Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

231–240 of 501 posts

Re: Brave, the false sensation of privacy

#231
post #93

The only reason I use Brave is that I can type “you” + tab to directly enter YouTube search from the URL input field, and this works for gMaps and Amazon. For the life of me I cannot figure out how to configure this in Firefox.

In Firefox almost any search box can be right clicked and there is an option "Add a keyword for this search". If you use "y" shortcut for youtube, then your URL entry is "y gangnam". Also if you use DDG as your main URL search engine, they have bunch of "bang" shortcuts that redirect your query to online searches. For yt you'd use "!you gangnam". Others can be found here: https://duckduckgo.com/bang

Thank you and the others who recommended this!

Re: Brave, the false sensation of privacy

#232
The surest sign that Brave has made it is that 3 hours in, we aren't seeing a rush of rebuttals from Sampson, Clifton, or Eich in the comments.

The article rehashes some FUDy and misleading comments which have been knocked down years ago.

Brave's not perfect, but for different reasons than this author raises.

Re: Brave, the false sensation of privacy

#233
Slightly off topic, but it was a lot of fun to listen to Brendan Eich on Lex Fridman's podcast talk about Brave and the browser wars of the 90s and 00s. I've been using the Browser for several months without any of the rewards enabled and appreciate that it seems to quietly remove 95% of ads and does it effectively.

https://lexfridman.com/brendan-eich/

Re: Brave, the false sensation of privacy

#234
post #16

> Their adblocker is just a fork of uBlock Origin, This does not appear to be true. Here is the github repo for their open source adblock engine written in rust: https://github.com/brave/adblock-rust Here is a (somewhat dated) article describing it by the authors: https://brave.com/improved-ad-blocker-performance/ > Google will take decisions that benefit their advertisement business, like making impossible to use ad…

There are more lies in that article. This one for example is so often repeated but untrue:

> Rewards is their shitty program that will replace ads displayed on websites with their own.

Brave doesn't replace ads with their own. Brave ads are displayed as desktop pop-ups. They can also be easily disabled (which, surprise, the author doesn't mention because of his bias). And the idea behind Brave ads is to give you tokens which are then distributed to the content creators you engaged with. This is the default setting. Their idea is not to shovel you with ads or offer you "get rich with crypto" schemes. Idea is to block ads but still provide revenue to the content, based on how many users engage with that content.

When I see people saying "Brave replaces ads with their own" I have to wonder if they have tried using Brave themselves before writing these critique articles.

Re: Brave, the false sensation of privacy

#235
post #200

Earlier quoted context omitted.

I mean more like not just the data transfer layer, but the whole cell telephony baseband firmware enables privileged access to your phone. This can be the entry vector for multiple exploits that go way below the application layer. E2E encrypt is meaningless at this level.

> but the whole cell telephony baseband firmware enables privileged access to your phone This is very outdated, at least for a significant number of smartphones (including all iPhones, but not limited just to those). Apple and IIRC other manufacturers long since isolated the baseband, treating it simply as a standard USB or PCIe peripheral (and in the latter case using an IOMMU with it amongst other things). It has z…

^ This. Prior to Apple, the phone OEMs and carriers had hooks all into your baseband firmware for all kinds of things; firmware updates, CALEA hooks, automatic provisioning, etc...

Source - used to certify these things in a lab environment.

Re: Brave, the false sensation of privacy

#236

Earlier quoted context omitted.

You could pay for ad-free YouTube, if you dislike the ads so much. Many argue that "They'll pay to have ads removed", but that doesn't seem to hold true when services offers that exact option.

> Many seem to argue that "They'll pay to have ads removed", but that doesn't seem to hold true when services offers that exact option. I would pay for ad free Youtube, if it was an option. Even with Youtube Premium, included promotions continue to be shown

That’s interesting, maybe that’s market/country dependent. I pay for Premium and haven’t seen and ad or promotion since I signed up.

That really not okay when you actually pay to have no ads.

Re: Brave, the false sensation of privacy

#237
post #26

The people arguing that Firefox has an edge because it maintains a separate browser engine (like the writer of this article) are going to have real difficulties making their argument. Ditto the attacks on Brave for not being private enough. The people who care about privacy should be more worried about getting caught in Google's web of properties than about privacy per-se - that company is bad news. And Firefox is mo…

>It doesn't matter much when the engines involved are BSD license vs GPL

Without a competing engine, Google is free to cease development on Chromium and start a new private fork, and autoupdate all Chrome browsers to that new fork. Then they can add all sorts of web features that only they support. Every browser dependent on Chromium will fall behind in security updates and web features, and become more unusable than Firefox is today.

Re: Brave, the false sensation of privacy

#238

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

The entire blog reads like a conspiracy theory 4chan /g/ fever dream

Re: Brave, the false sensation of privacy

#239

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

> But I really dislike the author’s strident writing style. Colorful and emotional language gets attention. Dispassionate writing doesn't. Whenever I see people criticize an author for a little rhetorical flair, I play the famous "Pirates of the Caribbean" scene in my mind: Hacker News: "Your article is the most strident and obnoxious piece of technical writing I've ever heard of" Author: "Ah, but you have heard of i…

I think this is a popular narrative, but I don't think it's true. Especially in HN, some of the best articles I can remember aren't angry people being obnoxious, but can even be highly-technical and entirely dispassionate.

Also, I am not sure people do remember these types of articles. Perhaps they remember some notion of the content, but I'm doubtful many detractors would remember the author.

Re: Brave, the false sensation of privacy

#240

Earlier quoted context omitted.

That draft is referring to the operation of their own DNS servers, not messing with third-party DNS.

"... except in reasonable and justifiable cases where a user has been placed into a so-called "walled garden" for reasons of abuse, security compromise, account non-payment, new service activation, etc." Their own words

What's your issue with that? In that scenario, the user doesn't even have Internet access. If they didn't force the DNS to specific servers, the user would only see that their service isn't working with no indication as to what's going on. It's clearly not something they do with normal, functional users and I never said that they didn't have the capability to do it.
Post reply on HN