Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

401–410 of 501 posts

Re: Brave, the false sensation of privacy

#401
post #331

Earlier quoted context omitted.

Same here. I've also had Brendan Eich respond to one of my posts on HN - not something I'd expect from any other browser on the market. He understands techies because he is one. I wish Mozilla was headed by a techie and not a lawyer :(

Reminder that there's a reason Brendan Eich doesn't work for Mozilla anymore, and it's not just layoffs due to dwindling userbases. Half of their board stepped down when he was about to be appointed. Decoupling software from the people behind it may be a good thing, but I don't want to support people that work against my interests.

This doesn't remind me of anything. Your comment is just innuendo.

Re: Brave, the false sensation of privacy

#402

Earlier quoted context omitted.

That was a pretty rapid shift from "Comcast isn't doing anything to your DNS" to "So what if they are? There are times when they should!"

Yeah, wow I guess I should have included the caveat "Comcast isn't doing anything to your DNS... except when you literally don't have Internet access and couldn't reach a third-party DNS server anyway"

[deleted]

Re: Brave, the false sensation of privacy

#403
The Epic Privacy Browser is still the best if you want a Chromium-based privacy browser. Brave cloned them anyway and added their crypto and reduced the privacy. Firefox isn't recommended for privacy, though TOR is of course very good for anonymity, but Epic is better for everyday use.

Re: Brave, the false sensation of privacy

#404

Earlier quoted context omitted.

Almost everything is SSL-secured now. There's not very much an ISP can snoop on. DNS lookups and IP addresses, I guess.

How are IPs "not much"? I get that you mean that they don't see the requests and responses themselves, but you can easily infer interests, life events, other particularities from the request targets and the timings alone.

I mean, 95% of those IPs are just going to be some Cloudflare CDN anyway, right? I think you'd be hard-pressed to infer much real info from them.

Re: Brave, the false sensation of privacy

#406

Earlier quoted context omitted.

These are all smart thoughts but you’ve clearly never worked for or with an ISP. As business entities in general they don’t have that kind of technical sophistication. They are more on the level of “we have to hire these vendor consultant groups to install VMs for us” than “we build a crawler so that we can use domain plus byte count to drink-anonymize visited pages.”

BT (a UK ISP) were up to hijinks in 2008 - "BT and Phorm: how an online privacy scandal unfolded" https://www.telegraph.co.uk/technology/news/8438461/BT-and-P...

Yes. The problem for them is that times have changed.

Re: Brave, the false sensation of privacy

#407

Earlier quoted context omitted.

These are all smart thoughts but you’ve clearly never worked for or with an ISP. As business entities in general they don’t have that kind of technical sophistication. They are more on the level of “we have to hire these vendor consultant groups to install VMs for us” than “we build a crawler so that we can use domain plus byte count to drink-anonymize visited pages.”

It doesn’t matter that most of them might not be that capable. They just hoard this data and sell it to the people with the means and resources.

It's not that easy to hoard when you have less than one competent engineer in the company and have to contract out to some vendor to build the data lake where they can hoard it.

Hoarding itself is beyond the sophistication of most service providers in the present day.

Re: Brave, the false sensation of privacy

#408

Earlier quoted context omitted.

The other great thing is, in case you wanted to support Mozilla, the MozillaVPN is using Mullvad's service, and routinely provides great service. I will add though, if you're a huge privacy advocate, and don't want to supply your email or card details to Mozilla but want to use a VPN, Mullvad directly is still the best choice imo.

I use Mozilla VPN, but the program (Ubuntu 20.04) 1+ times per day just closes and it does not have a network kill switch. So I have to continue to use Firefox's DoH to prevent my university to occasionally take a peek at my traffic. Assuming they don't bother reversing IPs to domain names.

You don't need a "network kill switch" with wiregaurd, you might be using the openVPN option which mullvad also provide for compatibility. Because wiregaurd is stateless you don't have to worry about stuff leaking through while physical layers go up and down, you can just leave the wg interface up and keep hoping around safely... I literally haven't taken my current wg connection down in days, yet my computer is put to sleep every night.

If you use Linux you don't even need an app (not Firefox's or Mullvad's), you can just pop one of the wiregaurd configs (mullvad.net can generate them for you) into /etc/wiregaurd and then use the super simple wg-quick cli interface to bring it up. You can also tell systemd to bring up a specific interface at startup with one line.

Re: Brave, the false sensation of privacy

#409

Earlier quoted context omitted.

I still don't really get how brave is supposed to work: You watch significantly fewer ads than before, these ads are then supplied to whoever you yourself engage with. That seems like watching these fewer ads directly on the site, just with a few hoops in between. The difference is that now you watch fewer ads in total, and you have the Brave-browser as an inbetween, which also somehow has to survive. This means that…

I recently did a 5 minute video on the history of digital advertising, with an introduction to Brave's model: https://youtu.be/LsrrT502luI . Per https://brave.com/rewards and https://creators.brave.com , users opt-in to Brave Rewards and begin participating with privacy-preserving Ads. Each ad nets you, the user, 70% of the associated revenue. Rewards come in the form of BAT, which moves more easily and comes with co…

I understand that money goes in through the advertisers: But how is that money sufficient to maintain the current websites?

You watch fewer ads than before, which means (if the ads pay the same) that each website gets on average (i.e. if the split is the same as before) less money. As you describe it, only 70% of the ad-revenue actually reaches the user, meaning even if you watch the same amount of ads, websites get 30% less money, and that ignores that many people just opt-out of ads. (BTW do you know where that 30% go to?)

> The blockchain enables users to effortlessly and anonymously participate.

That actually makes sense. But if you want to get money out of BAT, don't you have to pay a transaction fee? And if you don't, then how does Uphold make any money to pay their developers?

For me it seems that there's money vanishing at every point and very little or nothing to replace it.

Also, wouldn't brave have a quasi-monopoly on ads in this configuration? Even if brave is an honorable company (and I have no reason to doubt that), it makes me uneasy to know that we are breeding another potential "too-big-to-fail" giant like Facebook/Amazon/Google.

Edit:

Rereading your comment again and noticing the "users can distributed bought BAT directly" part: Then the monetization system makes a little more sense. Do you have stats on how much people are paying in? Is the ultimate goal to get rid of ads entirely or at least shift over to a "pay for what you use" model? In that case I can understand that. (though the monopoly on website monetization part still makes me kind of uneasy)

Re: Brave, the false sensation of privacy

#410

Earlier quoted context omitted.

I use brave and rewards but have never cashed out so didn’t provide any KYC info. I just donate BAT to sites. Brave does “request info up front” for users who want to use the wallet. Requesting it from users who won’t need it is a waste of time. All Robinhood users perform financial transactions, very few Brave users do.

Is the lack of other options to send micropayments to sites the reason you do this? If there was a way to one click send micropayments to sites from a browser that did not require you to watch ads, but you send your own money, would you do it?

Honestly it’s because I’ve never had enough tokens to qualify for the minimum. So I just leave stuff in my wallet and transfer every once in a while.

I would prefer a wallet that I have control over, but I kind of ignore the BAT stuff and just use it because it’s a clean browser that’s easier for me than managing adblocker plug-ins. The tokens are just a bonus.

Post reply on HN