Earlier quoted context omitted.
We use zero-knowledge proofs and blinded tokens to track when an ad has been viewed by a user. But there is no user data involved here. The magic of cryptography is that you can prove you viewed the ad without telling us anything about you
Do you have any reading material about how you achieved this? I can't really see how zero-knowledge proofs could solve this. There is no cryptographic way to prove that software executing on a clients machine triggered a notification. Especially on Linux where an open source notification manager could be modified to reject it.
Brave, the false sensation of privacy
461–470 of 501 posts
Re: Brave, the false sensation of privacy
#462Earlier quoted context omitted.
"…it’s important to say that Rewards uses Uphold…" The author then takes a jab at KYC, the process of confirming your identity by providing ID and other information. No user of Brave Rewards is required to do this. Users are able to opt-in, participate, earn, and pass along rewards to content creators and publishers. If a user wishes to "cash out," however, they do have to verify their identity in compliance with rel…
"It’s a concerning issue for a “privacy” oriented browser to connect to Cloudflare’s and Google’s domains, since both of them are telemetry." The author here is referring to proxied URLs, which were already addressed. They claim these are "telemetry," which is absurd. Telemetry is about understanding how users and products intersect. To suggest Brave is doing any telemetry here, or assisting Google/Cloudflare with Te…
Re: Brave, the false sensation of privacy
#463Earlier quoted context omitted.
Thanks for the attempt to clarify. My question was, what do you do with the IP address of the user that you get through these “phone-home” requests and I think it is left unanswered? > We've worked hard to keep them to a minimal. How is 80 requests minimal? (source: your own above-mentioned article). It seems to me that 0 requests would be minimal. What is preventing Brave from being a zero-telemetry browser by defau…
We drop the IP address. When needed, we'll convert it to a regional identifier (e.g. United States) so that we can have a count of how many users are in the US, UK, etc. I'm not sure where you saw 80 request; my network analysis post ( https://brave.com/popular-browsers-first-run/ ) shows Brave issuing 70 requests over a 10-minute period. Compare with Chrome (91 requests), Firefox (2,799 requests), Edge (367 requests…
>0 requests is not realistic, IMHO. When you launch a browser you want to make sure the user has a fresh local DB of known-malicious URLs (so you don't have to pipe each request through a look-up service, like Opera does) for client-side checking. You also want to make sure the client has an updated list of blocking rules for other types of content. There's quite a bit of setup needed when you launch a web browser.
It is quite realistic and possible. Both examples you gave can be opt-in. Perhaps I do not want my browser to arbitrarly show a malicious URL warning. Updating content blocker can and should be opt-in as well. Maybe particular rule set work well for my setup and I do not want the update to break it.And maybe I just do not want the browser to send requests home.
And even if both of these are enabled these should be just two requests - what is going on in the remaining 68? It just looks like a very high number even if it is smallest among other test browsers (which doesn't make Brave good, just makes every tested browser broken in this regard).
>Zero telemetry is unwise, assuming you want to build a product that works for a diverse set of users, devices, and environments.
This is based on what? You should really provide an argument when making a bold claim like this.Zero telemetry should be the corner-stone of any privacy respecting product. Only zero telemetry ensures and guarantees that user privacy will be 100% respected. Everything else, even sending just one unwanted request "home" or anywhere else, can and should raise valid questions about what is done with the data including IP address since this will be closed source even in an open-source browser like Brave.
Re: Brave, the false sensation of privacy
#464Earlier quoted context omitted.
Do you have any reading material about how you achieved this? I can't really see how zero-knowledge proofs could solve this. There is no cryptographic way to prove that software executing on a clients machine triggered a notification. Especially on Linux where an open source notification manager could be modified to reject it.
Certainly! Check out the resource detailing our Ad Confirmation process at https://github.com/brave/brave-browser/wiki/Security-and-pri... (it's a little old, but should be helpful). We leverage the Privacy Pass approach too, so reading https://www.petsymposium.org/2018/files/papers/issue3/popets... will also help understand our process. I hope this helps!
Re: Brave, the false sensation of privacy
#465Earlier quoted context omitted.
The difference with emailing money on PayPal is that the recipient is notified. Brave was collecting currency on behalf of people without even notifying them. Just because someone can collect the money/currency at a later date doesn't make it fine. If I collected money on behalf of charities yet only gave the money to the charity if they explicitly asked me for it, I doubt that would go down well with donors. I could…
You're missing one of the earliest points in my response; the tokens people were "sending" to creators [were from Brave]. We gave the user 5 BAT and asked them who they'd like to support with it. User's could pick a creator, and we would work on notifying that creator that [BAT from Brave had been directed towards them by Brave users]. All of that aside, the feedback from users around this time was phenomenal, and he…
Re: Brave, the false sensation of privacy
#466I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…
I have been testing Brave for some time and i have not received lot of BAT since using it, i can summarize in few words but Brave are so cheap on paying BAT at the cost of giving you ads. For privacy better stick with Firefox or LibreWolf and earn crypto somewhere else.
Re: Brave, the false sensation of privacy
#467Earlier quoted context omitted.
Brave is its own ad network and offers targeting to over 200 IAB categories. I don't agree that profiling my demographics and offering them up for sale is protecting my privacy, even if that does not include PII. If I want to skip out on Brave Ads then I don't really need the Brave browser.
You're going to have to help me understand how Brave's current ad model is at odds with protecting your privacy. Brave [does not] send any data to advertisers. That means no PII from the user, no meta data from the user, and no cohort ID or anything else for the user.
What about Brave itself? Brave Ads offers a lot of IAB advertising categories for sale to advertisers. If everything is pushed to the client and happens on the client, how does Brave Ads even know which IAB categories might be missing (and not exactly for sale in its network)? How would an advertiser know if/when an ad was even served?
The model still relies on assessing the folks that install Brave to know what you have to sell, and advertisers at least feeling like they are getting value from that advertising, most want some kind of measurable result. It would seem that some information is flowing back to Brave to allow for attribution and payments. Why do I trust anyone to hold this information? How can I know what happens to this information in the future? I can probably be deanonymized from Brave data.
Re: Brave, the false sensation of privacy
#468I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…
This is the law; it's not Brave's design. Our design enables you to opt-in, earn, and give to content creators without having to provide any information. The law, however, requires and compels Brave to add KYC into the mix when you wish to self-fund or cash out. Anti-money laundering is not something we can or would circumvent.
Re: Brave, the false sensation of privacy
#469Earlier quoted context omitted.
ISPs can see a lot, but it does have limits. As long as we're using SSL (and I suppose, assuming it hasn't been cracked), the ISP really only knows what domains I'm visiting. So they might know that I'm going to WebMD, but they don't necessarily know that I'm reading up on treatment options for nose fungus. They also don't necessarily know exactly which member of my household is going to that website, nor can they li…
ISPs have perfect knowledge of your IP, so if they can get even basic traffic logs from _anything else_ can reconstruct your browsing history more accurately than any other third-party. Since you are probably visiting your ISP's site regularly to pay your bill, there are also a lot of possibilities for them to regularly associate third-party cookies with your login. They also have the highest-quality ambient location…
Now they might think differently because there is a market for info. Thank you government...
Re: Brave, the false sensation of privacy
#470Earlier quoted context omitted.
You're missing one of the earliest points in my response; the tokens people were "sending" to creators [were from Brave]. We gave the user 5 BAT and asked them who they'd like to support with it. User's could pick a creator, and we would work on notifying that creator that [BAT from Brave had been directed towards them by Brave users]. All of that aside, the feedback from users around this time was phenomenal, and he…
Ah OK, I thought they were able to donate BAT they earnt from ads, that is definitely different. Still misleading, but better.