VMs for us” than “we build a crawler so that we can use domain plus byte count to drink-anonymize visited pages.”

[deleted]

Re: Brave, the false sensation of privacy

#197

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

> But I really dislike the author’s strident writing style.

Colorful and emotional language gets attention. Dispassionate writing doesn't. Whenever I see people criticize an author for a little rhetorical flair, I play the famous "Pirates of the Caribbean" scene in my mind:

Hacker News: "Your article is the most strident and obnoxious piece of technical writing I've ever heard of"

Author: "Ah, but you have heard of it!"

Re: Brave, the false sensation of privacy

#198
post #94

Earlier quoted context omitted.

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

Comcast isn't doing anything to your DNS. They're the largest ISP in the country, there'd be a huge uproar if they were doing something like that. There are plenty of experts who are subscribers who'd be able to figure out exactly what's going on.

That couldn't be more wrong. They literally published an IETF draft standard on how they do it.

https://datatracker.ietf.org/doc/html/draft-livingood-dns-re...

Re: Brave, the false sensation of privacy

#199

Earlier quoted context omitted.

I guess there are feasible attacks if the ISP is sufficiently motivated. They can't read the data transmitted, but they know how many bytes is in it, and with a cross reference on page sizes in the domain you're on, they might be able to narrow it down considerably.(maybe even to 1 possible page) A more far-fetched attack is a sort of timing attack: if you first visit arstechnica.com and then shortly afterwards visit…

These are all smart thoughts but you’ve clearly never worked for or with an ISP. As business entities in general they don’t have that kind of technical sophistication. They are more on the level of “we have to hire these vendor consultant groups to install VMs for us” than “we build a crawler so that we can use domain plus byte count to drink-anonymize visited pages.”

BT (a UK ISP) were up to hijinks in 2008 - "BT and Phorm: how an online privacy scandal unfolded"

https://www.telegraph.co.uk/technology/news/8438461/BT-and-P...

Re: Brave, the false sensation of privacy

#200
post #108

Earlier quoted context omitted.

You can just use whatsapp or whatever. The phone network with SIP/SS7 etc. is hopeless, but you don't have to use it, and most people I know prefer other forms of communication anyway.

I mean more like not just the data transfer layer, but the whole cell telephony baseband firmware enables privileged access to your phone. This can be the entry vector for multiple exploits that go way below the application layer. E2E encrypt is meaningless at this level.

>but the whole cell telephony baseband firmware enables privileged access to your phone

This is very outdated, at least for a significant number of smartphones (including all iPhones, but not limited just to those). Apple and IIRC other manufacturers long since isolated the baseband, treating it simply as a standard USB or PCIe peripheral (and in the latter case using an IOMMU with it amongst other things). It has zero special access to anything on the rest of the phone which in the smart phone era is where everything of interest actually lives and happens.

Post reply on HN