Live data from Hacker News

Goodbye Brave

arunmozhi.in

181–190 of 252 posts

Re: Goodbye Brave

#181
post #5

I think this is due to Brave proxying some Google requests through their own servers, because otherwise the same people would complain that a Google server is being contacted. > I am thinking of going back to [Chromium] with the usual extensions like Ghostery, AdBlock+ > [Brave's] amazing ad-blocking and tracker protection If you just need an adblocker, sure. At this point everone should have heard of uBlock Origin.

Serious question, why not Firefox? If open source and freedom of the web is important using Firefox is the best option.

For me:

- Doesn't come with a built-in ad blocker, so have to install a 3rd party plugin (I don't want to install any extension into my browsers) - Mozilla upper management have been making terrible decisions for the last 5+ years. By not using Firefox I'm sending a message (I used to give $$ to Mozilla) - Firefox keeps having features removed (RSS, FTP, etc), and gimping the UI.

It's not much to ask to have these 3 things improved, at which point I'd move back to Firefox from Brave.

Re: Goodbye Brave

#182
post #21
post #14

I cannot understand why technically savvy people keep using spywares like Brave ( https://spyware.neocities.org/articles/brave.html ) or Chrome ( https://spyware.neocities.org/articles/chrome.html ) when we have better alternatives such as Vivaldi ( https://spyware.neocities.org/articles/vivaldi.html ) or Firefox ( https://spyware.neocities.org/guides/firefox.html )

Got conned by BAT and have a growing sentiment that by continuing to use Brave, I'm enabling the company to make back the advertising earnings promised; I refuse to do KYC to redeem them.

KYC is only required (by law, with which Brave must comply) for those wishing to cash-out (or deposit their own) BAT (into or out of the Rewards Wallet). No KYC is required for the use of Brave's general-purpose "Brave Wallet". Also, no KYC is required for users who wish to earn BAT (via Brave's privacy-respecting Ads) and use said BAT to support content creators.

Sampson (Brave Team)

Re: Goodbye Brave

#183
post #42

Earlier quoted context omitted.

Unfortunately I still see too many people use Adblock plus and the like which leads me to believe ublock origin lacks some sort of name or brand recognition with your average user

on a fresh install of FF, if I click on extensions it shows AdBlock± as the first in a list of suggested add-ons. Also in that list is Ghostery. no sign of UBlock Pay for placement?

I haven't looked at the recommended add-on page for a while but I do recall ublock being on there at one point.

Re: Goodbye Brave

#184
post #168

Earlier quoted context omitted.

Don't forget to enable IPv6 and WebRTC.

As far as I am aware ipv6 and webrtc are privacy regressions, so one should enable them only if necessary.

How is IPv6, a protocol that is superior to the IPv4 mess we have come up with to cope with the fact that 32 bits aren't enough to represent each unique computer, a privacy regression? Is the end-to-end principle of the internet a privacy regression too?

Re: Goodbye Brave

#185
post #14

I cannot understand why technically savvy people keep using spywares like Brave ( https://spyware.neocities.org/articles/brave.html ) or Chrome ( https://spyware.neocities.org/articles/chrome.html ) when we have better alternatives such as Vivaldi ( https://spyware.neocities.org/articles/vivaldi.html ) or Firefox ( https://spyware.neocities.org/guides/firefox.html )

Interesting spyware website, thanks. I see that some of the stuff that I saw on Reddit is actually true. I’ve stopped using Brave for about 6 months now, so far so good.rn I’m on chromium. One of the reasons why I also quit this was because some problems with their rewards crypto programs. Basically, this content creator Tom Scott, makes great videos, tweeted some stuff about Brave explaining the issue. He says that…

The claim that Brave is spyware is bogus; see https://twitter.com/BraveSampson/status/1348400822925856770 for a point-by-point response. Best to get privacy and security insights from reliable, competent sources (e.g. https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf).

The issues mentioned by Tom Scott (from December of 2018) were wholly unrelated to security or privacy, and instead serve as a case-study in UI/UX and messaging. Allow me to explain a bit in greater detail.

Brave held a token sale in 2017 which resulted in 300 million BAT being added to a User Growth Pool. In 2018 we invited Brave users to direct BAT grants (that is, BAT belonging to Brave) to their favorite content creators. Some users expressed a desire to support Tom Scott (as they should; his content is phenomenal).

Brave's UI explicitly marked verified creators as such, but made no explicit indication when a creator was unverified (we followed a similar model to Twitter, which gives checkmarks only to verified accounts). This resulted in some confusion among our users about whether or not Tom was a verified creator.

Some users chose to direct BAT (again, from Brave's own User Growth Pool) to Tom's YouTube account. At the time, this BAT would migrate from the UGP through to a Settlement Wallet, waiting to be collected by the creator. Again, we're talking about BAT from Brave's own wallet--no user funds involved.

After listening to Tom's feedback over Twitter, Brave took action and made a series of prompt changes. For starters, we began to explicitly identify unverified creators as such (not doing so was a naïve design decision on our part). Secondly, we modified the contribution model such that Brave (the browser) would not send tips to any unverified creator (that is, no BAT would go into a settlement wallet). Instead, issued tips now remain in the user's control for up to 90 days while the browser routinely checks to see if the intended recipient has verified.

We blogged about these changes at the time: https://brave.com/rewards-update/. We made these changes in fewer than 48 hours, IIRC. Tom's feedback was excellent, and resulted in a substantially better tipping model in Brave. Of these changes, Tom shared on Twitter "These are good changes, and they fix the complaints I had!".

I hope this helps!

Sampson (Brave Team)

Re: Goodbye Brave

#186
post #2

Seems a little ironic to call out a piece of software whose literal job it is to connect to the internet for... Connecting to the internet. Tongue in cheek aside, I don't know much about Brave - is there some specific reason that it needs an always-on server to call home to?

The user attempted to install an extension; this results in a request to Google's Servers (which Brave proxies to prevent users from making unintended contact with Google). If Brave's proxy happened to return a 401 response (requesting authentication), then the user would see the "Access Denied" message shown in their screenshot. It's also possible that this message could have come from Google's own server (via the Brave proxy). It's not possible to tell from the data available.

We're looking into this from our end, to see if there were any recent proxy-interruptions which might explain the user's experience.

Sampson (Brave Team)

Re: Goodbye Brave

#187
post #154

Emphasis mine in the below quote: > "Arunmozhi is a freelance programmer and an open-source enthusiast." I'm surprised, shocked and dumfounded that Firefox is not even mentioned while Vivaldi and Chromium are being considered. For someone who put up with Brave for years and its other issues, it really seems strange that Firefox is not in consideration.

He’s an open source enthusiast, not an idiot.

You're a GamerGate Enthusiast, an AntiVaxer, a Climate Change Denier, a Troll, and an Idiot.

Re: Goodbye Brave

#188
post #168

Earlier quoted context omitted.

As far as I am aware ipv6 and webrtc are privacy regressions, so one should enable them only if necessary.

How is IPv6, a protocol that is superior to the IPv4 mess we have come up with to cope with the fact that 32 bits aren't enough to represent each unique computer, a privacy regression? Is the end-to-end principle of the internet a privacy regression too?

IPv6 enables insane precission of device tracking. A side effect of not having enough ipv4 addresses and using NAT is that all your home devices let's say, go out on the internet using only a single IP address. Also, the geo-location accuracy using ipv4 is at the level of a city. With ipv6 you can get to a geolocation accuracy of a building block and confidently target individual devices within ones home network since they will use unique ipv6 addresses.

Surely, privacy minded people will find a way around those, but out of the box ipv6 is a privacy regression for the reasons listed above

Re: Goodbye Brave

#189

I am still using Brave, but I am immensely bothered by them forcing us into using their own wallets (out of deals they make, None uses Uphold! except forced by Brave) instead of any decentralized option. Then constant bugs when paying out BAT rewards, causing you to lose them, but never refunds you.

Uphold (and Gemini) are required only for those who wish to KYC. Brave cannot act as a funnel for unchecked funds between large advertisers (e.g. Walmart, Amazon, Coinbase, etc.) and anonymous external wallets. If a user wishes to "cash out," Brave must comply with relevant AML laws and regulations. Note, this requirement only exists for uses who wish to "cash out" or deposit their own BAT, and only for the Brave Rew…

Hmm I understand. Some launchpads are using external KYC systems allowing for verification while using Metamask. I wish something like that would be possible.

Lost funds weren't much to bother with. It was just, I had disabled "automatically pay to creators" option on all my devices, but I saw a transaction go out. Then I checked on reddit, and some other people had similar issues.

I will still keep using Brave, no worries. I think it is a good project nevertheless. My complaints are more just small pet-peeves, no biggie. Keep up the good work. Thanks

Re: Goodbye Brave

#190
post #188

Earlier quoted context omitted.

How is IPv6, a protocol that is superior to the IPv4 mess we have come up with to cope with the fact that 32 bits aren't enough to represent each unique computer, a privacy regression? Is the end-to-end principle of the internet a privacy regression too?

IPv6 enables insane precission of device tracking. A side effect of not having enough ipv4 addresses and using NAT is that all your home devices let's say, go out on the internet using only a single IP address. Also, the geo-location accuracy using ipv4 is at the level of a city. With ipv6 you can get to a geolocation accuracy of a building block and confidently target individual devices within ones home network sinc…

>IPv6 enables insane precission of device tracking. A side effect of not having enough ipv4 addresses and using NAT is that all your home devices let's say, go out on the internet using only a single IP address

Use random addresses, no further words needed. If you are actually that paranoid, feel free to use stateless translation to change the host part of the IP.

>Also, the geo-location accuracy using ipv4 is at the level of a city. With ipv6 you can get to a geolocation accuracy of a building block and confidently target individual devices within ones home network since they will use

Unless your ISP is announcing unique /48s of individual building block, no. If your home router gets a static IPv4 address, the same problem prevails, not relevant.

>Surely, privacy minded people will find a way around those, but out of the box ipv6 is a privacy regression for the reasons listed above

Out of the box IPv6 offers the same privacy regressions as the original IPv4 before we fucked it to high hell. NAPT is a royal pain for any P2P protocol.

Post reply on HN