Live data from Hacker News

Brave’s use of direct mailers

brave.com

141–150 of 172 posts

Re: Brave’s use of direct mailers

#141

I like Brave. But they always seem to be "asking forgiveness rather than permission".

Seems like their business model is at odds with their privacy goals.

Not at all. EDDM doesn't impact user privacy. Brave never sees any user data during this process.

Re: Brave’s use of direct mailers

#142

Earlier quoted context omitted.

That sounds like an unhealthy paranoia. Which seems more likely? The USPS is delivering spam mail against the wishes of the recipient (I still get spam mail weekly despite opting out) or a privacy-focused company is snooping on your devices to steal your personal info (so they can send you mailers?).

> or a privacy-focused company is snooping on your devices to steal your personal info (so they can send you mailers?) I never said that. I don't want Brave on my devices due to their past bad behavior: lying, stealing money from creators in their affiliate program, redirecting legitimate links to shady crypto sites, running a crypto pyramid scheme, and so on. This is just the latest in a long list of reasons not to…

Brave doesn't harvest or collect any user data; we explicitly requested that no names be printed on these mailers (which was the case prior to this recent batch). You're mistaken about the other issues as well (they are every bit as overblown and misrepresented as this present issue).

"Stealing money from creators" is quite misleading. When Brave held its token sale in 2017, we allocated 300M tokens to the User Growth Pool. Shortly thereafter we began staking Brave users with tokens to identify creators for whom they would like to offer support. Brave's UI showed a check-mark for verified creators, and nothing for unverified creators (we naively followed the Twitter model).

Some users took the BAT they received from Brave, and attempted to tip it to unverified creators (which landed those tokens in an omnibus settlement wallet). The UI/UX caused a great deal of confusion towards the end of 2018, leading to monumental feedback from several content creators, including Tom Scott of YouTube. Tom's insights gave us the direction we needed to overhaul the Rewards (called 'Payments' at the time) system in major ways. Ultimately, Tom approved of the changes. But note, no money was ever stolen from any creator. Additional details are provided in our 2018 blog post at https://brave.com/rewards-update/.

It was also never the case that Brave was "redirecting legitimate links to shady crypto sites," either. You're referring to our Partner and Affiliate Links in Suggested Sites. That is, if you typed "bitcoin" into the address bar, prior to any network activity, Brave could list (among other options) an affiliate link to binance.us. The user could then decide to visit the bitcoin-related property using Brave's affiliate link, or disregard the suggestion entirely. This feature is off by default in Brave today, but you can read more about it on our blog at https://brave.com/referral-codes-in-suggested-sites/.

Re: Brave’s use of direct mailers

#143

Wait what? I'm really confused about what was going on here, what was the nature of the alleged mistake, and why it was a mistake or bad.

Brave used an official USPS mass market program to distribute mailers. The USPS allows these mailers to be mailed to every address (by route) in a zip code. The USPS also allows you to filter by such things as "age, household size, and income" (again the route is the granular level), but there's no indication Brave used this filtering. To use the program, you have to print your own mailers. Naturally, the mailers hav…

We did communicate our desire to exclude names from mailers; you can see an example from last month at https://twitter.com/TravelTechGuy/status/1513965348177219588. Because we wish not to be exposed to any user data, our QA process ends prior to the stage where names would be printed. Once we learned names had been printed on a recent batch (a deviation from previous batches), we took prompt action to "halt and catch fire," so to speak.

Re: Brave’s use of direct mailers

#144
post #8

Quoted post unavailable.

They say they're using the USPS's EDDM tool, and they link to it in the post. I clicked, and skimmed until I found this: > Choose the neighborhoods in the EDDM Online Tool where your customers live. Use the tool to target customers by specific demographics such as age, household size, and income. So it seems like the database belongs to the government rather than the startup. It doesn't appear that this had any actua…

No privacy impact. Brave doesn't have any names or addresses; those are with the United States Postal Service (never exposed to Brave). We asked that names NOT be printed on these mailers. Previous batches went out without names, as intended. You can see an example of this from a Tweet last month: https://twitter.com/TravelTechGuy/status/1513965348177219588.

Re: Brave’s use of direct mailers

#145
post #19

Earlier quoted context omitted.

As far as I know, the database is owned by the USPS, and they can't do their job _without_ that information. You can dislike Brave for buying access to the information, or dislike USPS for selling said information. But the information is already collected by USPS so they can do their job.

Why can't they do their job without that information? You can send a letter to an address without the USPS a.) Having the address in their database b.) Knowing who is living there So Brave, the privacy company, is using a service that collects data about people.

Brave never has access to your information. We didn't use "a service that collects data about people," we used the EDDM offering of the United States Postal Service, which has legitimate claim to names and addresses. This service is attractive in part because it exposes no data to Brave in the process.

Re: Brave’s use of direct mailers

#146
post #75

Since the outside of all US mail is imaged and stored by the USPS and shared with other government agencies, [1] Brave just gave its user list to the US Government. [1] https://www.newsweek.com/postal-service-photographs-every-pi...

The names and addresses are with the USPS. Brave (hello, I'm a team engineer) used the EDDM offering of the United States Postal Service. We were attracted to this method of advertising in part because it never exposes sensitive information to us at Brave. User data, instead, is with the USPS, which has legitimate claim over such information. As stated in our blog post, we sent only the artwork (for the mailer itself), and the Zip Codes we aimed to reach. That's it. We also asked that names NOT be printed, which was the case for earlier batches (e.g. https://twitter.com/TravelTechGuy/status/1513965348177219588). I hope this helps!

Re: Brave’s use of direct mailers

#147

Earlier quoted context omitted.

USPS EDDM requires that you only put the area information (city, state, and zip code) and the EDDM label. The fact that this included actual addresses, much less names, is off. The only actual addresses that should be included are Do Not Deliver addresses. Something is fishy here. This doesn't seem to actually be through EDDM, but through some mailer vendor.

It's EDDM, and previous mailers lacked printed names. Our request to exclude printed names, while honored in the past, was not honored with a recent batch. Rather than brushing this off, we chose instead to investigate where the break-down in communication occurred, and share our findings in the blog post. Thankfully, this issue has no impact on user-data, privacy, or security. But it is definitely frustrating for us…

I don't understand why addresses are being used to begin with. They're not needed. You simply choose the route/zip code and the mailer will be dropped off at every mailbox on the route, hence the name "Every Door Direct Mailer". It's specifically to avoid using addresses.

This sounds more like a traditional direct mailer through a vendor rather than EDDM.

Re: Brave’s use of direct mailers

#148

I feel like the criticism towards Brave ITT is unjustified. This is a USPS service which is available to businesses. If you're a privacy conscious person in the US, you've likely opted out of this list. Brave is reaching the people who may not have done this, to the end of getting regular folks to know their alternatives against big tech companies. I guess don't get the ire, or what the expectation is for them to gro…

One of the foundations of privacy is that data sharing in any form should be opt-in, not opt-out.

Re: Brave’s use of direct mailers

#149
post #77
post #24

Earlier quoted context omitted.

Even if the database contains banding by household income for example? Why does the USPS need that to do their job? Brave doesn’t show what targeting was used…

The US Census is public record and breaks down all kinds of demographic information by zip code. The USPS is almost certainly just using census data. Even if they didn't provide the convenience, a marketer could easily replicate what they currently do. If you have a problem with the US Census Bureau collecting demographic data or making it public, those are certainly valid positions to hold. However, point your ire a…

You haven’t answered my point as to why the USPS needs this extra info to do their job?
Post reply on HN