Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

221–230 of 501 posts

Re: Brave, the false sensation of privacy

#221

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

Most of the article is in fact factually incorrect.

The main thesis is that: Brave's adblocker is just uBlock Origin and so it's better to just use uBlock Origin on FF.

But Brave's adblocker is not just uBlock Origin so the entire article falls apart.

Everything else is just trying to misrepresent everything in the worst possible light.

> It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities.

Righttt... we're not children, we all know what you're trying to do here.

Re: Brave, the false sensation of privacy

#222
post #54
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

With the amount of VPNs popping out it seems that there is more than almost none worrying.

A clarification as there seems to be some confusion:

Whether VPNs solve the issue or not is irrelevant to my point. Their primary advertised feature is to hide your traffic from your ISP, McDonalds or whoever, and people buy them. (Secondary feature is masking location for streaming services, which doesn't really work).

Re: Brave, the false sensation of privacy

#223
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs are a blackbox and it's not possible to figure out what they do from user-side.

There is also hardly anything you can do about from your side. Using a vpn or similar solutions is only shifting the problem from one provider to another. You can reduce the exposure with some measurments, but they are also expensive and complicated.

But for this (and other) reasons companies have started to fix it from the server-side by offering encrypted connections and working on ways to hide your trail from the middleman and their attatched agencies.

Re: Brave, the false sensation of privacy

#224
post #13

I don't like the crypto nonsense of Brave, and while I like Firefox in theory, its performance leaves a lot to be desired and they don't seem to know who their user base is. Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.

Edge has the best security of any browser on Windows ducks

How is it better than any other Chromium based browser like Chrome, Brave or Vivaldi? I can understand it is more integrated than the others, but how is it more secure?

Re: Brave, the false sensation of privacy

#225
post #172

Earlier quoted context omitted.

Curious: how can they detect whether you're torrenting commercial media if you've enabled Bittorrent protocol encryption? Surely all they can see then is the outer (envelope) of the packets...?

This is a bit of a misconception. Copyright holders have always gone after seeders based on people connecting to swarms, tracker info, and crawling DHT. There’s no reason to use DPI when the list of uploaders is just given out by trackers and DHT for free. See: https://www.usenix.org/legacy/event/woot10/tech/full_papers/...

Exactly

Bittorrent protocol encryption is only useful to protest against the use of DPI for bandwidth shaping, it has no influence on privacy.

Even with (the weak) encryption, connections to trackers and DHT nodes are easily identified

Re: Brave, the false sensation of privacy

#226
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

ISPs do not know as much as Google/FB thanks to SSL, but they know a lot more than you'd think by analyzing connection metadata.

Also many ISPs are also carriers, which makes things worse.

Source: worked for telecos, have seen a lot of shady stuff myself.

Re: Brave, the false sensation of privacy

#227
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs are a blackbox and it's not possible to figure out what they do from user-side. There is also hardly anything you can do about from your side. Using a vpn or similar solutions is only shifting the problem from one provider to another. You can reduce the exposure with some measurments, but they are also expensive and complicated. But for this (and other) reasons companies have started to fix it from the server-si…

Encryption solves security, but doesn't entirely address privacy.

An ISP might not know what a user does at pornhub.com, but the ISP does know when and how often the user visits pornhub.com and how much data is exchanged when they do. I'm sure someone would pay for that kind of fingerprinting.

Re: Brave, the false sensation of privacy

#228
post #225
post #172

Earlier quoted context omitted.

This is a bit of a misconception. Copyright holders have always gone after seeders based on people connecting to swarms, tracker info, and crawling DHT. There’s no reason to use DPI when the list of uploaders is just given out by trackers and DHT for free. See: https://www.usenix.org/legacy/event/woot10/tech/full_papers/...

Exactly Bittorrent protocol encryption is only useful to protest against the use of DPI for bandwidth shaping, it has no influence on privacy. Even with (the weak) encryption, connections to trackers and DHT nodes are easily identified

Thank you for clarifying this!

Re: Brave, the false sensation of privacy

#229
post #37

Firefox user here. I've looked into Brave, but decided I didn't really want it. This article is incredibly slanted. It takes every single possible fact it can and spins it into "Brave Bad." Something like this: > Brave is just another Chromium skin. So at the end, when using Brave or any other Chromium based browser, you’re giving marketshare to Google and supporting their evil web empire. Is simply not true. Every b…

the biggest deal is hardcoded whitelist imho. rest of the article is just raw emotions

You can't fully block certain services without breaking pages. Block Facebook and you break hotlinked images and comments on some sites. Block Twitter and embeded tweets break. Some people use these services to login too. And so on.

I assume most users here understand this and would be able to fix the page, but the average user doesn't know how to do that. But then more advanced users should use uBlock Origin too, which lets you block Facebook, Twitter, Disqus, etc, too, so I don't think it's a major issue for us.

Re: Brave, the false sensation of privacy

#230
post #204

Earlier quoted context omitted.

Simply use a package manager.

[insert link to infamous HN Dropbox comment here]

This is the second reference to that in this thread. It's getting pretty old and I don't even think it's relevant
Post reply on HN