Brave Browser Passes 20M Monthly Active Users and 7M Daily Active Users
brave.com
brave.com
Rather than having your traffic logged by your local ISP, bound by the laws of the land and all the privacy regulations in your country, you send all your traffic through a third party based in a foreign country with no oversight whatsoever.
Or - with browsers - rather than install and configure Firefox to disable the (very limited) telemetry and configure ad blockers etc, you install a chromium derivative with all the Google pieces replaced with a different flavour of mystery sauce. You're still having all the analytics captured, it just goes to somebody with far less scrutiny than Google.
I agree though that you cannot check if the VPN provider logs your traffic or not even if they claim they don't log it.
The thing with being protected through paying off politicians is that it works, until it doesn’t.
Dilettantes, perhaps?
I'm referring primarily to gaming subcultures (board and video). Tech illiterate may not be the proper term. But most geeky people I know (even the ones who build their own PCs, and dabble in scripting) have a very cargo-cultish understanding of computing technologies.
Dilettantes, perhaps?
Advertisers can very well get websites to run "cloud functions" at the edge (with Fastly, Cloudflare, Netlify, Vercel, AWS Lambda etc) under the first-party domain, and the content blockers (native or not) will be none the wiser. This is similar to how content blockers struggle to block ads served from first-party domains on YouTube and other Facebook properties.
Exhibit A: https://github.com/samkelleher/cloudflare-worker-google-anal...
Interesting link. I will say though, Brave's been aggressively pushing for an end to third-party cookies, and if websites are increasingly forced to run first-party analytics as a counter-measure, that is still a major win for the internet as a whole.
Same for ad blocking but I have native mitigations with browser meta data spoofing on every http request (which of course gets unmasked if you log into sites, but its always funny to get a warning email from google when I check gmail occasionally).
I lost track of him about 10 or 15 years ago, but I wouldn't be surprised to know that he has a mobile infested with ads!
I actually do like some ads. I have money, and I like to buy cool and interesting things. Occasionally, ads tell me about a new thing or service I'd never heard of. Those are ads that I'm really glad I saw. When they're respectfully informing me of things I might actually be interested in, then I don't mind them.
When I don't like ads is when they slow the page load down by 100x. When I don't like ads is when they have malicious exploits of my browser to install malware on my computer. When I don't like ads is when they auto-play video or put intrusive obnoxious things all over the screen. (Seriously, does anyone respond to those kinds of ads?) When I don't like ads is when they chase me around the internet trying to get me to buy the thing that I just bought.
Using Brave, I see the static ads, and I get to choose to see ads through the Brave network or not. At the moment, I don't mind the Brave network ads -- they're mostly for crypto, which I don't care about; but they're not obnoxious and I know I can turn them off. And occasionally they're for things I might actually be interested in, like chess or electronics.
Right now only 2 of the sites I visit regularly are signed up to be Brave content creators; when this reaches a critical mass, I'll probably start putting in $10-20 per month specifically to support them. At that point, maybe I'll disable the Brave netork ads... or maybe I won't.
Is this in reference to tor?
I use brave because it's fast, compatible with chrome extensions, but a least a little bit disconnected from Google. Trackers and ads are blocked by default, and it's generally a nice browser.
Brave is like that, but a browser. You replace Google/Firefox with a smaller, maybe slightly less watched, browser that still does the same stuff.
At least with FF there isn't an incentive to sell your attention.
Brave is explicitly positioning themselves as a reseller of attention which they then obscure by pretending to focus on privacy. I'm not sure why anyone uses them - they're an ad company and their incentives are not aligned with their users.
I find them really untrustworthy and their pro-privacy branding has really confused their users.
for many of us who grew up in 'third world' (and/or 'developing') economies, this is not in any way better to "heavily regulated". I expect that people from very corrupt ex-soviet states will agree with this sentiment.
That's nice if you live in one of those countries. Some countries have very little privacy regulations for data collected by ISPs; others actually mandate collection and storage of data.
[0] https://www.crikey.com.au/2020/02/25/data-retention-scheme-a...
Using a VPN is a good way to obscure that information. Not every website you visit or app you use needs to know that you're in city X on Monday and Tuesday evenings, and city Y the rest of the week. That's pretty sensitive stuff for a lot of people.
In these cases, deception of the user is a prerequisite for "success".
That's only fallacy if you think I'm using VPN because I care about who has my browsing data.
I really couldn't care less. I'm using it because my country blocks certain websites and Netflix doesn't have Arrested Development or West Wing licenses for it.
which is precisely the point because one of the most popular use cases of VPNs is to send copyright infringement letters to /dev/null.
Every single time when VPNs come up there's people talking about all the pitfalls of VPNs when the vast majority of people just want to get past geo-restrictions or avoid being sued for torrenting.
If someone goes into private mode (and tor becomes enabled) and visits a site, wouldn't the owners of that site have less information on that person than if they visited from their own IP address?
What exactly is the fallacy here?
Look for the fingerprinting result.
It's that you're "safe" because big bad mega corp isn't seeing your DNS traffic or in this case they aren't sending you ads.
But you've traded big bad mega corp for up and coming bad mega corp2, so you're not really any safer.
Not sure I agree with that in this case.
I have seen that argumentation only in reverse when people were defending DNS over HTTPS by Cloudflare.
US ISPs:
- Were given retroactive immunity for their participation in illegal domestic spying.
- Often operate in a duopoly, caring not at all about their reputation.
- Routinely engage in shady practices like DNS hijacking.
This is the extent of Brave's analytics: https://brave.com/privacy-preserving-product-analytics-p3a/
You can also disable it completely.
At this point:
I use Chrome for one Metamask HD sequence
I use Firefox for another Metamask HD sequence
I use Brave for another Metamask HD sequence
Funny to say this, but I use so many browsers mostly for accounting purposes.
I wish there was a good wallet that maintained multiple HD paths and assisted in other best practices.
for two, I don't know anything about Firefox profiles, does that create a profile for my extensions too? Will multiple firefox profiles have different metamask instances segregated?
As with Firefox, the profiles are completely disconnected, and have different history, extensions, cookies, etc.
If you don't like Chrome's resource hogging, try something like The Great Suspender.
I've started using them recently to have entirely seperate environments for personal and work websites and it's a blessing. Previously I used 2 browsers just like you, now I have the unlimited power of Firefox AdBlockers in every environment.
Brave allows me to easily donate money to creators. I currently fund the internet to the tune of $10/month using Brave. Someday that will be $100/month.
Brave removes ads "pre-render" so it is the fastest experience one can get. Other ad-blockers remove them after they have already loaded via JavaScript. Brave does this natively.
Brave has features to let users watch ads and earn currency, I don't use that at all. But some do, and it is consensual and fine for them.
Brave has an option called "Private w/Tor" and that is what yabones is claiming that "its users fall for the VPN fallacy". Which may be true for a small percentage but yabones is making a sweeping generalization here by implying "all users", which is not even close to true. I don't even use Private w/Tor mode. I don't consider anything truly private on the web and nobody else should either.
Brave is one of the best things to happen to the web as the web has become swamped with tracking and ads. Brave does remove all those by default.
Isn't this only for sites "signed up" with BAT with Brave keeping the BAT if the site isn't enabled?
NB: It has been a long time since I've checked out Brave so my info may be out of date.
Doesn't Ublock Origin remove ads "pre-download" which is obviously faster?
Honest question - how much does that money actually reach the creators? Brave is sitting in the middle and I assume a. is charging a fee and b. has to be trusted to properly account for the money it has to pay creators.
It's a weird sort of marketplace where supply (content) isn't constrained at all, since it's trivial to duplicate. This means there's limited incentive for Brave to be nice to creators.
Are there any (3rd party, not Brave) stats on how much money creators are getting?
Tell that to Pi-hole.
>Different flavour of mystery sauce
There's no "mystery sauce". It's completely open-source.
>You're still having all the analytics captured, it just goes to somebody with far less scrutiny than Google.
Brave's completely open about its analytics, and they're designed specially to be privacy-preserving. (No, it's not some naive "anonymous identifier".)
https://brave.com/privacy-preserving-product-analytics-p3a/
And you can also turn them completely off.
Some don't like Brave's approach of an alternative, opt-in ads / rewards system because in their view everything crypto-related or ads-supported is scammy. That's an understandable perception: a significant number of crypto enthusiasts appear to be scammers pumping pyramid schemes, and we've already established the ad-tech industry is a towering inferno.
But technically I think you have to concede Brave's on-device ad relevance model is a better way (and the only conscionable one) to run an ad system that delivers relevant ads to interested users, and even directly reward them for their attention. If you think ad-supported anything is a non-starter, then you'd just never enable Brave Rewards, or use another browser (although they're entangled in the current ad-tech system so...)
What you say about 'VPN fallacy' makes little sense.
By default Brave is the most aggressive in blocking trackers, adware, and spyware compared to Firefox and Google — and this is actually a problem for Brave.
Follow their web-compat issues on Github [1] to see the kind of things they're dealing with (an example of the very problematic and kind-of-unresolvable issues that come up include the Duolingo issue [2]).
Users can disable shields on a per-site basis to deal with these things, but it's an open question as to whether this kind of friction will increase or decrease, and whether it's a barrier to larger adoption.
There is no question though that the Brave team have the most commitment to privacy compared to Firefox and, of course, Google.
Your statement that the Google spyware Brave has removed in their Chromium derivative has been replaced by some mystery sauce is based on...?
I do find it curious that whenever this little challenger brand pops up on HN there's a predictable surge of hot take / bad take commentary which aggressively tries to paint a picture of Brave as anything but a plucky challenger brand full of technologists who are expending a lot of energy on privacy, security, and moving browsers forward.
The accounts trying to shop a myth of Brave as a low-rent scam operation will inevitably find buyers for various reasons, but you'd hope technologists in the main will do their research and ignore, or even become curious as to what is driving this continued negative opinion-shaping...
I did mine, and I fell for Brave due to a desire to opt-out of the worst of ad-tech surveillance, get a faster browser, and participate in a novel attempt to bootstrap a frictionless crypto / tipping / payment economy. Not all of these novel ideas will work, but they're worth exploring.
For now Brave's been a dream, and when I accidentally use another open test browser for normal browsing, I'm taken back to a gross dystopia of a web experience.
I'm going to give Brave a try
I use Epic and LOVE it. However, do need a second browser to remove my dependence on IE/Edge
I could care less what some abstract country has on me. My own country - different story.
What some other country has on your country’s citizens (whether friend or for) is a target for your country's security services, by exchange or espionage, so you can't ignore one if you are concerned about the other.
Using a local ISP means that domestic spies will easily hoover up traffic and have easy ways link it back to all sorts of data about you. Using a VPN means that first the VPN provider has to be compromised somehow, the data has to be aggregated into the pool of domestic data - not a trivial task.
It is a pretty simple improvement that puts more of a burden on data collection agencies.
Yes I can. I understand reasonable security concerns and that is why countries have various security agencies who are being paid to do their job so I let them worry about it. My job is to worry about myself personally and I really do not care about what Timbuktu knows about me. They can't do shit to me personally. My own government and corporations however can.
The exception of course are large neighbours and their multinational corporations. I was surprised and irritated when I've discovered that Amazon knows exactly what kind of car I have even though I bought it from a used car dealer without any Internet involvement and I do not keep Alexa and likewise spyware in my place.
If “Timbuktu” has information about you and it's friendly with your government, it's likely to trade it; if it has it and it's unfriendly with your government, it's a target for your government’s espionage. In either case, it's a place where your information is that your government is likely to be trying to get it (unless you are a particular target, not in isolation, but along with other information), so if you are concerned about your government, you should be concerned about it.
Anyone here in HN has any clue as to ethics of those VC funding Brave?
In completely unrelated code paths, all open source, we have timing-channel blinded, few bits per answer, automated survey questions that tell us, e.g., how many people reset default search to a different engine (but nothing more). See https://brave.com/privacy-preserving-product-analytics-p3a/.
I'm not sure why you wrote what you wrote. Assumption? It makes an ass of u and umption, to quote Samuel L. Jackson's character from "The Long Kiss Goodnight" :-/.
It's run by one of the principle Firefox devs (Eich) and none of the stories about it ripping people off or being insecure appear to have been well founded.
I've used all the major browsers, starting with Mosaic and Netscape, was there when FF was phoenix, have been writing websites for 20 years (only a small amount of that time commercially). YMMV but it seems trustworthy, privacy focused, fast enough (ie I can't tell if it's different in performance terms).
It's just reskinned Chrome with privacy extensions built in and a system to enable people to try and send micropayments to sites if the sites are signed up.
It's not reminiscent of Eclipse in anyway for me (mind Eclipse to me most evokes poor DE integration, I'm a long time KDE user, and having a billion settings).
Use the browser that pleases you most though.
Plus, and I have no evidence of this apart the synchronized hype they do for the browser, but I'm pretty sure Brave is secretly bankrolling those very... political... Linux YouTubers.
I do enjoy the irony that Mozilla seems to have gone downhill ever since he left / got kicked out. The people replacing him, IIRC, aren't as knowledgeable or expert as he was. But then, I am somewhat a fan of pure meritocracy.
Of course (to reply to downvoted up-comment), we don't and never did "[replace] ads on sites you visit". But when it comes to evil-me, making false claims is justified? Seems so!
I ask because I feel the same but don't actually have any proof that things are shady. It is just a feeling which obviously isn't enough to convince others but is enough to put me off using it the few times I've tried.
Something about all this 'rewards' stuff just feels dodgy. No idea why I feel this, I probably read something at some point but don't recall now.
[0]: https://secure.fanboy.co.nz/fanboy-annoyance.txt?a=0 [1]: https://raw.githubusercontent.com/AdguardTeam/FiltersRegistr...
Brave's primary customers are advertisers. While this is not evidence in itself, it is certainly something to be wary of.
Which FAQ?
This appears to be the only FAQ that mentions anonymized data:
> Will Brave sell user data to advertisers?
>
> We do not have access to identifiable user data. The anonymized aggregated ad campaign related data we do collect is used for accounting and reporting, but this data cannot be mapped back to devices or user identities of any kind. Learn more
If you follow the "Learn more" link it says:
> If you switch on Brave Rewards and switch on ads (in Rewards settings) you will see ad notifications, and will receive BAT to reward you for viewing these ads.
It seems like it's off by default?
So like Firefox?
Do they collect your history? No. Then good
Firefox does too.
Source: https://www.theverge.com/2020/6/8/21283769/brave-browser-aff...
I get that it's unethical do it without users consent,
but I am personally OK with anyone using affiliate links for whatever I subscribe to. I don't lose anything, I don't pay for it, some company is letting other people or smaller companies increase budget. I often ask my colleagues if they can get me referral link before I signup for something. What's wrong with it?
A widget hand-made by an owner-operator in small-town USA who sells from his own website gets ignored while the Amazon-listed widget made in a Chinese sweatshop gets shilled because Amazon pays affiliates.
This can be used to track users across the web without their knowledge or consent.
However I don't know Brave's implementation here. Just answering the question in the abstract.
It has a taste of paying too much if the vendor can afford to give a fraction to the affiliate.
Of course you pay for it, it's the same thing as free shipping: the seller increases its prices to take into account how much they're going to pay to affiliates.
Well, a lot of reporting on the affiliate code situation partly mischaracterized what actually happened. There was an auto-complete suggestion that was auto-selecting when you pressed "enter", and it was fixed shortly thereafter. There is a blog post about it called "On Partner Referral Codes in Brave Suggested Sites".
That said, it does essentially the same thing Firefox does when you do a search on Firefox. Try right now: go into Firefox, type in a search in the URL bar, press enter, and you'll see it appends/"injects" a Firefox "affiliate code" as a query parameter so that Firefox gets a cut from Google. One salient difference is that Firefox's "affiliate code" is a vanity code (human readable: "?client=firefox-b-d"), so it isn't viscerally shocking.
If it read "?client=brave" like it does on Firefox, it's very likely no one would have ever cared!
Previous discussion: https://news.ycombinator.com/item?id=22510008
TL;DR It's an ad company posing as a privacy company. Brave replaces other ads with Brave's, created a crypto currency for the purpose of sharing profits with website owners, but in reality pockets almost all of the money since site owners rarely become aware of it [0] or more likely because it's spread so thin across the web that few sites reach the 100$ threshold.
Why "of course"? Keep your signing key off the repo, but you can very much keep them open source too.
A company taking money on your behalf without notification, while slimy, isn't mining.
Sometimes the users on this site sound like they are drowning, but when you throw them a like jacket, they push it away as they complain about the colour.
As for "modify user's input without their consent", go type keywords into any browser, Firefox Safari Chrome Edge etc. You'll see search affiliate client code, same as we had by mistake for the two binance domains, and only as suggestions for other partners (all of this, we removed in the springtime, to quell concerns and misrepresentations such as you make here).
We do not "accept money" as intermediary, the browser holds the tips to unverified creators. You seem to be operating on misinformation here. In December 2018 we briefly shipped a system that sent our own funds when directed, back to us, on behalf of unverified creators. That too was a mistake, but we fix bugs and so such tips are now buffered client-side. In any case, we were the source of funds there, not the user.
We've taken great pains with Brave Ads (not an "ad network" by the way) to avoid any privacy problems, starting by making them opt-in, using in-browser-only data matched against a fixed-per-population-per-day catalog, confirmed via Privacy Pass (blind signature cryptographi). This is the wave of the future, even Google is trying to do a Privacy Sandbox now, but they are piling up risks and letting partners into the sandbox last I looked.
It's clear you have some underlying problem with us, but it isn't based on the facts. What's the story?
Firefox feeds itself in the hand of Google. They won't do anything that will make Google less dominant.
But last week I swiched to Brave, because Firefox simply couldn't deliver the performance I need for all the heavy weight web apps I use (Cloud9, VSCode, Gravit Designer, Slack, Asana).
Brave is overall pretty snappy and I only got problems with Recaptcha, which wants me to do a ridiculous amount of tests.
Which seemingly is getting worse and worse, especially like the last 2? weeks.
Nightly already has the fix and Beta will get the fix when we finish uplifting Chromium 87 to that channel
What was the issue?
... and yet they keep growing.
The more interesting conversation to have is if the growth is linear or early exponential.
They're obviously making up their numbers, probably by 10-100x.
Steam is somewhere between 95-105m real MAU, and publishes only real numbers on its games. I know lots of Steam users, many more than 5. I know zero Brave users. Really, there's no way it is anywhere near as popular as they claim.
> "The average CTR (click-through rate) for a Brave Ads campaign is 9%, well above the industry average of just 2%"
Again, another huge red flag. There's nothing special about Brave browser. It just means there is some adversary, like bots, clicking ads, or they are lying.
I'm sure people will downvote this, or talk about whom they know uses Brave. Whatever. I would love to see a real audited number here.
It's fast and blocks ads - that's quite a draw.
Ublock origin is an extension, so accessing the options menu feels a bit janky on mobile as the options are shown in default HTML styling, and you need a couple more clicks to turn off scripts.
Alternative explanation: you live in a bubble.
Or maybe anecdotes do not tell the whole story.
The current iOS beta allows users to sync their bookmarks with Windows and iOS privately, and it's what convinced me to switch. I didn't need to create an account with my email address, or install iCloud...just scan a QR code.
I wish they'd fix the captcha problem though, a lot of sites that use ReCaptcha think Brave browser users are bots (due to the security).
Shooting to have the official version out today or tomorrow
On Brave Nightly since 6 months. block ads, Fingerprinting - aggressive , 3rd party cookies blocked,
If anyone has any suggestions I would love to hear them as it is the only thing keeping me on Chrome these days.
However, the problem comes to licensing costs :( Setting aside the privacy implications of sending content on a site (since you opt-in), the content needs to be fed to a service. Microsoft and Google charge a per-transaction fee on each of these service calls and it can end up being quite expensive
Here's a list of the telemetry https://github.com/brave/brave-browser/wiki/P3A
By default (you can turn this behavior off if you wish,) Brave will periodically (every 120 minutes or so) popup an ad. The ad doesn't appear 'in the browser window.' On Windows 10, for instance, it pops up in desktop Notifications. The ad is a sentence of text and a button, full stop. No video, audio, animations, or anything creepy. Just a little dialog box you can click or dismiss.
Every time that happens you receive BAT, a cryptocurrency, that accumulates in your automatically created BAT account. You do with it what you will but, by default, it is periodically distributed to sites that opt-in to accepting BAT.
It's opt in. Not default
(If you're aware of others, I'm all ears.)
I don't think it has anything to do with the javascript engine per se, but more the general API surface that Chromium gives you. There might be some additional benefit that Chrome is the most used browser (currently) and so there might be some developer sentiment or familiarity with it; Chrome's popularity might push adoption for Chromium.
I'm not even sure what moz would gain here.
The same could be said of the browser tech itself. They could just switch to a webkit engine, have the same market share, and still "gain" whatever it is they are gaining now.
(Note also that the choice is not a dichotomy between Blink and Gecko. WebKit exists.)
Also yes in general every JS-heavy web app I've ever used runs much smoother on Chromium than FF.
My favorite lightweight browser though is fallon. It's like IE but not as bad.
A standardized (and importantly open) platform that executes code exactly the same is the best to execute code on.
Flash was terrific because you, as a developer, didn't need to wonder if it would run the same on every machine. It did.
It was a major hit to my productivity when Flash went away. HTML5 never really replaced it - mostly due to browser compatibility issues.
Flash was not open but chromium is. The future is oddly bright here.
You might say ‘just fork it’, but I'll see how you do that and keep maintaining a full-featured browser. That would also make it not a monopoly.
Chromium itself has features tied to Google. The ‘Ungoogled Chromium’ project is dedicated to undoing that.
Likewise Android goes where Google wants it to go.
If you check the commit logs or the AUTHORS file, you'll notice a growing number of non-Google authors https://source.chromium.org/chromium/chromium/src/+/master:A...
Microsoft notably has a big presence in the source code and at events like BlinkOn. As each of these folks get their code merged, they gain privs like merge access and start getting tagged as a reviewer in other's change lists
I think you can probably figure out why.
I'm not sure why it shows up for nytimes.com, though, and not other sites.
The experience should be better in Brave Beta, and in the future we hope to get rid of the problem entirely by removing the current injection-based detection.
I've turned off all crypto, but this appears on every reload of the site. Can I know if there is a setting to toggle or is this a bug?
I choose Brave for the privacy, Ad-blockers, degoogling, and pretty good maintenance upkeep. I think a sizable portion of your audience choose it for the same reason. Your crypto work is certainly interesting but I think should be entirely opt-in or an extension.
Thanks for your response here :)
For example Tor Browser with default user agent gets all the captchas, many rounds per. Same Tor Browser with manually overriden normal Firefox UA barely gets any captchas.
Instead of the ad network facing the consequences of chargebacks, unfulfilled obligations, fraud and abuse, everyone holding the token will be on the hook. With all of the horrible things that go on in the ad/affiliate industry experienced publishers should be wary of this.
Also, as an expat the KYC stuff has generally been insurmountable. Hard to square that with the privacy angle.
However, I do look forward to innovation in this space. Brave/BAT has issues, but at least they're doing something.
The killer feature for me is that it lets you disable scripts for individual websites or 'Allow scripts once'. This basically makes most paywall news sites readable.
That said, it does essentially the same thing Firefox does when you do a search on Firefox. Try right now: go into Firefox, type in a search in the URL bar, press enter, and you'll see it appends/"injects" a Firefox "affiliate code" as a query parameter so that Firefox gets a cut from Google. One salient difference is that Firefox's "affiliate code" is a vanity code (human readable: "?client=firefox-b-d"), so it isn't viscerally shocking.
If it read "?client=brave" like it does on Firefox, it's very likely no one would have ever cared!
Disclosure: I'm invested in $BAT, the browser's native token
Chrome+ublock is the best way.