Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

251–260 of 501 posts

Re: Brave, the false sensation of privacy

#252
post #234

Earlier quoted context omitted.

There are more lies in that article. This one for example is so often repeated but untrue: > Rewards is their shitty program that will replace ads displayed on websites with their own. Brave doesn't replace ads with their own. Brave ads are displayed as desktop pop-ups. They can also be easily disabled (which, surprise, the author doesn't mention because of his bias). And the idea behind Brave ads is to give you toke…

To play devil advocate. On one side, Brave come with an adblocker that will remove any ads from the website you're visiting. On the other, they provide their own ads through the reward program. So it can be seen as "replacing website ads by its own". I approve that line of reasoning, but I think that what the author meant.

You can disable seeing ads in settings though. if you choose to see ads however, the website doesn't get anything, you get crypto from it.

Re: Brave, the false sensation of privacy

#253
post #100

Earlier quoted context omitted.

The recommendation of _The UNIX and Linux System Administration Handbook_ is a good one. As far as Comcast, I'm stuck with them, too. At least in my experience, they don't monkey with DNS - I run and use my own DNS servers, and have never seen interference. They do run deep packet inspection, and if they detect you, for instance, torrenting commercial media, they'll inject scary messages in port 80 traffic. Given tha…

Curious: how can they detect whether you're torrenting commercial media if you've enabled Bittorrent protocol encryption? Surely all they can see then is the outer (envelope) of the packets...?

Bittorrent trackers by design have a list of all IPs in the swarm and give to anyone who asks (that's how peers coordinate).

Re: Brave, the false sensation of privacy

#254

Another shady practice: you could donate to any website, but Brave itself received the amount if not claimed by the website creator. Users did not know. ( https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br... , https://redd.it/a8g1i9 ) Don't use Brave. Tell others not to use it.

Brave can't send BAT to a site that doesn't accept BAT. For example, HN doesn't. When I click on the BAT icon, the first thing I see is a message saying the tokens will remain in my wallet until the site accepts my tip.

This is now how it used to work - which is why the OP uses “could” instead of “can” - see the linked article.

Re: Brave, the false sensation of privacy

#255

> brave-core-ext.s3.brave.com fetches 5 extensions and installs them. It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities. Okay, so which 5 extensions? There has to be more information on this somewhere. Article seems kind of lazy and definitely loses steam after the second half.

Well... There's a more serious first start browser comparison by netmeister.org [0] which shows that 4 downloads are made.

I downloaded and extracted the files. They look like helpers or partials for Brave internal extensions.

All of them include manifest files with their names:

- 1_0_14: "Brave HTTPS Everywhere Updater extension". Contains a 1MB ZIPped database of https domains.

- 1_0_21: "Brave NTP sponsored images component". Contains three photos (to display in their new tab probably).

- 1_0_22: "Brave Local Data Files Updater extension". Seems to contain whitelists and blacklists for extensions, autoplay, referers, trackers, etc.

- 1_0_498: "Brave Ad Block Updater extension". Contains a 2.4 MB filter list for their adblocker implementation.

Nothing seems to be harmful at all. This mechanism is used by almost all Chrome/Chromium based browsers to update their internal extensions and components.

But, if the poster cares about backdoors... Well, every major browser out there has features that could be used to backdoor their users like Firefox Telemetry Experiments (which download xpi files) and Chrome Components. They also can change properties at will unless its disabled (via flags, about:config, recompiling, etc).

Note: I'm a Vivaldi and Chromium user. I only use Brave with iOS which is kind of a different beast (since everything has to be implemented on top of iOS provided WebKit) since it somehow blocks ads better than stock Safari with AdGuard filters. For stuff like banking (on iOS) I use Safari.

Note 2: Blink and WebKit have deviated quite dramatically so they are indeed different browser engines (like Gecko is) with different implementations, quirks and bugs.

[0] https://www.netmeister.org/blog/browser-startup.html

Re: Brave, the false sensation of privacy

#256
post #19
post #13

I don't like the crypto nonsense of Brave, and while I like Firefox in theory, its performance leaves a lot to be desired and they don't seem to know who their user base is. Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.

> its performance leaves a lot to be desired I'm not sure what you're talking about; this may be the case several times in the past, but you should check again because this is a thing that constantly changes. Firefox performance today doesn't really leave a lot to be desired IMO > Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge! Tree Style Tabs has been around since like… 2007?. Or d…

Tree Style Tabs has been pretty limited since the port to WebExtensions. It can no longer take the place of the existing tab bar, and instead sits alongside it unless you do some Firefox profile CSS trickery that I never got working properly. Mozilla was considering adding a "hide tab bar" feature but I think they abandoned that.

Re: Brave, the false sensation of privacy

#257

Earlier quoted context omitted.

"... except in reasonable and justifiable cases where a user has been placed into a so-called "walled garden" for reasons of abuse, security compromise, account non-payment, new service activation, etc." Their own words

What's your issue with that? In that scenario, the user doesn't even have Internet access. If they didn't force the DNS to specific servers, the user would only see that their service isn't working with no indication as to what's going on. It's clearly not something they do with normal, functional users and I never said that they didn't have the capability to do it.

That was a pretty rapid shift from "Comcast isn't doing anything to your DNS" to "So what if they are? There are times when they should!"

Re: Brave, the false sensation of privacy

#258
A rebuttal of the points in the article, as most of it is arguing in bad faith:

> Brave's adblocker is uBlock origin

It's not[1].

> Brave Today can't be disabled

Currently called "Brave News" if you're looking for it. And of course it actually can be disabled[2].

> Rewards is used to track you

A request being made to a URL does not mean you are being "tracked". Brave ads are the most privacy-preserving ad architecture[3] I know about, and they are the only people trying to make a better funding model for the web that still has a lot of the upsides of ad-driven content (mainly that it is not a regressive funding model). FF is worse in this regard because Mozilla gets most of their revenue from adtech giants that clearly don't give a flying fuck about your privacy. If you think Mozilla's funding model isn't a conflict of interest and makes the web more privacy-conscious, I have a bridge to sell you.

> Telemetry automatically violates your privacy

Not really? Of course, someone very concerned with privacy should opt out of telemetry, and Brave lets you do that.

> Auto-updates violate privacy

How so? As I point out later, the most likely result of auto-updates is that they help preserve your privacy by getting bugs patched faster.

> Affiliate codes

Yes, Brave had pre-programmed history items that were affiliate links to a crypto exchange. This harmed nobody in any way and the backlash was over-the-top. But they disabled in response to user feedback. I kinda liked this idea, as it is another way Brave was trying to fund themselves without being beholden to the Googlopoly which is an endeavor I very much support (with the caveat that it can't hurt users, which again this did not).

> Uphold doesn't care about your privacy

Uphold is a financial institution based in the US (as Brave is) which by necessity needs to comply with KYC/AML regulations. That means they need to collect your personal info. Take it up with the US government if you're unhappy.

> Tor tabs leaking DNS

Was fixed fairly quickly[4] and I think worth pointing out that no other browser even bothers trying to do something like this (integrating Tor for better privacy). Conveniently left out of the part where the author made the claim that "Brave isn't better for privacy than FF because it's just uBlock origin". Clearly brave is trying things that are not just adblocking to increase user privacy.

In general with this point, kinda funny that apparently the author of this article wants Brave to be the only software engineering org in existence that never has bugs. I guess if that's your stance though it makes sense that you wouldn't want auto-updates. For everyone else that lives in reality, auto-updates are a good thing for security (and therefore privacy, as made clear here when a privacy-related bug inevitably happens).

> Chromium and Google’s monopoly

Yeahhhhh, using FF isn't the silver bullet you think it is, as again, Mozilla gets the vast majority of their revenue from being paid by Google. What happens if that dries up? Seems unlikely that maintaining Blink without Mozilla will be easier than Brave maintaining a privacy-centric fork of Chromium (which will presumably continue to get not-privacy-related upstream improvements from Google/Microsoft/etc in perpetuity).

> brave-core-ext.s3.brave.com fetches 5 extensions and installs them. It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities.

This is worse than all the Bitcoin maximalists / shitcoin pump-and-dumpers with their "this is not financial advice" shtick. We know what you're doing, it's pretty transparent. Especially when you do it twice:

> They were also accused of theft with BAT but this isn’t verifiable so I’ll only link the source for you.

In summary, I disagree with basically all of this article, significant parts of which are just factually wrong.

[1] https://github.com/brave/adblock-rust

[2] https://support.brave.com/hc/en-us/articles/360056341952-How...

[3] https://brave.com/intro-to-brave-ads/

[4] https://github.com/brave/brave-browser/issues/13527

Re: Brave, the false sensation of privacy

#259
post #172

Earlier quoted context omitted.

Curious: how can they detect whether you're torrenting commercial media if you've enabled Bittorrent protocol encryption? Surely all they can see then is the outer (envelope) of the packets...?

This is a bit of a misconception. Copyright holders have always gone after seeders based on people connecting to swarms, tracker info, and crawling DHT. There’s no reason to use DPI when the list of uploaders is just given out by trackers and DHT for free. See: https://www.usenix.org/legacy/event/woot10/tech/full_papers/...

You're right that is how it generally operates, but in the case of Comcast I think this meme doesn't want to die because in the late 00s Comcast really did do DPI to interfere with torrents: https://www.techdirt.com/articles/20071029/020756.shtml

Fairly googleable with "Comcast sandvine". Afaik they haven't done anything like that for years, though.

Re: Brave, the false sensation of privacy

#260

Earlier quoted context omitted.

do we need randomized dom nodes ?

I guess I'd have to hear more details to know exactly what you're thinking, but my first instinct is to say that doing something like that would break CSS and accessibility without actually offering any significant impediment to tracking.

I was mostly wondering about privacy up to the dom layer (if that's even possible)
Post reply on HN