[1]: https://github.com/brave/brave-browser/issues/8793
[2]: https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br...
[1]: https://github.com/brave/brave-browser/issues/8793
[2]: https://davidgerard.co.uk/blockchain/2019/01/13/brave-web-br...
Seriously, if you want a browser that gives you control over your data and privacy, use Firefox. It doesn't do any of this shady nonsense.
https://www.thewindowsclub.com/google-chrome-reason-revealed...
But "chrome" to mean user interface is pretty far down the list of definitions for chrome, and even the most generous interpretation is similar to GUI/UI/UX and that doesn't exactly say "web browser".
Edit: forgot to mention you can install from 3p sources as I've done from my own site in the past. They just need to be signed by Mozilla first.
No they don't, xpinstall.signatures.required to false
I don't think there's really a good browser for both privacy and hacking. I use chromium when I have no choice (not sure what you're referring to concerning the disable modal ; if it's an issue with chromium too, I haven't hit it, and I have 11 extensions loaded from sources).
But my "main browser until it's not enough" is elinks (slightly modified by me to fix ruby support and offer a few more api methods to extensions). I can write extensions as simple ruby scripts, doing things like adding native markdown support, allowing to edit local files, adding proper indentation to HN comments, etc. It's the perfect browser for me (and with cookies disabled and js, css and images not fetch nor executed, it's a good privacy browser as well). But of course, you won't be able to use that to buy something on the web. Still, it's surprising how much I can accomplish with just that.
Forking a text browser is impressive. Though to be honest the older I get the less energy and time I have to be picky. (And building Firefox was so painful I vowed to only make changes via extensions.)
Actually, my first attempt to fix my problem was to try to find in firefox codebase where it deletes the extensions loaded from sources, either at the end or the start of the session, I supposed, to shunt that "feature". But after a week a free time spent on it, I made no progress. The codebase and the architecture are just too gargantuan to be tinkered with - at least for me.
'about:config' set 'xpinstall.signatures.required' to 'false'
So Firefox prevents this perfectly reasonable thing? WTF.
Not true. You can get them signed without publicly redistributing them.
As have I. The entire money making scheme behind it, while innovative, is a privacy nightmare.
> Seriously, if you want a browser that gives you control over your data and privacy, use Firefox. It doesn't do any of this shady nonsense.
Agreed, with the caveat that Firefox does have its own, completely different privacy issues[1][2]. Still, it's probably the best choice for a mainstream browser, and there are open source scripts out there[3] to plug up Firefox's few leaks. I used to use (and recommend) Waterfox as a more secure, private alternative to Firefox, but lately Firefox with Shawn's or a similar script applied is just as good. It's generally better to get FF from your operating system's repository and keep it updated that way rather than manually installing a fork.
[1] https://support.mozilla.org/en-US/kb/shield?as=u&utm_source=...
[2] https://www.mozilla.org/en-US/privacy/firefox/#health-report
[3] https://github.com/shawnanastasio/firefox-privacy-restorer
I had never heard of these before, but when I go to about:studies, I see that I have never participated in any studies, and when I click the link from that page to "Firefox data collection and use" setting, I see that I am opted out from everything. Pretty sure I didn't do that manually.
Your second link is to a page called "Firefox health report". I have no idea what conclusions I'm supposed to draw from that.
Can you provide more info about the privacy violations you're referring to?
Are you in the US? I also have not participated in any studies but in the preferences it is marked as active. My guess would be that they either run very few of them or are restricted to the US.
Are you on Linux? Many distributions include their own tweaks to the Firefox package, including disabling data collection.
https://support.mozilla.org/en-US/questions/1265029
But there are many others, just search "firefox privacy concerns" or similar keywords. Telemetry data -- Pocket suggestions -- etc.
I felt they should have made it an opt-in service that the user can choose on the first launch. Taking away user choice is rarely a good thing, and even less so when dealing with anything privacy related.
The original service was integrated a while ago, but it doesn't really have severe privacy implications. If you click a pocket button, it asks you to log in. If you don't click, it does nothing. This is the one that's hard to disable, but it's an annoyance more than a security problem.
Pocket suggestions are newer, showing articles on the new tab page. They are trivial to turn off, and for what it's worth all the sorting/filtering is done locally.
My point being, even if Pocket is 100% benign and never leaks any user data, the user should still have a say in whether it is turned on by default on a fresh installation. Anything less is user-hostile, a descriptor Mozilla should avoid if possible.
Is it? An ad bundle is downloaded to your pc. Your pc tracks some usage, and stores every analytic locally. Using the analytics, your local client chooses which ads to target you with. You wipe your local data cache, your analytics disappear. I would guess people wished more advertising respected privacy this way.
This seems like much LESS of a privacy nightmare than Google, Facebook, Verizon, Microsoft, Amazon storing a named profile for each person.
I always joked that if you were really Brave you wouldn't need their browser, it should be more aptly named "Wimp".
1. Block scripts on certain domains
2. Block ads & tracking (including on Android)
Those are my favorite Brave features. How do I get them on Firefox?
On desktop: regular Firefox + https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
In uBlock Origin, there is a setting that disables Javascript by default (which I use). You can then enable it temporarily or permanently on a per-site basis.
For ad-blocking, I supplement uMatrix with uBlock Origin. It has its own block lists that it perodically
On top of that, I use privoxy as an http proxy. Unfortunately, it can't filter https.
Yet another part of my defense is DNS blocklists that I put in to /etc/hosts.[1]
Using this combination, I virtually never see any ads.
As the author of both uBO and uMatrix, I don't understand the need to use uMatrix to block scripts when already using uBO, since uBO can do the same.
Even better, uBO supports replacing certain blocked scripts with a local, neutered version (to lower likelihood of site breakage), something which becomes broken if you block the same script with another extension (i.e. in either NoScript or uMatrix).
If this is possible to do in uBlock Origin, I don't know how.
AFAIK, uBO does not have a similar matrix-like interface. So if the equivalent control is possible somehow, it must be hidden further down in its interface, which makes it much less convenient for me than the simple matrix that's behind a single mouse click for me in uMatrix.
I'd love to learn how uBO can be used like uMatrix, if that's possible. There's no need for both extensions if uBO can do it all, but as far as I know it can't.
Any plans to update uMatrix so it behaves nicer on mobile? The popup interface resists pinch-to-zoom and the text is so small as to be literally illegible on mobile devices. So I can't read the various domains to decide which ones I want to block or permit!
[uBlock Origin was recently updated to make it more mobile friendly. Although, ironically, out of the two, it was already more usable on mobile as it was possible to zoom and pan round the interface.]
NextDNS has a more advanced version (you can add and remove domains) for $19.90/year
It's not quite as good as having a PiHole or similar setup because some devices have their DNS settings hard coded. You have to route those addresses to override your Chromecast, etc.
https://adguard.com/en/adguard-dns/overview.html https://nextdns.io/
I must admit that does not quite fit with a lot of the thing I've read about Brave over the years.
[2] was fixed a while ago as mentioned in your link.
[3] was also fixed quickly.
I don't know if you've ever run a company but if you do, I hope your users won't attack you and remember every single mistakes you've ever made even if just 3.
Disclaimer: I don't work for Brave and rarely use it sometimes as secondary browser.
For example, the decision to hijack links to insert their own affiliate links is not a mistake, it was a decision. These kind of decisions are not made by a developer in the team, it is a leadership level decision, coming from principles those leaders live by, and also one that does not put users first. On the contrary, it takes advantage of the users.
The principle of 'forgiving mistakes' applies only to honest mistakes. Otherwise we would all be browsing with Chrome/posting on Facebook/[insert currently hated company on HN here] and forgiving them all their 'mistakes'.
This is why Firefox decided for example to support non-free mp4 or EME (DRM), even though it goes against their mission of supporting the open web. They decided that not supporting these features would kill their market share, relevance and revenue making it hard to support their users in the future.
When Brave made the decision to insert affiliate, they saw it as a way to help with their revenue which helps their mission without hurting privacy too much (they still block more trackers than any other browser in the market including firefox). Still, they rectified this quickly showing that they are not stubborn and are ready to sacrifice revenue for their users. Anyway, it's not easy to balance all this and you will be hard put to find saints that do it all perfectly out there, good luck finding one though.
Although this can be a sound principle for many, I do not agree with it. Brave is not 'entitled' in any way nor should the world bend to make Brave possible. It's a company like any other, with a product like any other and with, IMO, questionable leadrship principles demonstrated over and over again. The market will 'price' it accordingly in terms of market share.
If I was to build a browser (which btw I am doing) I would put 100% user interest first, at the price of not succeeding in the market. That is the only way I could sleep well at night.
I never said it was entitled, I said it had to balance things to survive.
> If I was to build a browser (which btw I am doing) I would put 100% user interest first, at the price of not succeeding in the market. That is the only way I could sleep well at night.
A quick look at the history of humanity will show you that even the most moral entities had at a point of their existence have to compromise with morality to survive, or made bad choices out of self-interest. Just like every single human being who has ever lived. I don't think you can never ever ever compromise on anything while accomplishing anything significant. By the way, do you plan on taking out mp4 and user freedom hostile features such as EME support in your browser?
I don't think you can never ever ever compromise on anything while accomplishing anything significant.
Not with that attitude you don't.
These aren't mistakes, though, at least not in the sense of accidents. They were bad ideas, but it certainly wasn't a case of "oops, I accidentally added affiliate hijacking, silly me".
I mean, I suppose you could interpret them as severe naiveté and/or incompetence? That's probably the most charitable way to look at them, but still wouldn't exactly encourage me to use the product.
ps: Edge's reader mode and narrator are top-notch.
If I was going to plump for one company, Microsoft might not be the worst choice simply because their business model doesn't revolve around monetizing my personal information.
Yet they seem intent on collecting as much data as possible.
Compared to google which continues to make their UI more hostile to users with each iteration.
Try ungoogled-chromium:
https://github.com/Eloston/ungoogled-chromium
Put uMatrix, HTTPS everywhere
Firefox does not send your unencrypted browsing data to Microsoft and it does not send Windows 10's advertising ID to Bing Ads.
---
You may trust Microsoft enough to run Windows 10, but it does not follow that Microsoft already has that data. And giving even more data to a company that already has plenty on you is always unwise.
If you care about privacy or security for that matter, compartmentalization is key.