It looks like we are coming from two different sides of the table. So let's try to agree with this statement:
"A privacy respecting browser has no business sending data on its own anywhere without the user being OK with it first."
This is true by the very definition of what privacy is.
If you want to check for updates - let the user initiate/opt-into automatic updates. If you want to update your malicious domain list (is that useful at all?) - let the user initiate/opt-into it. And so forth.
If you want to make these choices on the behalf of the user, and enable this and other things you do in those 70 requests you do on startup - that is of course fine. But you lose the right to call yourself a privacy-respecting product because Brave client just sent data to Brave servers without user knowing/consenting to it.
> which also found Brave to be the "most private" browser tested
A statement like "Brave is most private of the tested browsers" implies that privacy is somehow an analogue measure between 0 and 1, where Brave is for example 0.6 and Chrome is 0.4 or something.
But privacy is a binary measure, you (company/product) are either respecting privacy of the user or you are not. You can not respect it 'a little'. You look at your friends the same way - one has propensity to leak information and the other one doesn't. There is no category for friends who leak 'a little' information. Either they do or they don't. And frankly being called 'most private' in the company of those browsers is like saying a dog is 'most likely to fly' in the company of an elephant, dinosaur and a rhino. Be cool and be a bird to begin with.
> An IP address is rather unavoidable. But whether or not an IP address constitutes PII is debatable.
Kahm. IP address is rather avoidable - just do not send data without user's consent. It is that simple. We are doing it, so I know.
It is also not that much of a debate whether IP address is PII. It is.
Multiple court rulings such as State vs Reid [1], and Breyer vs Germany [2] as well as California CCPA act of 2018 [3] define IP address to be PII (w/ or w/o caveats) or at least a part of PII.
> That said, we drop the IP address when and where possible.
I never implied otherwise. What I did was to state the fact that Brave client sends data to Brave servers and that we can not tell for sure what is being done with this data because Brave's server code is closed-source.
Is this potentially a concern for the users? Yes. Can it be avoided? Yes - just become zero-telemetry by default. No need for discussion then.
A good relevant example is that Google advertises Chrome as a privacy respecting browser. Do you believe that based on what they say? Why not? Are there ways you could believe this? Yes, if no data ever left Chrome to Google servers without user explicitly allowing it first (by 'allowing it' I do not count accepting Terms&Conditions as those are never read by anyone and do not count as explicit/informed consent in this context).
> do you not maintain a client-side list of suspected-malicious domains
No we do not (could change in the future, in which case it will be opt-in of course). These lists in the current form are arbitrary, this hardly counts as security feature and there is very little chance the user will end up on a malicious website intentionally. Plus browsing the web is the responsibility of the user. The job of the browser is to stay out of your way, not make arbitrary decisions for you.
> check for updates to patch zero-day vulnerabilities in the wild
In Orion, user can check for updates manually or opt-in into automatic updates. So the feature is there. The key is however in "opting-in" because we want to have the right to call Orion a privacy respecting browser.
Orion does not even set a default search engine - otherwise the moment you start typing into address bar you would be leaking information (including IP address) to the search engine provider for suggestions.
To recap, Orion sends zero data to our servers or anywhere else for that matter (unless user first opts-in into it), on the first run, on any run or ever really. We call this "zero-telemetry by default" and we invite Brave to adopt this. Privacy is a serious matter, so let's treat it seriously.
[1] https://en.wikipedia.org/wiki/State_v._Reid
[2] http://curia.europa.eu/juris/document/document.jsf?text=&doc...
[3] https://oag.ca.gov/privacy/ccpa