Brave browser can inject headers in HTTP requests
github.com
github.com
> That is a very first beta version of Brave Rewards on Android. It is pointed on test network. DO NOT TRANSFER REAL MONEY!!! We use SafetyNet API for device attestation.There are grants available on first run. There are no grants on devices where attestation is failed(rooted devices, emulators). Auto-contribution time is set to 10 minutes, just for test purposes. Couple of verified pub on staging: duckduckgo.com 3zsistemi.si
Did it make it out? Here is the link
https://github.com/brave/browser-android-tabs/releases/tag/1...
A lot of people on the internet seem to be advocating it but reading the Wikipedia article they seem to have a business model of replacing website adverts with their own. Which doesn't seem all that ethical.
Personally I think compromises with the ad industry only end one way, and the addition of cryptocurrency into the mix should set of alarm bells.
Beyond that, I hope that you can start responding to things I’ve actually said, instead of just responding with “pithy” and tangential one-liners. I’m not interested in an intellectually bankrupt form of posturing in place of real debate.
Sorry for nitpicking, but I just couldn't get this to leave my mind. I understand that you were going for a wordplay with "not even wrong", but I'm still trying to imagine whether there's a geometric interpretation to make sense of this.
Would this imply that the angle between the two things cannot be defined? If so, what would be a possible situation here?
Well, I suppose there's a framework in which orthogonal could imply coplanar and so skew lines would.be “not even orthogonal”; particularly they'd have no contact at all irrespective of relative alignment.
We are all paying for those marketing budgets- its included in the price of everything we buy. Paying for our own brainwashing.
You must have me mistaken for another commenter. I never said the word "freeloaders." Perhaps are you projecting?
Turning down the volume on the radio doesn't involve hijacking any DRM or ad tech. It's built into the hardware. To wit: The analogy is bogus.
Do you have the right to control what runs on your computer when you don't own the copyright? The answer to that is no. The copyright owner decides that. You can opt out by not visiting your favorite sites in the future. Please take a stand and do not visit them.
> Beyond that, I hope that you can start responding to things I’ve actually said, instead of just responding with “pithy” and tangential one-liners. I’m not interested in an intellectually bankrupt form of posturing in place of real debate.
I continue to do that sir.
This is factually incorrect, as has been pointed out elsewhere in this thread. You can do whatever you like with what’s runs on your computer, assuming that you legally acquired it. Feel free to levy a moral objection if you like, but don’t pretend that your personal hangups are reflected in law. Your right to play with something on your computer is the same as your right to remix music you own; it only ends if you try to distribute it.
I know businesses want to pretend the web works like television, or radio, or newspapers, but it doesn't.
Whatever a site sends me as a response to a request is mine. It's mine. The transaction is completed, the response belongs to me and I can do whatever I want with it. I can not run the javascript. I can run my own javascript. I can mess with the HTML and CSS. I can choose not to view the ads. Hell, Brave is based on and works on this premise, it injects its own ads. They can do that. I can do that. I have no reason to do that, but I could.
That's the way the web works, has always worked, and will always work. And it's the reason ads on the internet were doomed from the start. The only reason they worked, at all, to begin with is that the public wasn't aware that ad blocking was possible, and browsers weren't capable of it, but the underlying capability was always there, it was always implicit to the way the request/response model of the web worked.
The only group acting entitled are businesses. They feel entitled to more control over the end user's experience than they have. If they want that kind of control, they can put up a paywall. Or go back to old media. Or accept the true nature of the field they're playing on, that they cannot have complete control over the end state of their content on the web. They cannot force the end user to endure their advertising if they don't want to.
This is legally false. If a digital artist creates a painting and puts it up on their website, and you go view it, it does not become yours. The artist retains the copyright to the work, and not only is it illegal for you to then sell prints of it, but a violation of ethics, to boot.
Of course the image is mine, just as an image of the painting in a newspaper or brochure would be mine, it's a copy freely distributed by the copyright owner. I'm perfectly within my legal rights to do whatever I want with it, within the confines of the browser.
I'm not claiming i have the right to sell it or anything, but I absolutely do have the right to decide whether or not it shows up.
*if it was legally acquired. Remixing illegal stuff would still be possession of illegal stuff.
It's simply a matter of common sense, legal precedent and the way HTTP works.
To claim otherwise would mean companies have the right to force me not to alter the content of their responses in my browser, in order to guarantee their ads are viewed. If this were true, all browsers and many plugins would already be illegal, as would ad blockers, whose legality has been confirmed in multiple court cases.
Ethics and morality don't enter into the discussion. If I want to support a site by viewing their ads, I can. If I don't, I don't have to. The choice is mine to make. Sites depending on ad revenue, meanwhile, can try as hard as they want to convince me to choose to view their ads, but they have no legal right, nor technical ability to make me, as long as we're talking about content that can be filtered out of an HTTP response by a browser I control.
I haven't heard of this before. How does it work? Do you know of any examples?
[1] https://fossbytes.com/google-chrome-is-working-to-prevent-ba...
I used to use both of these popular browsers, and now I'm all-in on Brave. Chrome is fast but has well-documented privacy issues. But even running various tracker blockers and a Pi-Hole, Chrome wasn't nearly as fast as Brave (without additional blockers or the Pi-Hole).
I like to support Mozilla/Firefox, and Firefox has been my daily driver for most of the last two decades. But it just isn't as fast as Chrome (let alone Brave). It has better privacy than Chrome, and the inimitable Tree Style Tabs, but it takes noticeably longer to open new tabs and load pages.
I moved over to Brave once they started supporting Chrome extensions. I have found that my MBP's fan kicks on much less often than before on Chrome/Firefox, and the battery lasts longer as well. While I miss the TST that I enjoyed on FF, I'm getting by with Sidewise. The inconvenience of having the tabs loaded in a separate window is massively outweighed by the speed/privacy benefits of Brave.
As for the ethics of ad-replacement, this is a bigger question. If the baseline were "everyone has ads everywhere", this could be seen as an unethical alternative. But the baseline is "many people (and presumably nearly everyone who is savvy enough to install Brave) use adblockers". So it's not like they're going from seeing ads to not seeing ads. They're going from blocking them with one system to blocking and replacing them with another system. And they can send the revenue from the replacement ads to the websites they spend time on.
It is to have a chrome with adblocker on android. For all my desktop browsing I use firefox but on android some sites just don't work.
I haven't seen any Brave ads but if they start to appear, then I'm back on Firefox on android as well..
If you don't want to pay for content in some way then that is your problem and has nothing to do with Brave, Chrome, or FireFox.
To reiterate If the rise of Google has taught us anything it’s to analyze a business in terms of its likely future, not its present spin and PR. If all it takes to make more money is to flip a switch, then it’s reasonable to worry that such a flip is just a matter of wider adoption and time.
Brave is a combination of adtech undermining other adtech, cryptocurrency, and a lot of verbiage. I feel that’s a reason to be concerned when the line between said verbiage and future profits (assuming widespread adoption rather than withering away) is the flip of a single option from “opt-in” to “opt-out”.
Brave does not offer such value to advertisers (unless they start having people "Sign Up", which would be an effort significantly more difficult than flipping a switch), so where do you suppose the value in throwing as many ads as possible to as many people possible comes in? What value is there in showing me a browser-based ad for something completely irrelevant to me?
That aside, I responded directly to your comment, which basically says that if Organization X does something undesirable, related Organization Y would likely do it as well. On one level, I get it, it's almost agreeable. On another, it seems like you want to hold Brave accountable for the sins of Google, which is almost absurd to me. But hey, that's your right. Can you go ahead and copy/paste the comment again if you continue to disagree? I like being condescended to.
The alternative seems to be either ads/tracking (chrome), or directing people towards search engines owned by competitors (Firefox).
Then again, their whole tech stack is built on a competitors work too. All browsers depend so much on Google now its crazy
Somehow you're no longer rate limited after signing in
Edit: It's working now just fine, even if I am not signed in. Like they suggest below, it seems like that is Twitter being actively malicious to web users, and not Firefox.
However Firefox on Android is really super slowly almost stepping up on Android.
I don't like Brave's business model, but I like the browser itself. Firefox Mobile just didn't cut it to me. All I wanted was Chromium without Google, and all the privacy features[1] built-in. I'm glad such a browser exists.
[1] https://lh3.googleusercontent.com/vghNt_aflzbGItBHthEGnAvtRt...
It adds a new potential way monetize the web. Currently, the prevailing model is to offer a “free” product, where user data is being collected and sold to whoever is willing to pay.
Brave introduces the ability to pay per use and if you want to, you can opt-in to ads that are targeted based on anonymized data for targeting and you can earn BAT for doing so.
It basically changes the incentive model the ad industry and arguably a lot of the internet.
One interesting aspect is that they intend to integrate the ad matching & serving engine right into the browser. Thus (at least in theory) the browser can still serve "relevant" ads without exposing your clickstream to anyone. According to their materials, you'd have full control over what's collected and how it's used. It's opt-in.
IMHO The model hits the sweet spot for those who don't mind ads in principle but don't trust the ad industry.
https://twitter.com/galkowski_t/status/1074703403274698763
It seems blindingly obvious that Brave/BAT is in seriously dangerous legal territory. I would be that very close to 0% of the money transferred by BATs has made it to the "rightful" owners, where rightful is "where people paying BATs thought they were going".
If this scheme ever gets any serious attention, positive or negative, it's going to be a spectacular implosion.
And the one I use has a novel revenue model that doesn’t require anything shady - I give them money and they give me a product.
It seems like people don’t trust the motives of Google (and rightfully so).
And those “other choices” only work within the browser. Apple’s ad blocking framework works with apps that embed web views using the SafariViewConttroller like Feedly.
Android also supports blocking ads throughout the system, not just in WebViews, which is the only option on iOS.
You can buy VPN subscriptions that serve as ad blockers outside of the App Store and just go into settings and configure it yourself. Preferably, host your own VPN host on your computer where you know no third party is intercepting and recording your traffic.
I'm also not saying that it's perfect, but it is clearly better than Apple's alternative, which you have not disputed.
Sure there is a lot of C floating around but there is a solution in sight and there is some amount of effort being put in to rewriting things in Rust.
Again, you have not disputed that Apple is worse.
You really think people are auditing all of the open source software you are using? Where were they the year and a half the HeartBleed bug was out in the wild?
I'm saying it's significantly better than the alternative, and you continue to ignore that point. For example, reproducible builds directly stops XCodeGhost from ever happening, which was the single largest mobile malware infection in history by a wide margin. As another example, heartbleed has nothing on this 15 year old MacOS bug. https://www.macworld.com/article/3250125/macs/full-macos-com...
https://en.wikipedia.org/wiki/Stagefright_(bug)
And since Android phones both have a horrible security model and a horrible history of receiving updates, any malware or security issue is made worse.
I live in a neighborhood that has never had a reported break in. Does that mean I’m not more vulnerable if I leave my door unlocked and post a huge sign outside letting everyone know?
Even if you look at something like the way that third party keyboards work on Android, it’s a security nightmare.
On iOS, users have to explicitly go into settings to add a third party keyboard and even then it doesn’t have network access by default. The user has to go back into settings to enable the keyboard to have network access and then they get a big scary warning. Android users happily install keyloggers.
Also, even after you both install the keyboard and give the keyboard network access, iOS still switches back to the default keyboard when entering passwords.
Blocking exploits in the Play Store, among other things. Why do you think Stagefright was never exploited?
> It would have been just as easy for someone to infect the Android build chain.
We were just talking about reproducible builds.
> Keyboard nonsense.
Android also displays a scary warning for keyboards.
If the MMS app and the browsers were updated to filter Stagefright exploits (on Android, unlike iOS, system app updates do not require an OS update and happen through the Play Store, one of many things Android gets right and iOS gets wrong), the only way to exploit it is by publishing your own app to the Play Store and getting somebody to install it and hoping that the device doesn't have an selinux policy that limits the privileges of the exploit. The Play Store can trivially block apps that don't use an approved wrapper library for media that filters Stagefright exploits.
Also, what’s the differences between updating the OS from Apple’s servers and hypothetically updating an app from Apple’s servers. Are you trying to turn a weakness that Google can’t just press a button and allow every single Android worldwide to receive an OS update into a strength?
I appreciate that it would be nice if Google gave us the option to block stuff in Webviews, but it's not a replacement for having a real ad blocker like uBlock that is much more complicated and has many more features. I think the person you are talking to is mainly criticizing Apple for not letting you use such an ad blocker on their OS.
The difference in utility is stark enough that if I'm on the road and need to browse the web outside of known-safe sites, I find it more pleasant to do so on my 5.7" Android phone than on my 10" iPad.
Since I don't use Safari for "normal" browsing, I can't recall any specific problematic sites, but just opening some random news headlines I get the following unwanted behaviours, roughly half of which are nags to install the iOS app:
* theverge.com - nag to disable ad blocker
* nbcbayarea.com - nag to install app
* youtube.com - nag to install app, autoplaying video, all the rest of the junk that YouTube annoyances blocklist blocks for me with uBlock: https://youtube.adblockplus.me/
* lifehacker.com - annoying animated recommended story gif (to be fair this isn't an ad-blocking issue, it's just a configuration setting that Safari doesn't offer)
* bloomberg.com - nag to install app, nag to subscribe
* forbes.com - nag to install app
* observer.com - autoplaying video ad
* twitter - app nag, login/signup nag
I only use YouTube mostly for official AWS videos and then I use CornerTube. I usually don’t see ads. Do content producers get to choose when ads are shown?
That's my understanding. Also a mostly non-YouTube user though, I find the web interface really unpleasant - if I were going to "use" it on a regular basis I'd probably use youtube-dl.
One assumes that wasn't an accidental design flaw.
The JSON file that was linked to does have partner domains which (when the header is present) the website will provide a specific integration. When those specific partner sites are visited, the headers are sent with the request
An example someone mentioned here already is marketwatch. They have a promotion where you can sign up for a free subscription if you use Brave
The browser is open source and nothing is being hidden- although this and the whitelist (used for a better webcompat experience) could be better documented
Should these lists be shown in the UI and configurable? (ex: disableable?) I wonder what a better experience would look like for people that don’t want this functionality
It leaves others, but perhaps your idea of a UI to disable it addresses that somewhat.
I reviewed with team and created https://github.com/brave/brave-browser/issues/3301 to track this (folks are welcome to give it thumbs up). The fix for this should be something we can deliver in our next product release (0.60.x - 9 days from now)
edit: issue is now fixed! https://github.com/brave/brave-core/pull/1633
I also captured feedback on being able to customize/opt-out of this functionality with https://github.com/brave/brave-browser/issues/3302 (thumbs up and comments appreciated!)
I do have to wonder if this is as egregious as some of the comments between the two threads would make it seem given that this is an open-source project.
How about no? How about we find a better way to not starve than making sure everyone is fed their daily dose of manipulative marketing materials?
Just because someone rejects a shitty solution doesn't mean they suddenly acquire the burden of coming up with a new one.
Like, weren't micropayments all the rage just 5 years ago?
Are ads really the problem in itself? I'd say the real problem with ads are ad networks that track you, create a profile of you and use that to personalize ads, meanwhile providing an attack vector for malware and site owners abusing it historically in the form of Flash or other ugly and distracting ways of displaying them. Brave is providing a way to display ads that don't track you and don't infringe on your privacy. I don't see the downside here, only the upside that we can continue to have a 'free' internet where not only the well-off have access to vast swathes of the internet.
Nobody likes them, at best we tolerate them and or manage to ignore them.
So why have something that nobody likes? They're not inevitable, and society can function without ads.
The problem is that new content-centric business models have not yet emerged. So, some people remain chained to the old paradigms.
The crisis we have is a gap in vision. People don't realize that driving cost of information distribution to zero means that it no longer has enough scarcity to force the economic transfer of other scarce resources. Basically, what OSS did for commercial software, the Internet did for anything that fits within a 2D screen. Netflix, NYTimes, Fortnite, JK Rowling, and Jenna Jameson are all competitors in a space whose Pixels*Seconds value is commoditized.
Capitalism doesn't thrive unless there is an exponentiating dynamic. The only one available on the Internet is bandwidth capture. Which, for now, translates into attentional capture.
With the imminent arrival of P2P web software (e.g. Beaker Browser) and mesh networking, the tides will turn back towards a creator-centric peer network.
The other half is setting aside an amount of cash each month (an amount that you decide on), and paying it out to the sites you visit the most.
I like that idea better, but I don't know if it's sustainable, users don't want to pay money.
The point of Brave (to me) seems to be that it gives you the tools to keep your data secure and provides a way for you to willingly trade it for something of value (BAT). This is done by enabling ads. In essence you are the one being paid for your attention instead of Google or Facebook. The ads are serves by brave but purchased with BAT. So the same people who want to serve you ads need to buy BAT on the open market. This is what gives the token value.
So the point Isn't to get rid of ads. The point is to give you a way to actually get paid for your data. Your data has value and people are going to get paid for it as long as it A) exists and B) is useful to sell you stuff. I think that a tool to actually make people realize the value of their own data is something that we desperately need in this space.
> For some partners, Brave will set a custom header to identify the browser. We use the Chrome user-agent string, so accounting for traffic coming from Brave is otherwise hard. [...] As an example, if you navigate to https://www.marketwatch.com/ you will notice a custom header. [image of header listing containing X-Brave-Partner: dowjones]
[1] https://twitter.com/BraveSampson/status/1094713424452505601
It shouldn't. It should use Brave since it's not Chrome.
A more descript UA here ("Brave but built on Chromium") seems magnitudes better than imitating a native Chrome UA to avoid bad code that specifically looks for Chrome/ium, no?
His explanation as to whether this might make a user more prone to fingerprinting was a total cop-out too. It does make you more prone to fingerprinting "but only to their audience" isn't a good enough answer. Customers/partners which users have no control over and are expected to trust Brave executives as acting in their best interest. Where is the foundation that justifies this trust?
Brave plans to do all machine learning for their ad tech locally in the browser. Can you imagine Google ever doing that to protect their user's privacy?
I don't think it's the browser's role to police such things, it should be a dumb agent only requesting content, displaying it and not leaking any sensitive stuff.
I believe the way forward is to have another 3rd party where you can manage those things. Want to create one persona per category of website you visit?
Even go as far as one per website? Doesn't matter, your metadata, you own it and more importantly your browser stays out of that business.
Unless you've found some way to change the content of that url without the browser detecting it, I don't understand what you think there is to be concerned about here.
- the source code is open, so we can see that this is going on
- the url where the headers are downloaded from is open so we can see / monitor whatever headers get added
I'm not a security expert, just a lowly developer, what sequence of events should I be concerned about?
Every day the browser downloads from "laptop-updates" server a list of hosts and list of headers to inject.
This is supposed to help websites to identify that the user is running Brave (but there are other exceptions in the code, like at https://github.com/brave/browser-laptop/blob/master/js/data/... ) but in practice, the Brave developers can inject any header into any website remotely.
Every single Brave installation is uniquely tracked by a "download-id" which makes the backdoor even more powerful.
btw midori is without backdoors, so is dillo, or lynx.
No one brought up “website oriented” experiments. We’re talking about the browser itself. All modern browsers of them have the ability to download JavaScript and execute it to change functionality. All of them have the ability to toggle behavior remotely. That’s how you experiment, and experiment driven development is how modern software is made.
Finally, you can not be serious mentioning Lynx. It was obsolete in 1996. I know. I was there.
I ultimately went back to chrome though after I installed blokada. You might want to check that out as well.
You can get it from f-droid if you have that app store already.
They're adding a header to identify Brave browser to sites they have partnerships with, like MarketWatch.com and Cheddar.com.
For example, if you add the header: `X-Brave-Partner: cheddar` to your headers in Chrome, and navigate to cheddar.com you get 3 free months of their paywalled content. (Who pays for a subscription to Cheddar.com?!)
If you think about it, you can start to see why they HAD to add a new Header and not just use a custom Brave UserAgent string.
They currently use Chrome's UA string, if they used a uniquely identifiable string, publishers who weren't on-board with Brave's ad network could start nagging users/trying to get around Brave's ad-switching technology.
> [{"domains":["coinbase.com","api.coinbase.com"],"headers":{"X-Brave-Partner":"coinbase"},"cookieNames":[],"expiration":31536000000},{"domains":["marketwatch.com","barrons.com"],"headers":{"X-Brave-Partner":"dowjones"},"cookieNames":[],"expiration":31536000000},{"domains":["townsquareblogs.com","tasteofcountry.com","ultimateclassicrock.com","xxlmag.com","popcrush.com"],"headers":{"X-Brave-Partner":"townsquare"},"cookieNames":[],"expiration":31536000000},{"domains":["cheddar.com"],"headers":{"X-Brave-Partner":"cheddar"},"cookieNames":[],"expiration":31536000000}] <
also im not digging into the code at all, if i click on the link for this thread i land on the above snippet.
[
{
"domains":["coinbase.com","api.coinbase.com"],
"headers":{"X-Brave-Partner":"coinbase"},
"cookieNames":[],"expiration":31536000000},
{
"domains":["marketwatch.com","barrons.com"],
"headers":{"X-Brave-Partner":"dowjones"},
"cookieNames":[],"expiration":31536000000
},
{
"domains":["townsquareblogs.com","tasteofcountry.com",
"ultimateclassicrock.com","xxlmag.com","popcrush.com"],
"headers":
{
"X-Brave-Partner":"townsquare"},
"cookieNames":[],"expiration":31536000000},
{
"domains":["cheddar.com"],
"headers":
{
"X-Brave-Partner":"cheddar"
},
"cookieNames":[],"expiration":31536000000
}
]