Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

341–350 of 501 posts

Re: Brave, the false sensation of privacy

#341
post #234

Earlier quoted context omitted.

There are more lies in that article. This one for example is so often repeated but untrue: > Rewards is their shitty program that will replace ads displayed on websites with their own. Brave doesn't replace ads with their own. Brave ads are displayed as desktop pop-ups. They can also be easily disabled (which, surprise, the author doesn't mention because of his bias). And the idea behind Brave ads is to give you toke…

I still don't really get how brave is supposed to work: You watch significantly fewer ads than before, these ads are then supplied to whoever you yourself engage with. That seems like watching these fewer ads directly on the site, just with a few hoops in between. The difference is that now you watch fewer ads in total, and you have the Brave-browser as an inbetween, which also somehow has to survive. This means that…

I think the idea is this:

- Most people won't paypal/patreon/send money directly

- The current system uses ads as a shorthand for attention. If you're able to get attention you get more ad traction and more money.

- Ads suck and are a corrupting influence on everything, if there was a way to directly award attention without ads that would be better.

- Brave replaces ads by tracking attention directly and attempting to reward it directly with BATs. These is done instead of cash because (I'm not really sure why) - I suspect because it's easier to manage and easier to split into tiny amounts.

- Flattr from the late 2000s (2007?) was similar, but with cash (Flattr = Flat Rate) the idea being you'd put in $XX/month and it'd distribute it depending on what pages you viewed. It was created by some of the Pirate Bay founders iirc. It never got much traction.

The issues I have with these services:

- Ads are bad, but the attention economy is the underlying problem. Removing ads is good, but still incentivizing attention for $$ isn't great.

- In the case of 'privacy' Brave has now inserted themselves as the tracker of all attention, this is very high risk and not a lot better than the ad companies. Sure you don't see ads but a lot of the bad slot machine incentives around content remain.

- I don't want to necessarily pay everyone based on what I view, what if what captures my attention is crap? What if I'm reading something for context, but don't support it?

---

I get what they're trying to do, reward people without ads and without making users pay - but I'd rather the ad model just die and if some businesses can't survive without it we probably don't need them. I recognize this isn't super realistic because companies compete on a global stage.

A business truly operating in the interest of users would make a browser that had ad blocking built in without tracking - and worked on subverting ads full time (what users actually want). This includes real privacy by not being a new middle man tracking attention. Apple is the closest to doing stuff like this with their new onion router VPN, making it easy to block tracking from apps in the store, etc.

Brave pretends its interest is privacy and browser users, but it feels like a rationalization to me. Brave's core business is attention tracking and taking a cut of that, if not now - when they have more power. Its user's attention is what they monetize - those incentives don't lead some place good.

Re: Brave, the false sensation of privacy

#342

Earlier quoted context omitted.

I think people are misremembering or misunderstanding a recent controversy where Brave was adding their own affiliate links to the user's browsing session without the user's knowledge or consent: https://www.coindesk.com/brave-browsers-affiliate-link-contr...

I don't think this is it because the article has a separate section about affiliate link controversy.

These points had been true at some point though... Also, brave is constantly astroturfing, so you should always take whatever you read online with a grain of salt.

I used brave's android browser a long time ago as well (at that time these claims were true - but they didn't replace the ads on all pages). I cannot speak about whats the current situation however, as I'm not up to date on the topic.

Re: Brave, the false sensation of privacy

#343
post #339

German c't magazine tested all the main browsers in terms of privacy in the latest issue. Brave came out on top by a large margin. They even discovered that Edge sends a list of visited sites while in private browsing mode back to Microsoft! I've heard some negative things about Brave but i'm willing to give it a try now because it may just be noise. I can imagine the advertising industry being very motivated to keep…

You should also try Vivaldi[0] if you're already shopping around. Once Firefox went belly-up last week I needed a new browser, and Vivaldi made the cut for me. They publish their source code and do a great job of stripping the Google features out of Chrome.

[0] https://vivaldi.com

Re: Brave, the false sensation of privacy

#344

Earlier quoted context omitted.

Actually, I have heard that claim more than once, about various providers (up to, and including, “when I changed my DNS settings and the traffic slowed down, the tech got me to change them back, and the traffic sped up”). It's less common, I think, because more people know how to check their speed than change their DNS.

The only way I can think of that working is if the provider is intercepting DNS requests for popular speed tests to redirect to an internally-hosted version that would be faster. Otherwise, I can't think of any realistic way DNS settings can affect actual throughput.

If the ISP is checking for DNS lookup of speed test websites, then allocating higher bandwidth to the connection for a brief period of time?

Or, somehow more cynically, the ISP makes money from selling the data collected from DNS, so punishes people who use a different DNS provider. (DNS is plaintext-by-default, so I don't quite see how this would work, but it's possible.)

Or perhaps the system uses DNS lookups as a proxy for “is a human browsing the web”; if there aren't enough, it's clearly some kind of automated computer program that doesn't deserve internet access.

Re: Brave, the false sensation of privacy

#345

Earlier quoted context omitted.

Brave can't send BAT to a site that doesn't accept BAT. For example, HN doesn't. When I click on the BAT icon, the first thing I see is a message saying the tokens will remain in my wallet until the site accepts my tip.

This is now how it used to work - which is why the OP uses “could” instead of “can” - see the linked article.

The way it "used to work" was that Brave gave users BAT for using the Browser and Brave Payments (now Brave Rewards). The user could then visit a site/channel, and Brave would communicate if the property was verified or not (e.g. a verified property had a check-mark, and an unverified property did not). If you tipped a verified property, the BAT (as gift from Brave) would go to the creator's associated wallet. If the property was not verified, the BAT would go into a settlement wallet, awaiting the creator's registration. Again, this was Brave's BAT effectively being earmarked for a creator who had not yet verified. The feedback at the time from the community was that the UI/UX was confusing; indeed it was. We quickly modified the model, and today it is substantially better as a result. Unverified properties are now as explicitly identified as verified ones, and tips to the former are held on-device for up to 90 days.

Re: Brave, the false sensation of privacy

#346

Another shady practice: you could donate to any website, but Brave itself received the amount if not claimed by the website creator. Users did not know. ( https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br... , https://redd.it/a8g1i9 ) Don't use Brave. Tell others not to use it.

That's not true. If the website or user does not claim the rewards within 3 months it goes back to the user.

Correct. Tips and contributions to unverified properties remain [on the user's device] for up to 90 days. The browser will make routine attempts to send the tip through; if it fails to do so after 90 days those rewards are unlocked and can be given to another creator.

Re: Brave, the false sensation of privacy

#347
post #15

So I feel as if the author is missing the point. Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a…

The issue is that Brave's "point" is a self-defeating motive. It wants to rid the internet of ads by... creating more amicable ads? Furthermore, the proceeds from said ads almost never benefit the creators of the content, meaning that Brave has effectively created an ulterior economy adjacent to the internet. Great, just what we needed, Another Competing Standard.

Nobody in the ads industry wants this, and a good 90% of the privacy sector is watching Brave in horror. Creators will make less money and be exclusively paid in a fiat currency, which probably won't appeal to anyone either. If nobody can reconcile Brave's existence, it will always be a second-class citizen on the web, even if it is forked from Chrome.

Re: Brave, the false sensation of privacy

#348

Brave is a scam, but recommending palemoon or icecat a is (for different reasons) also a bad idea.

How exactly is Brave a scam? The author certainly couldn't argue this point (detailed response to their claims can be found here: https://news.ycombinator.com/item?id=27552530 ).

The fact that author's arguments are flawed (imo not all of them are) does not imply their claim is incorrect. A lot has been written on the topic Elsewhere, I'm sure you will be able to find some better explanations if you so desire.

Re: Brave, the false sensation of privacy

#349

Earlier quoted context omitted.

> So when it was pointed out that it's still a problem, they came up with a solution that I think strikes a good balance. Fair enough. To me, it couldn't have been more obvious that collecting "money" in creators' names and also misrepresenting that was Bad™. I'll try to be gracious and chalk this up to "lack of common sense" instead of "part of the evil plan".

Actually I'm less charitable than "lack of common sense" and chalk it up to hubris – I think what happened is that they couldn't really imagine why someone wouldn't want to accept donations from their viewers/consumers, regardless of source, and so just defaulted to collecting for everyone assuming everyone would love to hop on board the BAT train. This of course turned out not to be the case for various reasons and…

The BAT that was moving around at that time was from Brave. We allocated hundreds of millions of tokens back in 2017 to a User Growth Pool. We distributed tokens to users of the Brave Browser, and allowed them to send those tokens off to their favorite content creators. This is similar to how PayPal lets you email money to anybody, even if they aren't signed up on PayPal. Our thought here was that users could effectively earmark the BAT they received from us, and that creators could sign up and claim those tokens.

We identified verified creators as such, but didn't make the non-verified state as explicit. We largely followed a similar pattern to that of Twitter (checkmark for those who are verified, and nothing for those who aren't).

When you visited a YouTube channel, website, etc., we would show you the name and favicon for that resource in the tipping UI. In the case of some YouTube channels, the page name was just the YouTuber's name, and their favicon was a picture of their face.

The changes that Tom Scott and others suggested back in 2018 were ground-breaking. They helped us realize some naïve decisions in the UI/UX of the tipping process and more. We moved quickly to implement those changes (https://brave.com/rewards-update), and the entire system is now substantially better as a result. But there was never any ill-motive involved. We had BAT, and we wanted users to give it to their favorite creators. Tom Scott approved of the changes at the time, which was a nice way to wrap things up

Re: Brave, the false sensation of privacy

#350

Earlier quoted context omitted.

Actually, I have heard that claim more than once, about various providers (up to, and including, “when I changed my DNS settings and the traffic slowed down, the tech got me to change them back, and the traffic sped up”). It's less common, I think, because more people know how to check their speed than change their DNS.

The only way I can think of that working is if the provider is intercepting DNS requests for popular speed tests to redirect to an internally-hosted version that would be faster. Otherwise, I can't think of any realistic way DNS settings can affect actual throughput.

So, suppose I'm Huge Video Streaming Corp X, and I get a DNS request asking me for the address of my servers. Well I have over a thousand servers around the globe, which one do you need? Any of them would work, but you likely want the fast nearby one, right? So I can try to guess based on the IP address the query came from...

I know the best answer for a Comcast DNS server in New York is the server I physically installed in a New York Comcast rack, but when a public DNS server asks me from Paris, maybe I suggest a London server, 'cos that's pretty close to Paris, shame that New York isn't.

EDNS Client Subnet is a feature that lets a DNS server say OK, I'm asking on behalf of somebody from 10.20.30/24 and so my system can do the same trick with ECS. But doing this unwinds most of the privacy benefit of using a public service, so several famous public DNS servers explicitly do not use ECS.

Obviously the cheap bulk host used for some Single Serving site like "Is pizza rat mayor of New York yet?" isn't affected, that is only one server and it is wherever it is, but somebody like Netflix absolutely is affected by this because they have their machines close to the customers to deliver better performance and if they don't know where the customer is that inteferes.

QUIC has an optional feature called Connection Migration to help improve this, the remote server is like "Um, now that you're connected to www.example.com here in Glasgow, Scotland, I notice your IP address is from Tokyo, Japan, and this is just a suggestion, but maybe talk to my identical twin also named www.example.com in Tokyo, Japan for better performance? Here is the IP address to try"

Post reply on HN