Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

451–460 of 501 posts

Re: Brave, the false sensation of privacy

#451

Earlier quoted context omitted.

I did test out Brave a while ago and the reward system was on by default. I had to go to the settings to turn it off, and in fact this option did not sync. So whenever I installed it on a new device I had to turn it off again, and I suspect that's deliberate. I also don't think that Google shares my information with third parties, pretty sure they say explicitly they don't do that. And as to Brave's model of pooling…

Brave Ads/Rewards is definitely OFF by default in Brave (I just double-checked, https://imgur.com/UIASmf4 ). You're invited to enable it during the Welcome screen, but it's off by default. If you install Brave today (make sure you don't have an old profile sitting around in %localappdata%/BraveSoftware/ already) and observe otherwise, that's a bug (please let us know). I think you're misunderstanding how Brave's anon…

It may be unrelated, but this blog post and the rather lively HN discussion made me install Brave for the first time.

Out of all chromes of Chrome I have sampled, Brave has the best visual polish. Best regards to your UI/UX design team.

Re: Brave, the false sensation of privacy

#452
post #298

Earlier quoted context omitted.

Brave ad blocker is written in Rust and browser extensions in JavaScript, so it should be faster

Not only faster, but we aren't beholden to the APIs offered by Google and others. Manifest v3 threatened the existence of popular content-blockers like uBlock Origin. Since we are the browser, we aren't so limited. A recent example of how we are able to do more was with the introduction of CNAME blocking, which allowed us to identify when a third-party tracker had managed to be requested from a first-party URL: https…

Hey, thanks. One of my favorite computers is a Surface 3 running a Cherry Trail CPU. I tried Brave out and it's noticeably snappier on the old hardware than Firefox or Chrome.

Re: Brave, the false sensation of privacy

#453

Earlier quoted context omitted.

I understand that money goes in through the advertisers: But how is that money sufficient to maintain the current websites? You watch fewer ads than before, which means (if the ads pay the same) that each website gets on average (i.e. if the split is the same as before) less money. As you describe it, only 70% of the ad-revenue actually reaches the user, meaning even if you watch the same amount of ads, websites get…

I think you're conflating the user with the publisher here; the user received 0% of the ad revenue in the past. With Brave, the user receives 70% of the ad revenue (the other 30% goes to Brave, which builds and maintains this apparatus). You're correct that publishers lose revenue when ads are blocked on their sites, but not blocking ads means users are at an increased risk of being abused by malicious third-party ac…

Even if a site made significant effort to have "non-malicious ads" I don't think brave would not block them with and put in their own.

I.e Brave is bootstrapping on manipulation of the intent of the publisher.

A cleaner aproch may be to approach publishers offer them a "better way" and decuple it from the browser marketing privacy / reduced ad load.

Likewise standards bodies, NGOs and Gov agencies need to protect users in the web and app ecosystems making it a more level in respecting user privacy / reduced harm. To control publisher / advertising / user relationship in a fair way.

But we live in a time of fast pace asymmetrical software mediated warfair and a few eggs are going to be cracked along the way in to trying to build something better.

Re: Brave, the false sensation of privacy

#454

Earlier quoted context omitted.

Do you have to download the chosen ad or is it already on your system? If you selectively downloaded ads, your ip address could give you away and you get a floc like situation

The ad catalog for your region is downloaded; it comes with click-through URLs, titles, body text, and some other information. There is no connection made beyond this to retrieve any other ad-related data. You can see what your own regional catalog contains by visiting https://sampson.codes/brave/ads/my_region/ .

Thanks for clarifying!

Re: Brave, the false sensation of privacy

#455
post #18

I always find it odd that we worry so much about how much our browsers are tracking us, but almost nothing about what our ISPs are doing. Every time I've looked into it, it seems much worse. As far as I can tell, ISPs are legally allowed to sell your browsing history to third parties: https://arstechnica.com/tech-policy/2017/03/for-sale-your-pr...

ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…

Oh not to mention, this might soon change as eSNI/ECH is adopted! Then the only information being leaked would be the IP address of the server. And with widespread use of CDNs nowadays would make the information collected pretty useless. Ofcourse that is if your DNS queries are not leaking everything. (which they are! Use DNS-over-HTTPs guys!)

Re: Brave, the false sensation of privacy

#456
post #429

Earlier quoted context omitted.

The BAT that was moving around at that time was from Brave. We allocated hundreds of millions of tokens back in 2017 to a User Growth Pool. We distributed tokens to users of the Brave Browser, and allowed them to send those tokens off to their favorite content creators. This is similar to how PayPal lets you email money to anybody, even if they aren't signed up on PayPal. Our thought here was that users could effecti…

The difference with emailing money on PayPal is that the recipient is notified. Brave was collecting currency on behalf of people without even notifying them. Just because someone can collect the money/currency at a later date doesn't make it fine. If I collected money on behalf of charities yet only gave the money to the charity if they explicitly asked me for it, I doubt that would go down well with donors. I could…

You're missing one of the earliest points in my response; the tokens people were "sending" to creators [were from Brave]. We gave the user 5 BAT and asked them who they'd like to support with it. User's could pick a creator, and we would work on notifying that creator that [BAT from Brave had been directed towards them by Brave users]. All of that aside, the feedback from users around this time was phenomenal, and helped us redesign the system into something substantially better.

Re: Brave, the false sensation of privacy

#457

Earlier quoted context omitted.

What browser fingerprint are you seeing in your research? I don't believe Leith et al found any such issue in their review at https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf , nor did I in https://brave.com/popular-browsers-first-run/ . I'm happy to discuss any requests you like; we also document all of this to the best of our ability on GitHub as well ( https://github.com/brave/brave-browser/wiki ). As f…

Thanks for the attempt to clarify. My question was, what do you do with the IP address of the user that you get through these “phone-home” requests and I think it is left unanswered? > We've worked hard to keep them to a minimal. How is 80 requests minimal? (source: your own above-mentioned article). It seems to me that 0 requests would be minimal. What is preventing Brave from being a zero-telemetry browser by defau…

We drop the IP address. When needed, we'll convert it to a regional identifier (e.g. United States) so that we can have a count of how many users are in the US, UK, etc.

I'm not sure where you saw 80 request; my network analysis post (https://brave.com/popular-browsers-first-run/) shows Brave issuing 70 requests over a 10-minute period. Compare with Chrome (91 requests), Firefox (2,799 requests), Edge (367 requests), and Opera (106 requests).

0 requests is not realistic, IMHO. When you launch a browser you want to make sure the user has a fresh local DB of known-malicious URLs (so you don't have to pipe each request through a look-up service, like Opera does) for client-side checking. You also want to make sure the client has an updated list of blocking rules for other types of content. There's quite a bit of setup needed when you launch a web browser.

Zero telemetry is unwise, assuming you want to build a product that works for a diverse set of users, devices, and environments. The main issue here is not whether you collect telemetry, but [how] you do so, and what that looks like. Brave is careful to preclude abuse from the design phase; see https://www.brave.com/p3a for more on how we handle Privacy-Preserving Product Analytics.

Re: Brave, the false sensation of privacy

#458
post #441

Earlier quoted context omitted.

When the notification pops on screen, you are granted the rewards. If your OS is not able to show the notification (due to Focus Assist, DND, or some other reason) then you are not rewarded (a future update to Brave will let users control visibility from within the browser entirely).

I believe the question was about the mechanism by which you viewing the ad is reported to Brave, not how the ad display was implemented. (A weird interpretation of "reported".)

Our Rewards server distributes virtual tokens to the instance of Brave (which has an associated Payment ID). These tokens can be exchanged when ad notifications have been viewed, and when other ad-related events occur. The tokens aren't tied to any user information.

Re: Brave, the false sensation of privacy

#459
post #453

Earlier quoted context omitted.

I think you're conflating the user with the publisher here; the user received 0% of the ad revenue in the past. With Brave, the user receives 70% of the ad revenue (the other 30% goes to Brave, which builds and maintains this apparatus). You're correct that publishers lose revenue when ads are blocked on their sites, but not blocking ads means users are at an increased risk of being abused by malicious third-party ac…

Even if a site made significant effort to have "non-malicious ads" I don't think brave would not block them with and put in their own. I.e Brave is bootstrapping on manipulation of the intent of the publisher. A cleaner aproch may be to approach publishers offer them a "better way" and decuple it from the browser marketing privacy / reduced ad load. Likewise standards bodies, NGOs and Gov agencies need to protect use…

Brave does not touch first-party ads; you can do all of the first-party advertising you like. Unfortunately, whether the third-party ads are malicious or not is not up to the publisher. The publisher is simply asked to add a bit of JavaScript to their page, and that's it.

Brave doesn't inject ads onto webpages; so there is no scenario where you (as a publisher) would have our ads displayed on your page (unless you, yourself displayed them).

Please see this 5-minute overview of the problems facing digital ads, and Brave's proposed model: https://youtu.be/LsrrT502luI

Re: Brave, the false sensation of privacy

#460

Earlier quoted context omitted.

"Brave's approach to funding is at odds with privacy." Elaborate, please. Brave's ad model is built for privacy and security. User's must first opt-in. Your data remains on your device. Ad catalogs are downloaded and reviewed locally. You are rewarded when you see an ad notification. I repeat, rewards are granted when your attention has been spent; no clicks necessary. I discussed the model further in this recent 5-m…

Brave is its own ad network and offers targeting to over 200 IAB categories. I don't agree that profiling my demographics and offering them up for sale is protecting my privacy, even if that does not include PII. If I want to skip out on Brave Ads then I don't really need the Brave browser.

You're going to have to help me understand how Brave's current ad model is at odds with protecting your privacy. Brave [does not] send any data to advertisers. That means no PII from the user, no meta data from the user, and no cohort ID or anything else for the user.
Post reply on HN