Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

431–440 of 501 posts

Re: Brave, the false sensation of privacy

#431
post #367

Earlier quoted context omitted.

kyc laws only applies to exchanges that allow cashing out. I don't understand why kyc would be required here. The browser user should be the miner getting a reward as a private key. They should be able to move it to any exchange (this is where kyc is required) or trade privately. Why they chose to implement the design in this way is not what I would expect.

> kyc laws only applies to exchanges that allow cashing out. I don't understand why kyc would be required here. Because cashing out is kind of the entire point of BAT? If creators couldn't redeem their BATs for actual spendable currency, they wouldn't really be any different from a Facebook Like button that people have to pay to click.

People sell their redditor accounts frequently for their digital tokens (upvotes) - reddit does not require people to use KYC.

Yes, I understand there is an implicit difference here, but this just shows how dumb KYC laws are to begin with as they can be easily bypassed by criminals and serve only to dox the law abiding citizens.

I, as a pro-social, well behaving, net positive contributor to society - have to trust everyone I do business with with my personal information. It's honestly absurd, if I were a criminal I would bypass this with great ease, yet because I want to behave legally I put myself at risk for identity theft frequently just to be able to do business with other people who also likely don't want to be responsible for securing my private information.

Re: Brave, the false sensation of privacy

#432

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

This is the law; it's not Brave's design. Our design enables you to opt-in, earn, and give to content creators without having to provide any information. The law, however, requires and compels Brave to add KYC into the mix when you wish to self-fund or cash out. Anti-money laundering is not something we can or would circumvent.

Lol. This is like Tesla saying regulations prevent them from releasing full self driving. Don't advertise something you can't deliver.

Re: Brave, the false sensation of privacy

#434
post #426
post #177

Earlier quoted context omitted.

It is open source. If someone doesn't like a decision they can fork the codebase. Mozilla's Gecko has been beaten down to sub-double-digit market share, they're less relevant right now than when IE6 was >75% of the market. They have no power to influence the direction the web moves in. And yet life is going on better than ever. If you want a counterbalance to stop Google making the important decisions, Firefox has fa…

Browser vendors can carry small patches against Chromium but significant changes are very costly to carry long-term as the code changes under you. Furthermore, Google controls how heavy that burden is for you. In practice browser vendors who choose Chromium don't challenge Google's Web platform decisions except in very narrow cases like FLoC. In contrast Mozilla and Apple examine every Google-proposed Web platform fe…

> Browser vendors can carry small patches against Chromium but significant changes are very costly to carry long-term as the code changes under you. Furthermore, Google controls how heavy that burden is for you.

This is fundamentally wrong; at any point anyone can hard fork chromium and then the long term costs of maintenance and rate of code change are completely out of Google's control.

> In practice browser vendors...

This is because Google generally makes great choices with Chrome that don't need to be second guessed. One of the reasons for Chrome's ubiquity is Google makes a great browser.

Re: Brave, the false sensation of privacy

#435
post #200

Earlier quoted context omitted.

> but the whole cell telephony baseband firmware enables privileged access to your phone This is very outdated, at least for a significant number of smartphones (including all iPhones, but not limited just to those). Apple and IIRC other manufacturers long since isolated the baseband, treating it simply as a standard USB or PCIe peripheral (and in the latter case using an IOMMU with it amongst other things). It has z…

^ This. Prior to Apple, the phone OEMs and carriers had hooks all into your baseband firmware for all kinds of things; firmware updates, CALEA hooks, automatic provisioning, etc... Source - used to certify these things in a lab environment.

That's great to know. I'd like to feel reassured but I'm sure there's new exploits somewhere, the carrier level i think is just so attractive to large scale actors. Any internet links to read up on this, and on the next generation of possible carrier level exploit vectors?

Re: Brave, the false sensation of privacy

#436
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

I only know enough about networking to be dangerous but I am convinced Comcast is doing shady shit with my modem when I change the DNS settings to use non-Comcast servers. Every once in a while I’ll attempt to use Wireshark to try to make sense of what’s happening but I’m pretty clueless and don’t really know what I’m looking at/for. If anyone knows any good resources to learn about the ISP nuts and bolts that make i…

I'm getting this second hand, but I've heard that some isps will redirect dns traffic to their servers based on it going to port 53.

Re: Brave, the false sensation of privacy

#437

Earlier quoted context omitted.

So... I dunno... Just ignore the whole BAT/Rewards nonsense? I use none of that shit, though I do use Brave for a (very) few things that require a Chrome-like browser (i.e. Won't work in Firefox with my battery of plugins). I don't regard it primarily as a high-privacy tool (FF is better at that, though far from perfect) but it's better than using Chrome on non-Goog sites. Ah, the world has become a strange place. I…

Isn’t this only an issue if you actually want to cash out your $2 or whatever. The bigger benefit of Brave is that you can contribute money to websites or content creators that your prefer. This is like the “old” internet where ads didn’t care what content they were shown next to, giving much more freedom of expression on the net. Say YouTube thought your video joking about COVID meant they thought you deserved to de…

You can’t cash $2. There’s a 25 BAT minimum

Re: Brave, the false sensation of privacy

#438

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

> But I really dislike the author’s strident writing style. Colorful and emotional language gets attention. Dispassionate writing doesn't. Whenever I see people criticize an author for a little rhetorical flair, I play the famous "Pirates of the Caribbean" scene in my mind: Hacker News: "Your article is the most strident and obnoxious piece of technical writing I've ever heard of" Author: "Ah, but you have heard of i…

this is one of the major problems with the current media landscape. all publicity is good publicity. look at Trump. look at the Paul brothers. HN is one of the few safe harbours from that. personally, I’d like to keep it that way

Re: Brave, the false sensation of privacy

#439
post #239

Earlier quoted context omitted.

> But I really dislike the author’s strident writing style. Colorful and emotional language gets attention. Dispassionate writing doesn't. Whenever I see people criticize an author for a little rhetorical flair, I play the famous "Pirates of the Caribbean" scene in my mind: Hacker News: "Your article is the most strident and obnoxious piece of technical writing I've ever heard of" Author: "Ah, but you have heard of i…

I think this is a popular narrative, but I don't think it's true. Especially in HN, some of the best articles I can remember aren't angry people being obnoxious, but can even be highly-technical and entirely dispassionate. Also, I am not sure people do remember these types of articles. Perhaps they remember some notion of the content, but I'm doubtful many detractors would remember the author.

my ideal article tells me everything I need to know in simple language, without meander or emotion. that’s rare even here

Re: Brave, the false sensation of privacy

#440
post #419
post #16

> Their adblocker is just a fork of uBlock Origin, This does not appear to be true. Here is the github repo for their open source adblock engine written in rust: https://github.com/brave/adblock-rust Here is a (somewhat dated) article describing it by the authors: https://brave.com/improved-ad-blocker-performance/ > Google will take decisions that benefit their advertisement business, like making impossible to use ad…

The Epic Privacy Browser Team is integrating uBlock into Epic in their next update and didn't find a significant degradation in performance from any Chrome limitations, nor a significant performance improvement in Brave's implementation. Epic's mobile browsers were built on Brave/Chromium, but now that Brave has endpoint and other dependencies as mentioned it doesn't explain, it isn't possible to continue to build on…

> HTML filtering is the ability to filter the response body of HTML documents before it is parsed by the browser.

> For example, this allows the removal of specific tags in HTML documents before they are parsed and executed by the browser, something not possible in a reliable manner in other browsers. This feature requires the webRequest.filterResponseData() API, currently only available in Firefox.

https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b... I'm going to trust Gorhill on this one. If a significant feature _does not exist_ in Epic then the only way that it couldn't hurt performance is if it was somehow useless. I suspect the Epic people (accidentally?) didn't measure that aspect.

Post reply on HN