Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

441–450 of 501 posts

Re: Brave, the false sensation of privacy

#441

Earlier quoted context omitted.

How does it report the ad was viewed?

When the notification pops on screen, you are granted the rewards. If your OS is not able to show the notification (due to Focus Assist, DND, or some other reason) then you are not rewarded (a future update to Brave will let users control visibility from within the browser entirely).

I believe the question was about the mechanism by which you viewing the ad is reported to Brave, not how the ad display was implemented. (A weird interpretation of "reported".)

Re: Brave, the false sensation of privacy

#442

Earlier quoted context omitted.

I don't really care about brave either way, it's just dubious that the ads are somehow untrackable when you apparently get credit for seeing them some how?

We use zero-knowledge proofs and blinded tokens to track when an ad has been viewed by a user. But there is no user data involved here. The magic of cryptography is that you can prove you viewed the ad without telling us anything about you

Ah, I hadn't noticed you declaring your financial interest before and was wondering if you were a Brave employee.

Re: Brave, the false sensation of privacy

#443
post #427

Earlier quoted context omitted.

We use zero-knowledge proofs and blinded tokens to track when an ad has been viewed by a user. But there is no user data involved here. The magic of cryptography is that you can prove you viewed the ad without telling us anything about you

Do you have any reading material about how you achieved this? I can't really see how zero-knowledge proofs could solve this. There is no cryptographic way to prove that software executing on a clients machine triggered a notification. Especially on Linux where an open source notification manager could be modified to reject it.

Assuming you have gone through this [0] and it did(n't) click for you.

I'm equally not so convinced on this anonymous ad system they claim to have built. The browser claims to generate an adID based on your history but encrypt this info to the advertiser. Maybe someone who has actually interacted with the ad platform can provide more insight on what information is exposed.

Zero-knowledge advertising sounds practically like an oxymoron to me, but hey they claim to have made it work.

[0] https://brave.com/themis/

Re: Brave, the false sensation of privacy

#444

Earlier quoted context omitted.

How are IPs "not much"? I get that you mean that they don't see the requests and responses themselves, but you can easily infer interests, life events, other particularities from the request targets and the timings alone.

I mean, 95% of those IPs are just going to be some Cloudflare CDN anyway, right? I think you'd be hard-pressed to infer much real info from them.

Maybe then mask the hosting provider's identity, but surely the different websites have different IPs? Also, there are easily accessible services that aggregate info like this, and also keep record of past IP changes, like SecurityTrails.

Re: Brave, the false sensation of privacy

#445

Earlier quoted context omitted.

> The only "data" going out is your region (e.g. the United States). Every request Brave makes "home" will transfer private data like IP address of the user and browser fingerprint, regardless of the payload. Can you clarify what is done with this data? Also if it is true what says in the article that some requests "home" can not be disabled, why is that the case?

What browser fingerprint are you seeing in your research? I don't believe Leith et al found any such issue in their review at https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf , nor did I in https://brave.com/popular-browsers-first-run/ . I'm happy to discuss any requests you like; we also document all of this to the best of our ability on GitHub as well ( https://github.com/brave/brave-browser/wiki ). As f…

Thanks for the attempt to clarify. My question was, what do you do with the IP address of the user that you get through these “phone-home” requests and I think it is left unanswered?

> We've worked hard to keep them to a minimal.

How is 80 requests minimal? (source: your own above-mentioned article). It seems to me that 0 requests would be minimal.

What is preventing Brave from being a zero-telemetry browser by default?

Re: Brave, the false sensation of privacy

#446

I appreciate articles that look into topics in some depth that I’m curious about. But I really dislike the author’s strident writing style. Now, if there’s a single exaggeration or untruth from the author, It’ll throw the rest of the article in doubt for me. I think it would be better if it was a bit more dispassionate. Another thing I’ve noticed in security (and I actually work in this field) is that if a project ma…

Is the writing very strident? To me it didn’t really come across as such, though I guess standards differ when it comes to largely technical writing compared with other types of writing (e.g. on politics).

Re: Brave, the false sensation of privacy

#447
post #434
post #426

Earlier quoted context omitted.

Browser vendors can carry small patches against Chromium but significant changes are very costly to carry long-term as the code changes under you. Furthermore, Google controls how heavy that burden is for you. In practice browser vendors who choose Chromium don't challenge Google's Web platform decisions except in very narrow cases like FLoC. In contrast Mozilla and Apple examine every Google-proposed Web platform fe…

> Browser vendors can carry small patches against Chromium but significant changes are very costly to carry long-term as the code changes under you. Furthermore, Google controls how heavy that burden is for you. This is fundamentally wrong; at any point anyone can hard fork chromium and then the long term costs of maintenance and rate of code change are completely out of Google's control. > In practice browser vendor…

No-one is going to hard-fork Chromium. The reason you adopt Chromium is because you don't want to pay to maintain your own browser engine.

Re: Brave, the false sensation of privacy

#448
post #447
post #434

Earlier quoted context omitted.

> Browser vendors can carry small patches against Chromium but significant changes are very costly to carry long-term as the code changes under you. Furthermore, Google controls how heavy that burden is for you. This is fundamentally wrong; at any point anyone can hard fork chromium and then the long term costs of maintenance and rate of code change are completely out of Google's control. > In practice browser vendor…

No-one is going to hard-fork Chromium. The reason you adopt Chromium is because you don't want to pay to maintain your own browser engine.

> The reason you adopt Chromium is because you don't want to pay to maintain your own browser engine.

Same argument applies to Gecko, but if people want to get in to the web browser game it makes a lot more sense to start with a de-facto open standard - which is Chromium. There are already a lot of browsers based on that engine, which is apparently named Blink according to Wikipedia, with backers who could easily choose to maintain an engine if they wanted to.

If the world ends in 12 months then sure, no-one is going to fork Chromium. But in the future, at some point Google will start doing a bad job maintaining it and Chromium could well be forked. If someone decides they need a browser engine to maintain full time they're probably going to fork Chromium as the technically strongest starting point and start maintaining a branch themselves. Forking Gecko would get them ... not much useful. Maybe some PR points.

The Blink license says people can fork it. There isn't any legal or technical reason that it is unforkable. At some point, it will be forked.

Re: Brave, the false sensation of privacy

#449

Earlier quoted context omitted.

I recently did a 5 minute video on the history of digital advertising, with an introduction to Brave's model: https://youtu.be/LsrrT502luI . Per https://brave.com/rewards and https://creators.brave.com , users opt-in to Brave Rewards and begin participating with privacy-preserving Ads. Each ad nets you, the user, 70% of the associated revenue. Rewards come in the form of BAT, which moves more easily and comes with co…

I understand that money goes in through the advertisers: But how is that money sufficient to maintain the current websites? You watch fewer ads than before, which means (if the ads pay the same) that each website gets on average (i.e. if the split is the same as before) less money. As you describe it, only 70% of the ad-revenue actually reaches the user, meaning even if you watch the same amount of ads, websites get…

if user buy BAT directly than distribute to the content creator, the story sounds similar to likecoin

Re: Brave, the false sensation of privacy

#450

Earlier quoted context omitted.

Ah, OK. I didn't realize verisign did that too. Comcast followed not long after... https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red...

Comcast used to do a lot of messed up stuff. As I mentioned in a comment somewhere close to here, I've been a customer long enough to have seen those bad days and how they've managed to change since those days.

Have they really though? They still do DNS hijacking and bandwidth caps and speed boost for a few seconds only and automatic price increases and worthless bundles and such, don't they? They were so bad they had to rename to Xfilthy or something but their practices didn't really change as far as I can tell. What are some examples of things they've improved?

That's aside from all the political shenanigans they pull, trying to kill municipal broadband and net neutrality. There's scarcely a more evil ISP.

I switched away from Comcast as quickly as I could, and never had trouble with either smaller cable companies or fiber providers.

Post reply on HN