Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

261–270 of 501 posts

Re: Brave, the false sensation of privacy

#261
From the German Wikipedia:

> On March 3, 2021, Brave announced that it had acquired search engine technology from the former browser manufacturer Cliqz for its own search engine, Brave Search. The former owner, the German publishing house Hubert Burda Media, has held shares in Brave since then.

Hubert Burda Media is a traditional publisher, owner of well known German publications as well as hardware stores. They also own XING, which is the German version of LinkedIn which nearby everybody uses here.

Hubert Burda was the president of the VDZ (=Verband Deutscher Zeitschriftenverleger, Association of German Magazine Publishers), so it's safe to assume that he is against internet user privacy.

I'm not sure if they are able to legally access user data through this "partnership" with Brave.

Re: Brave, the false sensation of privacy

#263
I would love to use something other than brave but Firefox is shit and arguably getting worse over time. They have been sacrificing ux for revenue streams for a while now. Also extension management is a joke, especially if you have more than 5 extensions.

I have like 30 chrome extensions... Most of which get used at least weekly. Many of them do things like prevent sites from blocking text select or copy paste, things like that. I believe extensions are the mechanism of agency that enables a browser to be an "user agent" again.

Re: Brave, the false sensation of privacy

#264
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

ISPs have perfect knowledge of your IP, so if they can get even basic traffic logs from _anything else_ can reconstruct your browsing history more accurately than any other third-party. Since you are probably visiting your ISP's site regularly to pay your bill, there are also a lot of possibilities for them to regularly associate third-party cookies with your login. They also have the highest-quality ambient location data (outside of explicit app permissions) to link with all of that.

Re: Brave, the false sensation of privacy

#265

Earlier quoted context omitted.

I find it funny that people say this when this is pretty much exactly what FLOC is - the browser choosing your interests and deciding which interests to send to the ad server - but without the "show ads on every website and hold the profits from website owners until they claim it".

> deciding which interests to send to the ad server I was looking at their media kit[0]. They link to a presentation[1] which mentions that the ads are sent to the browser and then the browser itself picks the ones that should be shown to the user. If this is really the case, then the browser isn't sending that information to the ad server. [0] https://brave.com/brave-ads/assets/Brave_Media_Kit.pdf [1] https://www.yo…

This wouldn’t work for an ad network as big as Google’s, and would further centralize who can serve ads to users (something Google can’t get away with like Brave can).

Re: Brave, the false sensation of privacy

#266
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

You can encrypt your DNS lookups with several different services.

Re: Brave, the false sensation of privacy

#267

Earlier quoted context omitted.

Lots of people are pointing out that this isn't the case anymore , but the fact is that it used to work this way, and they only changed it after backlash. That was enough to turn me off of Brave forever.

Yeah, I too dislike it when companies respond positively in response to criticism. I prefer the orgs I interact with to be perfect and never make mistakes and when they do (but they don't because I only interact with perfect institutions) I prefer them to double-down instead of improve.

Your hyperbole seems to be purposefully taking the parent post in bad faith.

He is expressing skepticism towards their original intentions and you like how they responded. No need to talk past each other.

Re: Brave, the false sensation of privacy

#268

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

I have been testing Brave for some time and i have not received lot of BAT since using it, i can summarize in few words but Brave are so cheap on paying BAT at the cost of giving you ads. For privacy better stick with Firefox or LibreWolf and earn crypto somewhere else.

Re: Brave, the false sensation of privacy

#269
post #53

Earlier quoted context omitted.

TLSv1.2 traffic contains the hostname of the site you're connecting to, and the list of ciphers. This can be fingerprinted to identify your browser, and the server-side software. [1] TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing... [1] https://engineering.salesforce.com/tls-…

> TLSv1.3 on the other hand encrypts the hostname (eSNI) eSNI is not the default behavior, and has few deployments at scale. TLSv1.3 transmits SNI in the clear. eSNI is being replaced with ECH[1], but in many cases, there is a 1:1 relation between the IP address and the site being served. ESNI and ECH are only one layer of obfuscation - a middleman (such as an ISP) could still snoop your DNS (unless DoH/DoT) and/or c…

Right. The actual improvement from TLS 1.2 to TLS 1.3 in this respect is that in TLS 1.2 the certificate was in the clear.

Encrypted Client Hello isn't finished. I would say the basic idea is settled, but there are plenty of technical nits and it might be next year before they have a final document.

Eventually the idea is that ECH will be GREASEd by always sending ECH data, if the client knows it is supported it will use ECH and if not then it will fill out the ECH data with random nonsense. Since it's encrypted, an adversary can't easily distinguish one from the other and a site which doesn't offer ECH will ignore the nonsense anyway.

The idea of probing servers on port 443 works well enough for dozens of popular sites with dedicated servers, but much less well for the long tail. A bulk host won't give you a list of every customer just because you hit port 443 on each server and pled ignorance, you'll get a generic "Under construction" page and no information.

Re: Brave, the false sensation of privacy

#270

Earlier quoted context omitted.

Yeah, I too dislike it when companies respond positively in response to criticism. I prefer the orgs I interact with to be perfect and never make mistakes and when they do (but they don't because I only interact with perfect institutions) I prefer them to double-down instead of improve.

Your hyperbole seems to be purposefully taking the parent post in bad faith. He is expressing skepticism towards their original intentions and you like how they responded. No need to talk past each other.

I don't agree. GC cannot speak to their intentions, so at the end of the day this is just holding them to a standard that it is unreasonable to ever hold any institution to. Humans make mistakes and organizations are comprised of humans. What matters is how they address such mistakes, which I've only seen positive improvement from Brave.
Post reply on HN