Live data from Hacker News

Brave, the false sensation of privacy

ebin.city

411–420 of 501 posts

Re: Brave, the false sensation of privacy

#411

Earlier quoted context omitted.

If the ISP is checking for DNS lookup of speed test websites, then allocating higher bandwidth to the connection for a brief period of time? Or, somehow more cynically, the ISP makes money from selling the data collected from DNS, so punishes people who use a different DNS provider. (DNS is plaintext-by-default, so I don't quite see how this would work, but it's possible.) Or perhaps the system uses DNS lookups as a…

Your first example would be dead simple to detect and take advantage of to get those boosted speeds all the time. Your other two examples are a bit wild.

The first example is a real-life example. The other two are speculative, because I've heard a case where it wasn't the first example.

Re: Brave, the false sensation of privacy

#412

Earlier quoted context omitted.

That was a pretty rapid shift from "Comcast isn't doing anything to your DNS" to "So what if they are? There are times when they should!"

Yeah, wow I guess I should have included the caveat "Comcast isn't doing anything to your DNS... except when you literally don't have Internet access and couldn't reach a third-party DNS server anyway"

If you wanted to be honest you could have said "I have literally no idea what Comcast is doing with DNS, but I will attempt rationalizing everything they do as I am gradually informed of it"

Re: Brave, the false sensation of privacy

#413
post #33
post #27

FF + uorigin + a dns blocker like pihole seems to be where it’s at right now. Maybe EFF privacy badger on top Any better options out there? Been thinking of adding protonvpn

FF now does DNS over HTTPS by default (Preferences > General > Network Settings), it defaults to using NextDNS and is configurable. Some people will be uncomfortable with this default, but it's a step up from consumer ISPs who _will_ track you, to a 3rd party who Mozilla says wont. I add Mullvad VPN (because wiregaurd is frickin awesome), which also allows you to use their DNS servers, but for this you actually have…

>FF now does DNS over HTTPS by default

Just checked & mine was off. Not that I mind since it's supposed to hit the local pihole anyway

Re: Brave, the false sensation of privacy

#414
post #20

Earlier quoted context omitted.

I think your anger is misplaced - you should be angry at government who requires Brave (and eBay, and Etsy, and any company that is paying out money to people) to require this. If this wasn’t legally required they (and every other company) wouldn’t do it.

Brave, Inc has no requirement to be located in the US that does require these laws, hardly the fault of the government they are choosing to be incorporated under that Brave chooses that particular geographical position, especially since the US probably has some of the worst examples in recent history for disregarding the privacy of citizens and non-citizens alike.

I'm pretty sure the US government is notorious for enforcing its financial laws well beyond its borders.

Re: Brave, the false sensation of privacy

#415

I find Brave Rewards very egregious. You get lots of BAT and the marketing copy hypes it up immensely without mentioning, anywhere, that you need to provide your SSN and Driver's License to a third-party (Uphold) if you actually, you know, want to cash out. This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided y…

This is the law; it's not Brave's design. Our design enables you to opt-in, earn, and give to content creators without having to provide any information. The law, however, requires and compels Brave to add KYC into the mix when you wish to self-fund or cash out. Anti-money laundering is not something we can or would circumvent.

[deleted]

Re: Brave, the false sensation of privacy

#416
post #309

Earlier quoted context omitted.

It's a personal website, not a corporate blog. Why does it have to be dispassionate? The tone is strident, but there are no personal attacks or abusive language used.

Huh? I’m not saying there should be a law. I’m just saying I think it would be more effective and persuasive if it was more dispassionate. It’s my personal opinion.

OK, thanks for the clarification. I misunderstood your earlier comment.

Re: Brave, the false sensation of privacy

#417

Earlier quoted context omitted.

I recently did a 5 minute video on the history of digital advertising, with an introduction to Brave's model: https://youtu.be/LsrrT502luI . Per https://brave.com/rewards and https://creators.brave.com , users opt-in to Brave Rewards and begin participating with privacy-preserving Ads. Each ad nets you, the user, 70% of the associated revenue. Rewards come in the form of BAT, which moves more easily and comes with co…

I understand that money goes in through the advertisers: But how is that money sufficient to maintain the current websites? You watch fewer ads than before, which means (if the ads pay the same) that each website gets on average (i.e. if the split is the same as before) less money. As you describe it, only 70% of the ad-revenue actually reaches the user, meaning even if you watch the same amount of ads, websites get…

This step in the chain of progress may require people to adapt to the idea of making less money in exchange for a healthier web.

Re: Brave, the false sensation of privacy

#418

Earlier quoted context omitted.

A regional catalog is downloaded routinely. The only "data" going out is your region (e.g. the United States). This returns a protobuf catalog of ads for your region. Your device privately studies this catalog for relevant entries. When an ad is shown, it's presented as a native notification on the OS. This means the user sees a title (text), and a body (text). Screenshots of these notifications are on https://brave.…

> The only "data" going out is your region (e.g. the United States). Every request Brave makes "home" will transfer private data like IP address of the user and browser fingerprint, regardless of the payload. Can you clarify what is done with this data? Also if it is true what says in the article that some requests "home" can not be disabled, why is that the case?

> private data like IP address of the user and browser fingerprint

Presumably it would send the same data whenever it checks for software updates too.

I can't think of a threat model where downloading updates and downloading ads are different in terms of user privacy (except, of course, that a malicious update can do far more harm).

Re: Brave, the false sensation of privacy

#419
post #16

> Their adblocker is just a fork of uBlock Origin, This does not appear to be true. Here is the github repo for their open source adblock engine written in rust: https://github.com/brave/adblock-rust Here is a (somewhat dated) article describing it by the authors: https://brave.com/improved-ad-blocker-performance/ > Google will take decisions that benefit their advertisement business, like making impossible to use ad…

The Epic Privacy Browser Team is integrating uBlock into Epic in their next update and didn't find a significant degradation in performance from any Chrome limitations, nor a significant performance improvement in Brave's implementation.

Epic's mobile browsers were built on Brave/Chromium, but now that Brave has endpoint and other dependencies as mentioned it doesn't explain, it isn't possible to continue to build on them or even test them since Brave features don't work in outsider builds.

Re: Brave, the false sensation of privacy

#420
post #26

The people arguing that Firefox has an edge because it maintains a separate browser engine (like the writer of this article) are going to have real difficulties making their argument. Ditto the attacks on Brave for not being private enough. The people who care about privacy should be more worried about getting caught in Google's web of properties than about privacy per-se - that company is bad news. And Firefox is mo…

>It doesn't matter much when the engines involved are BSD license vs GPL Without a competing engine, Google is free to cease development on Chromium and start a new private fork, and autoupdate all Chrome browsers to that new fork. Then they can add all sorts of web features that only they support. Every browser dependent on Chromium will fall behind in security updates and web features, and become more unusable than…

If Google did that, we'd be better off with the Mozilla corporation taking over Chromium development than continuing to develop Gecko.

The erosion of interest in Firefox over the years raises a pretty basic question: if Google followed through with that scenario, how effective would Firefox be? They're got steamrolled in the last decade with massive amounts of funding (from Google).

Brave is literally showing that if someone wants to compete with Google, they're going to start with chromium as a base. Your argument is similar to "if someone wants to compete with Google, they need to be able to use Gecko/Webkit!". People with skin in the game are saying whatever the theoretical merits are to your argument, it is wrong. Gecko isn't part of the competitive equation any more.

Post reply on HN