Brave, the false sensation of privacy
ebin.city
ebin.city
This does not appear to be true. Here is the github repo for their open source adblock engine written in rust:
https://github.com/brave/adblock-rust
Here is a (somewhat dated) article describing it by the authors:
https://brave.com/improved-ad-blocker-performance/
> Google will take decisions that benefit their advertisement business, like making impossible to use adblockers on any Chromium based browser.
Because the brave adblocker is integrated directly into the browser (ie. not an extension) the Manifest V3 limitations don't apply.
Brave's Sync v2 works decently well.
> Rewards is their shitty program that will replace ads displayed on websites with their own.
Brave doesn't replace ads with their own. Brave ads are displayed as desktop pop-ups. They can also be easily disabled (which, surprise, the author doesn't mention because of his bias). And the idea behind Brave ads is to give you tokens which are then distributed to the content creators you engaged with. This is the default setting. Their idea is not to shovel you with ads or offer you "get rich with crypto" schemes. Idea is to block ads but still provide revenue to the content, based on how many users engage with that content.
When I see people saying "Brave replaces ads with their own" I have to wonder if they have tried using Brave themselves before writing these critique articles.
On one side, Brave come with an adblocker that will remove any ads from the website you're visiting. On the other, they provide their own ads through the reward program.
So it can be seen as "replacing website ads by its own".
I approve that line of reasoning, but I think that what the author meant.
Brave allows you to do whatever you want. You can see publisher ads without Brave ads. You can see Brave ads without publishers ads. You can see both. Or you can disable both.
Since individual users can achieve any configuration of ads they like, to me it seems that some people are only unhappy with this because they want to push their moral stances on everyone else. Like, for example, stating that the ability to block publisher ads while enabling Brave ads is immoral and shouldn't be allowed.
Brave basically aligns advertising incentives to match with viewer incentives. A Google served ad is not the same thing as a Brave served ad from the perspective of a viewer, because Brave ads are optional and some of their value accrues to the viewer.
Is the alignment perfect? No. But I do view it as a substantially better starting point than the currently centralizing, adversarial model that currently exists.
I used brave's android browser a long time ago as well (at that time these claims were true - but they didn't replace the ads on all pages). I cannot speak about whats the current situation however, as I'm not up to date on the topic.
The notion of getting paid to view a separate stream of ads seems bizarre. It's the 'Ad Buddy' model, but with crypto.
You watch significantly fewer ads than before, these ads are then supplied to whoever you yourself engage with. That seems like watching these fewer ads directly on the site, just with a few hoops in between.
The difference is that now you watch fewer ads in total, and you have the Brave-browser as an inbetween, which also somehow has to survive. This means that you get potentially even less money, since less ads are watched and the ones that are watched are more diluted (even if brave currently doesn't take a cut at the moment: At some point they have to pay their developers, too).
Also, why do they pay out in BAT? (other than the fact that they cooperate with "uphold" a crypto-exchange and that they also really really want to jump on the crypto-bandwagon)
Somehow there has to be money going into the system that supports its own existance. If brave had something like a subsciption service or other way to get additional funds into the Network, then it might be more understandable, but even then: Why should I support someone by using BATs instead of paypaling/patreoning/whatever-elseing him the money directly?
Per https://brave.com/rewards and https://creators.brave.com, users opt-in to Brave Rewards and begin participating with privacy-preserving Ads. Each ad nets you, the user, 70% of the associated revenue.
Rewards come in the form of BAT, which moves more easily and comes with considerably less friction. The blockchain enables users to effortlessly and anonymously participate. This also means that everybody with attention (and not necessarily disposable income) can support the content they love online.
As for paying out in BAT, creators can choose to have BAT auto-converted into Bitcoin, US Dollars, etc. Users can also have their rewards converted into another type of asset or currency via Uphold too. BAT is simply a utility token, whose utility is currently best demonstrated within the Brave ecosystem.
To your last point, the "money going in" comes from advertisers. They pay in fiat currencies, or via BAT. If they pay us in dollars, we purchase BAT as needed from the market. Users can also self-fund their wallet, if they have disposable income.
You watch fewer ads than before, which means (if the ads pay the same) that each website gets on average (i.e. if the split is the same as before) less money. As you describe it, only 70% of the ad-revenue actually reaches the user, meaning even if you watch the same amount of ads, websites get 30% less money, and that ignores that many people just opt-out of ads. (BTW do you know where that 30% go to?)
> The blockchain enables users to effortlessly and anonymously participate.
That actually makes sense. But if you want to get money out of BAT, don't you have to pay a transaction fee? And if you don't, then how does Uphold make any money to pay their developers?
For me it seems that there's money vanishing at every point and very little or nothing to replace it.
Also, wouldn't brave have a quasi-monopoly on ads in this configuration? Even if brave is an honorable company (and I have no reason to doubt that), it makes me uneasy to know that we are breeding another potential "too-big-to-fail" giant like Facebook/Amazon/Google.
Edit:
Rereading your comment again and noticing the "users can distributed bought BAT directly" part: Then the monetization system makes a little more sense. Do you have stats on how much people are paying in? Is the ultimate goal to get rid of ads entirely or at least shift over to a "pay for what you use" model? In that case I can understand that. (though the monopoly on website monetization part still makes me kind of uneasy)
You're correct that publishers lose revenue when ads are blocked on their sites, but not blocking ads means users are at an increased risk of being abused by malicious third-party actors. This is one of the main issues with ad and content blockers: they keep users safer, but they take revenue from content creators.
Brave is working on a model that reduces fraud, increases rewards for content creators, and rewards users for their attention. This won't be built overnight, let alone over a few short years. That said, we are making tremendous progress, now settling over 8-figures each month for verified content creators.
As Brave matures and develops, more options will become available for users and content creators to earn more.
As for transaction fees when converting BAT, you are correct. There are often transaction fees involved. But those often depend on how much you're moving around, if you're buying or selling, etc. Uphold and Gemini (our other partner in this space) may also differ between each other.
You're right about heavily centralization around Brave too. This is why we're working on THEMIS (https://brave.com/themis/), a protocol for decentralizing the Brave Ads ecosystem. We recently wrapped-up an effort in that space and blogged about progress: https://brave.com/themis-rfcc-wrap-up/.
We don't have stats to share on how many Brave users are self-funding their wallets vs earning with Rewards. That said, the latter category is naturally going to be much, much larger. It is also not an either-or thing either; many people opt-in to Brave Ads and also buy BAT to supplement their attention-based earnings.
I don't think the goal is to get rid of ads entirely, but rather to yield power to the user. Not everybody has disposable income, and therefore many people would prefer to opt-in to privacy-respecting ads, earn rewards for their attention, and support the Web by those means. For those who wish to self-fund, that is possible. They don't need to opt-in to Brave Ads either.
I.e Brave is bootstrapping on manipulation of the intent of the publisher.
A cleaner aproch may be to approach publishers offer them a "better way" and decuple it from the browser marketing privacy / reduced ad load.
Likewise standards bodies, NGOs and Gov agencies need to protect users in the web and app ecosystems making it a more level in respecting user privacy / reduced harm. To control publisher / advertising / user relationship in a fair way.
But we live in a time of fast pace asymmetrical software mediated warfair and a few eggs are going to be cracked along the way in to trying to build something better.
Brave doesn't inject ads onto webpages; so there is no scenario where you (as a publisher) would have our ads displayed on your page (unless you, yourself displayed them).
Please see this 5-minute overview of the problems facing digital ads, and Brave's proposed model: https://youtu.be/LsrrT502luI
Even if all ads on all websites were made in a privacy-respecting way, people would still use adblockers.
This is because people simply hate ads in their browser. It is because they make browsing experience miserable. They add bloat. They distract from the content. They add cognitive overhead. They slow down browsing. They are literally unwanted guests in our browsers.
So Brave’s model replaces one set of ads with another, basically achieving nothing to mitigate the problem itself - very existance of ads in the first place. What makes Brave’s ad model worse is that it offers people a monetary incentive for doing an activity (watch ads) that we know they are trying to avoid (by using a browser with an ad-blocker). So the very premise of this setup seems to be that people hate ads just because they are not privacy-respecting. But reality is that people normally simply do not want to be exposed to ads.
(btw the only ad based business model that would align all incentives is one in which users would be paying to see the ads)
And the content creator argument has long been debunked as smoke screen planted by companies in the ad business (and Brave qualifies as one), because monetizing any content through ads is the least efficient way to monetize creative work. What this model actually does though is incentivizes the creation of large quantities of low quality content.
The model for profit is around the bat coins gaining popularity. The payouts are extremely low for everyone.
Incorrect. Their revenue is in USD, and their payout is calculated using the revenue in USD. The price of the token does not affect them in any way.
Their model from profit is unbelievably simple. They are an ad network that uses the browser as a distribution vehicle. More people using the browser, more advertisers will be buying ad space, more revenue for them.
They do have a published roadmap about offering more services in the crypto-space (built-in web3 wallet with direct connection with crypto exchanges, use of NFTs to access features and services on different websites, etc) which are very interesting and it might even become a bigger play than the existing ad network. At the end of the day however, they can have a solid and sustainable business just with the ad distribution network.
- Most people won't paypal/patreon/send money directly
- The current system uses ads as a shorthand for attention. If you're able to get attention you get more ad traction and more money.
- Ads suck and are a corrupting influence on everything, if there was a way to directly award attention without ads that would be better.
- Brave replaces ads by tracking attention directly and attempting to reward it directly with BATs. These is done instead of cash because (I'm not really sure why) - I suspect because it's easier to manage and easier to split into tiny amounts.
- Flattr from the late 2000s (2007?) was similar, but with cash (Flattr = Flat Rate) the idea being you'd put in $XX/month and it'd distribute it depending on what pages you viewed. It was created by some of the Pirate Bay founders iirc. It never got much traction.
The issues I have with these services:
- Ads are bad, but the attention economy is the underlying problem. Removing ads is good, but still incentivizing attention for $$ isn't great.
- In the case of 'privacy' Brave has now inserted themselves as the tracker of all attention, this is very high risk and not a lot better than the ad companies. Sure you don't see ads but a lot of the bad slot machine incentives around content remain.
- I don't want to necessarily pay everyone based on what I view, what if what captures my attention is crap? What if I'm reading something for context, but don't support it?
---
I get what they're trying to do, reward people without ads and without making users pay - but I'd rather the ad model just die and if some businesses can't survive without it we probably don't need them. I recognize this isn't super realistic because companies compete on a global stage.
A business truly operating in the interest of users would make a browser that had ad blocking built in without tracking - and worked on subverting ads full time (what users actually want). This includes real privacy by not being a new middle man tracking attention. Apple is the closest to doing stuff like this with their new onion router VPN, making it easy to block tracking from apps in the store, etc.
Brave pretends its interest is privacy and browser users, but it feels like a rationalization to me. Brave's core business is attention tracking and taking a cut of that, if not now - when they have more power. Its user's attention is what they monetize - those incentives don't lead some place good.
The browser is sent a list of ads, and the browser decides which ads to serve based on its metrics. Brave doesn’t see this data and the user can choose to participate or not.
There are no easy answers, but this is an interesting model and a reasonable compromise for many.
The ads from Brave are completely separate from the website. They are presented as an OS notification pop-up.
> Somehow there has to be money going into the system that supports its own existance.
Yes, of course. Their revenue coming from the advertisers that get to place ads on their notifications. They only pay to the users a share of this revenue. If for some reason they stop getting advertisers, they will stop paying the users. Simple as that.
> This means that you get potentially even less money.
This is making the very bad assumption that they have a fixed revenue. As their user base grows, more advertisers will be interested in placing ads on their network and their revenue will increase.
> Also, why do they pay out in BAT?
Primarily, because it simplifies the logistics and allows them to escape the regulatory hurdles of having to become licensed money transmitters, and lets them outsource all of that crap to the crypto exchanges. A second-order but also important effect is that it attract users who want to speculate on the token.
> Why should I support someone by using BATs instead of paypaling/patreoning/whatever-elseing him the money directly?
Whynotboth.jpg?
Patreon is not bad, but they are not in a business that can fight surveillance capitalism. Patreon does not have a way to block Facebook from tracking my browsing. Brave does. Patreon does not block the Youtube ads from the people that you want to support. Brave does.
Lie. Brave doesn't track you. Your ad data never leave your machine (a bit like your bookmarks). The ad engine works privately on your computer and not on Brave server.
I can't really see how zero-knowledge proofs could solve this. There is no cryptographic way to prove that software executing on a clients machine triggered a notification. Especially on Linux where an open source notification manager could be modified to reject it.
I'm equally not so convinced on this anonymous ad system they claim to have built. The browser claims to generate an adID based on your history but encrypt this info to the advertiser. Maybe someone who has actually interacted with the ad platform can provide more insight on what information is exposed.
Zero-knowledge advertising sounds practically like an oxymoron to me, but hey they claim to have made it work.
A sufficiently-capable attacker could conceivably trick the browser into thinking a native OS ad-notification was displayed, we do rely on the OS to inform us at this point (though preview versions of Brave do not have this dependency), but we have considered this as well.
The main threat here would be an attacker who attempts to automate the confirmation process, and potentially duplicate it across various VMs or OS instances. Fortunately, we've considered this too. For reasons I hope are obvious, I can't go into greater detail here.
But yes, when you view an ad, that gets recorded somewhere (so that you can get rewards, and the advertiser can be billed).
You decide if you’re comfortable with this or not. The feature is easily turned on or off.
Every request Brave makes "home" will transfer private data like IP address of the user and browser fingerprint, regardless of the payload. Can you clarify what is done with this data?
Also if it is true what says in the article that some requests "home" can not be disabled, why is that the case?
Presumably it would send the same data whenever it checks for software updates too.
I can't think of a threat model where downloading updates and downloading ads are different in terms of user privacy (except, of course, that a malicious update can do far more harm).
I'm happy to discuss any requests you like; we also document all of this to the best of our ability on GitHub as well (https://github.com/brave/brave-browser/wiki).
As for disabling requests, this is a valid petition. Our goal is to have no extra requests when and where possible. We've worked hard to keep them to a minimal. There are some requests (e.g. product update requests) that we've been hesitant to make more easily blockable, since this could potentially leave large swaths of Brave users disconnected, and increasingly vulnerable.
> We've worked hard to keep them to a minimal.
How is 80 requests minimal? (source: your own above-mentioned article). It seems to me that 0 requests would be minimal.
What is preventing Brave from being a zero-telemetry browser by default?
I'm not sure where you saw 80 request; my network analysis post (https://brave.com/popular-browsers-first-run/) shows Brave issuing 70 requests over a 10-minute period. Compare with Chrome (91 requests), Firefox (2,799 requests), Edge (367 requests), and Opera (106 requests).
0 requests is not realistic, IMHO. When you launch a browser you want to make sure the user has a fresh local DB of known-malicious URLs (so you don't have to pipe each request through a look-up service, like Opera does) for client-side checking. You also want to make sure the client has an updated list of blocking rules for other types of content. There's quite a bit of setup needed when you launch a web browser.
Zero telemetry is unwise, assuming you want to build a product that works for a diverse set of users, devices, and environments. The main issue here is not whether you collect telemetry, but [how] you do so, and what that looks like. Brave is careful to preclude abuse from the design phase; see https://www.brave.com/p3a for more on how we handle Privacy-Preserving Product Analytics.
>0 requests is not realistic, IMHO. When you launch a browser you want to make sure the user has a fresh local DB of known-malicious URLs (so you don't have to pipe each request through a look-up service, like Opera does) for client-side checking. You also want to make sure the client has an updated list of blocking rules for other types of content. There's quite a bit of setup needed when you launch a web browser.
It is quite realistic and possible. Both examples you gave can be opt-in. Perhaps I do not want my browser to arbitrarly show a malicious URL warning. Updating content blocker can and should be opt-in as well. Maybe particular rule set work well for my setup and I do not want the update to break it.And maybe I just do not want the browser to send requests home.
And even if both of these are enabled these should be just two requests - what is going on in the remaining 68? It just looks like a very high number even if it is smallest among other test browsers (which doesn't make Brave good, just makes every tested browser broken in this regard).
>Zero telemetry is unwise, assuming you want to build a product that works for a diverse set of users, devices, and environments.
This is based on what? You should really provide an argument when making a bold claim like this.Zero telemetry should be the corner-stone of any privacy respecting product. Only zero telemetry ensures and guarantees that user privacy will be 100% respected. Everything else, even sending just one unwanted request "home" or anywhere else, can and should raise valid questions about what is done with the data including IP address since this will be closed source even in an open-source browser like Brave.
Telemetry is crucial to understanding how your product is used, as well as understanding what works and what doesn't. You cannot have one-on-one conversations with 30M+ users, which is how you learn, develop, and improve.
Brave needed to find privacy-respecting ways to achieve similar "conversational" insights. That's what we've done with Privacy-Preserving Product Analytics (https://www.brave.com/p3a/). P3A doesn't collect any user data, operates on a set of published "questions", and uses vague, range-based "answers". We also split up the requests to avoid developing a "fingerprint" from the answers.
Besides, malicious URLs directory and content blocking hardly qualify as 'security’ features.
Telemetry can be useful, and totally feel free to have as much of it as you want, as long as users opt-in into it. You seem to be making a lot of choices on the behalf of the user, when your default setup has whopping 70 requests “home".
There is a way to achieve everything you want, and for a privacy respecting product (or one claiming to be one) these choices absolutely need to be users' and not yours (by the very definition of the term privacy)
Epic's mobile browsers were built on Brave/Chromium, but now that Brave has endpoint and other dependencies as mentioned it doesn't explain, it isn't possible to continue to build on them or even test them since Brave features don't work in outsider builds.
What unexplained endpoints/dependencies does Brave have? I believe I demonstrated otherwise (with links to external resources) here: https://news.ycombinator.com/item?id=27552530.
> For example, this allows the removal of specific tags in HTML documents before they are parsed and executed by the browser, something not possible in a reliable manner in other browsers. This feature requires the webRequest.filterResponseData() API, currently only available in Firefox.
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b... I'm going to trust Gorhill on this one. If a significant feature _does not exist_ in Epic then the only way that it couldn't hurt performance is if it was somehow useless. I suspect the Epic people (accidentally?) didn't measure that aspect.
This seems particularly irritating because, let's say you set your browser to show you the max amount of ads for a while. You saved up for a few months, decided you had enough, tried to cash out only to discover that slap in your face that they never mentioned. Of course this benefits them, but the fact that the browser puts you in the situation of giving up your privacy to receive money is ridiculous for a "privacy" browser.
I don't like that Brave doesn't say, on their Brave Rewards page, warning: You will need to give up your privacy to cash out. If that's OK with you, great; if not, don't set your browser to show ads for months before you try cashing out or you'll get a nasty surprise.
From Brave's perspective, there's also a conflict of interest here. Remember, when an advertiser spends BAT to show an ad, 30% goes to Brave and 70% to the ad receiver. Brave has every incentive to get that 30%, don't they? If that means you were fooled into leaving your browser showing ads thinking you could cash out without losing your privacy, they benefit. And that's why it really smells fishy that they don't mention it on their product page.
I guess users could also send the tokens elsewhere to try and find an exchange that doesnt care about money laundering laws - but governments get quite involved in crypto.
Or is transfering tokens not possible?
This is what is also egregious. Yes, BAT is decentralized when you move it around in wallets, but as far as the browser is concerned, all BAT you earn from receiving ads is actually quite centralized.
I wouldn’t have any interest in using such marketplaces.
As for Brave: Whether or not KYC or other regulations explain their behavior, any cryptocurrency rewards program has an inherent incentive to make it as difficult as possible to cash out. People who cash out almost always sell their coins, putting downward pressure on the price. If they can use dark patterns to reduce the number of people selling coins, the coin price stays higher.
The ideal cryptocurrency rewards program (for the crypto, not the users) would give people coins but almost force them to hold those coins and make it as difficult as possible to sell. This simultaneously hypes the coin by spreading awareness and removes downward price pressure by making it difficult to sell. This almost always means the company or founders have a lot of the coin that they plan to sell off as it becomes popular.
Virtually everything that comes attached with arbitrary crypto tokens or rewards is a scam to make the founders wealthy while the users chase pennies.
If I go look at any other service which requires that kind of information, it's always right up front. Want a Robinhood account? Great, you have to provide the info when you open an acocunt.
I just donate BAT to sites.
Brave does “request info up front” for users who want to use the wallet. Requesting it from users who won’t need it is a waste of time.
All Robinhood users perform financial transactions, very few Brave users do.
I would prefer a wallet that I have control over, but I kind of ignore the BAT stuff and just use it because it’s a clean browser that’s easier for me than managing adblocker plug-ins. The tokens are just a bonus.
This is the government's fault not Brave's. There are laws that enforce the requirements. We do not have the freedom to move value or money around freely any more.
Brave may not be implementing the dox'ing, but they appear to be requiring you to use someone else's implementation which is absolutely their fault.
They have to figure all that out before they give you access to your account. Which means, yeah, there may well be a good reason for them to require you personally identify yourself before giving you access to the tokens: if they didn't, they'd risk getting into serious trouble with the authorities.
They didn't technically need to contract that stuff out to a third-party company, of course. But, from a practical perspective, they did. They're a small browser company and financial regulation compliance would be a huge and burdensome departure from their core skill set. I don't think they could have afforded to do it themselves.
What I'm not OK with is that Brave isn't upfront about this.
Why they chose to implement the design in this way is not what I would expect.
Because cashing out is kind of the entire point of BAT?
If creators couldn't redeem their BATs for actual spendable currency, they wouldn't really be any different from a Facebook Like button that people have to pay to click.
Yes, I understand there is an implicit difference here, but this just shows how dumb KYC laws are to begin with as they can be easily bypassed by criminals and serve only to dox the law abiding citizens.
I, as a pro-social, well behaving, net positive contributor to society - have to trust everyone I do business with with my personal information. It's honestly absurd, if I were a criminal I would bypass this with great ease, yet because I want to behave legally I put myself at risk for identity theft frequently just to be able to do business with other people who also likely don't want to be responsible for securing my private information.
AML is probably Anti-Money Laundering. It again has nothing to do with informed consent. It is possible to prevent money from being laundered by telling a person up front, before they agree to sign up, that they have to give their private information to a third party.
CYA is probably "Cover Your Arse". Again, it's not a legitimate concern for the same reason as above.
IANAL is obviously not a response to the original concern but merely intended to reduce the risk of the reply. But there's no legal issues being raised. The issue is purely whether or not a business who praises their privacy credentials should clearly let their customers know that, if they choose to engage in business with them, their private information will need to be shared with a business who they may not trust.
If OP's story is true, Brave is not above engaging in distrust for dollars. That's the lesson to be learnt here. Brave doesn't care about your privacy. They just hope that by marketing privacy, they can get a few customers. And they will and apparently do engage in shady practices that compromise your privacy. No acronym can justify that, other than something that stands for "Businesses need to be responsible for their actions, not just their profits".
It's entirely possible to trade bat for many other coins on exchanges without KYC, but Brave forces you to be unable to do that (regardless of your local laws it seems?)
This is something Brave could easily fix by just exposing an API to allow you to do what you want with your BAT instead of forcing you to use a third party KYC service.
If you want to get real BAT that you could send to any address, send to Uniswap, or cash out, you must create an account on Uphold and complete full KYC before you can withdraw. That's when, invisibly, the IOU BAT becomes functional, cryptocurrency-like BAT.
It's like there are 2 BATs in reality despite the marketing. FakeBAT and RealBAT. FakeBAT only works within Brave's approved creators and is what you receive in your browser, and you can convert it to RealBAT which is on Ethereum and ERC20 compliant but only if you do KYC.
And, you might be OK with that for what it is, and might not want money laundering. Fine, but don't advertise it to me as an extension of a privacy browser. This is perhaps the least private cryptocurrency ever outside of USDC.
Ah, the world has become a strange place. I currently use no less than 5 different browsers for different contexts, but mainly Chrome for Goog properties on the seldom occasion I have to go there, FF for almost everything else. Then the corner cases...
Of course this is a pipe dream with the modern ad-powered web. Why would tech giants have a desire to make changes that would affect their main revenue stream? Advertisers wouldn't be thrilled either.
Still, I think it's the best idea that actually has some merit of working at scale to change how the web is monetized today. And we need more of those. Just maybe not executed by Brave Inc.
This is Brave's own cryptocurrency that they use to sell their privacy-based browser. It's an important distinction.
That this optional payout requires identification seems to be A) a legal requirement, and B) an implementation detail of second-rank importance in the grand scheme of things.
Feels far-fetched to get one's knickers in a bunch over stuff like that not being at the forefront of their marketing.
Look, maybe this is a good idea, and it is the future of getting people to pay for stuff like news or software. If so then they need someone who understands that vision and can project it with confidence. Right now I have no idea who runs Brave or what person I would look to for understanding their goals. For such an innovative concept you really do need a visible delivery vehicle with whom people can relate.
If anyone knows any good resources to learn about the ISP nuts and bolts that make internet magic happen between my modem and everyone else’s servers I would be most appreciative.
Well that's vague. What are the symptoms? How would comcast even know that you changed DNS settings? It's possible to infer that from DNS queries to their servers dropping off and traffic to 1.1.1.1 or 8.8.4.4 increasing, but I doubt comcast is competent enough to build that sort of detection system.
Looking at you, Chromecast that tries 8.8.8.8 40 times an hour even though you know perfectly damn well that 10.10.10.1 is working
And with newer decides that use DoH, you can no longer prevent devices from contacting their own DNS provider without totally firewalling them (or perhaps using some IP blacklist or whitelist, if available?)
Everything that I don't have complete visibility into the network stack of goes on a VLAN that does not forward traffic to the internet, it advertises a proxy via WPAD and DHCP option 252. I have a whitelist of hostnames that each device is allowed to make CONNECT requests to, so far there is only one.
If it's not a plain unencrypted HTTP request to my proxy, or a CONNECT request involving a server/device pair I've decided to trust, it's not going anywhere.
This breaks a lot of things that I would just as soon rather do without. I can't change my universal remote hub settings from the vendor portal, boo-hoo. I can't view my cameras from the hardened VLAN or from the internet (unless I VPN in first since the only copy of the recordings is on my local NAS)... good.
Specifically for detecting if a user is not using their DNS, yes you could correlate a user's http requests (unless you are using ESNI the requested domain is in plaintext by design) with traffic logs on their DNS server and observe that there was no DNS request to the ISP DNS server before a request was made, I don't think that would be necessary. Most users use the ISP default DNS - that's your baseline. If most customers hit your DNS X times per Mb of web traffic, then someone using a custom DNS is going to stand out like a sore thumb.
Again, 100% agree that ISPs are not very technically competent (to put it mildly), but as time marches on the ability to both capture and more importantly analyze and report on that data is becoming cheaper and easier. ISPs want to get value from (sell) your data and vendors want to sell ISPs subscriptions to analytics and other platforms that bring them reoccurring revenue. Data from customer DNS is one of the most valuable sources of information an ISP has and I would be surprised if there was not at least an attempt to know how many customers did not use it.
I have an "XFi Gateway" combination modem/router provided by Comcast (perhaps my first mistake) so the DNS settings are restricted and cannot be changed. I have the Comcast modem/router set to bridge mode and connected my own router where I can control the DNS settings.
My understanding is the DNS settings closer to the client control. So in addition to having set my router to Cloudflare's DNS I also set my devices as well. One day, maybe a year ago or so, I'm on HN and I click an archive.is link, read the article, and go to the discussion thread only to see several comments about how archive.is is blocked by Cloudflare DNS. I checked the DNS settings on my MacBook and router and I was indeed using Cloudflare DNS but for some reason I was able to access the "blocked" address.
So I went to the terminal, cleared the cache, and checked nslookup archive.is and it responded correctly. Then I checked a nonsense DNS server: nslookup archive.is 5.9.3.7 or something and it still responded correctly. I tried the same with different websites and got the same result. So I searched "see my DNS server" or something and found a few websites but they all showed Cloudflare. Very odd.
When I logged in with my VPN, Mullvad, and changed the DNS settings on the router and my laptop to Mullvad's and repeated the experiment it finally returned NXDOMAIN. Then I disconnected from the VPN but left Mullvad's DNS settings, repeated the experiment again with the same results - even when I was using a totally bogus DNS server it was returning the correct IP address.
That's when I installed Wireshark and, lo and behold, I could see the requests that should have been going to 1.1.1.1 or 5.9.3.7 going to 75.75.75.75. Comcast.
A call to Comcast was, as expected, a complete waste of time. First they told me it was using their DNS settings because of "their firewall" and then they told me that if I used their built-in router rather than mine + bridge mode I wouldn't have the issue at all.
Messing around in Wireshark I eventually determined the issue had something to do with one specific port that was making the requests (I can't recall how but I think because I could see Mullvad VPN was using a different port for DNS?) so I fiddled around and forced (or maybe redirected?) my router to use that port too and that finally worked in avoiding the Comcast servers. But, knowing just enough to be dangerous and not entirely sure what I was doing, I didn't keep the forced port and decided I'd have to get my own modem and use my VPN in the meantime.
Before I had gotten around to buying a new modem (this was somewhat early in the pandemic) I saw a post on HN about NextDNS and decided I'd see if I ran into the same issue. I didn't, as far as I could tell at least. When I run Wireshark now (I still use NextDNS) I don't see any contact with 75.75.75.75 or 75.75.76.76. I think this is because NextDNS uses DoH? But who knows.
Like I said, I only know enough to be dangerous so perhaps I just had something configured in an odd way that made the Comcast servers step in as a fail-safe and there's a totally innocent explanation. But based on my experience as a Comcast customer I don't really think they're deserving of the benefit of the doubt so I've definitely got a bit of a tin foil hat when it comes to them secretly messing around with my traffic through the leased modem.
It's less common, I think, because more people know how to check their speed than change their DNS.
Or, somehow more cynically, the ISP makes money from selling the data collected from DNS, so punishes people who use a different DNS provider. (DNS is plaintext-by-default, so I don't quite see how this would work, but it's possible.)
Or perhaps the system uses DNS lookups as a proxy for “is a human browsing the web”; if there aren't enough, it's clearly some kind of automated computer program that doesn't deserve internet access.
I know the best answer for a Comcast DNS server in New York is the server I physically installed in a New York Comcast rack, but when a public DNS server asks me from Paris, maybe I suggest a London server, 'cos that's pretty close to Paris, shame that New York isn't.
EDNS Client Subnet is a feature that lets a DNS server say OK, I'm asking on behalf of somebody from 10.20.30/24 and so my system can do the same trick with ECS. But doing this unwinds most of the privacy benefit of using a public service, so several famous public DNS servers explicitly do not use ECS.
Obviously the cheap bulk host used for some Single Serving site like "Is pizza rat mayor of New York yet?" isn't affected, that is only one server and it is wherever it is, but somebody like Netflix absolutely is affected by this because they have their machines close to the customers to deliver better performance and if they don't know where the customer is that inteferes.
QUIC has an optional feature called Connection Migration to help improve this, the remote server is like "Um, now that you're connected to www.example.com here in Glasgow, Scotland, I notice your IP address is from Tokyo, Japan, and this is just a suggestion, but maybe talk to my identical twin also named www.example.com in Tokyo, Japan for better performance? Here is the IP address to try"
https://arstechnica.com/tech-policy/2009/08/comcasts-dns-red...
That's aside from all the political shenanigans they pull, trying to kill municipal broadband and net neutrality. There's scarcely a more evil ISP.
I switched away from Comcast as quickly as I could, and never had trouble with either smaller cable companies or fiber providers.
https://datatracker.ietf.org/doc/html/draft-livingood-dns-re...
Their own words
As far as Comcast, I'm stuck with them, too. At least in my experience, they don't monkey with DNS - I run and use my own DNS servers, and have never seen interference.
They do run deep packet inspection, and if they detect you, for instance, torrenting commercial media, they'll inject scary messages in port 80 traffic. Given that nearly all web traffic is encrypted now, the main effect of this is to break things like automated `apt-get update`s.
One thing you can do to detect transparent DNS hijacking is to ask a nonexistent server a question. Something like `dig @13.14.15.16 news.ycombinator.com` should not give you an answer. If it does, someone's spying on and/or gaslighting you.
Bittorrent protocol encryption is only useful to protest against the use of DPI for bandwidth shaping, it has no influence on privacy.
Even with (the weak) encryption, connections to trackers and DHT nodes are easily identified
Fairly googleable with "Comcast sandvine". Afaik they haven't done anything like that for years, though.
Wasn't there a HN story about people doing exactly that to figure out what condition people were looking up on WebMD? I don't recall when.
TLSv1.3 on the other hand sometimes encrypts the hostname (eSNI) and most of the TLS handshake, so there's much less data to fingerprint. It's not as widely supported, but support is growing...
[1] https://engineering.salesforce.com/tls-fingerprinting-with-j...
//Edited to clarify that eSNI isn't default behaviour of 1.3
eSNI is not the default behavior, and has few deployments at scale. TLSv1.3 transmits SNI in the clear.
eSNI is being replaced with ECH[1], but in many cases, there is a 1:1 relation between the IP address and the site being served. ESNI and ECH are only one layer of obfuscation - a middleman (such as an ISP) could still snoop your DNS (unless DoH/DoT) and/or correlate the IP addresses you connect to against the hostname(s) presented on that server.
Attackers already do that today with nmap - scan publicly addressable ranges on port 443 and see what names are on the certificate presented by the server.
Encrypted Client Hello isn't finished. I would say the basic idea is settled, but there are plenty of technical nits and it might be next year before they have a final document.
Eventually the idea is that ECH will be GREASEd by always sending ECH data, if the client knows it is supported it will use ECH and if not then it will fill out the ECH data with random nonsense. Since it's encrypted, an adversary can't easily distinguish one from the other and a site which doesn't offer ECH will ignore the nonsense anyway.
The idea of probing servers on port 443 works well enough for dozens of popular sites with dedicated servers, but much less well for the long tail. A bulk host won't give you a list of every customer just because you hit port 443 on each server and pled ignorance, you'll get a generic "Under construction" page and no information.
That's supported in supported in tls 1.3, but actual deployment/usage is spotty (it's an extension, not mandatory). AFAIK it also requires your DNS to cooperate, since that's how it gets the keys for the initial handshake.
As garbage as most US ISP options are, I'd trust them long before I trust random VPN services. And I can be reasonably certain that my physical connection goes to Verizon. My virtual connection could be going anywhere and I just have to believe that it's to people who are who they say they are.
You’re just trading one for the other and that new one might not even have to follow the same laws.
any VPN worth its salt has a business model built around not logging data and not selling data. Your ISP on the other hand, is in the business of selling you internet access. Your data is a secondary revenue stream for them.
They two are not equivalent.
With us technical people it's more likely, but not necessary for others that may have just heard 'use a vpn' and went to the App Store, searched for 'vpn' and prepaid 3 years.
Hide my ass VPN is still up - https://www.hidemyass.com/en-us/index
Depending on where you live the likelihood of your ISP doing something exceptionally nefarious might be way lower than some random VPN client someone finds on an appstore.
Whether VPNs solve the issue or not is irrelevant to my point. Their primary advertised feature is to hide your traffic from your ISP, McDonalds or whoever, and people buy them. (Secondary feature is masking location for streaming services, which doesn't really work).
EDIT: I wasn't thinking, OP is completely right. Sorry for the snark.
This is very outdated, at least for a significant number of smartphones (including all iPhones, but not limited just to those). Apple and IIRC other manufacturers long since isolated the baseband, treating it simply as a standard USB or PCIe peripheral (and in the latter case using an IOMMU with it amongst other things). It has zero special access to anything on the rest of the phone which in the smart phone era is where everything of interest actually lives and happens.
Source - used to certify these things in a lab environment.
Browser-based tracking, on the other hand, can see just about everything, because it's looking at the state of the data after it's been decrypted. And it can, with a reasonable degree of confidence, individually identify people, even when more than one person shares an internet connection, and even when one person uses more than one device or connects to the Internet from more than one location. The higher fidelity of that signal does imply that it's a greater privacy threat.
A more far-fetched attack is a sort of timing attack: if you first visit arstechnica.com and then shortly afterwards visit Amazon.com, one could look for links to Amazon on arstechnica and from there have a decent guess what product you viewed on Amazon. This becomes a lot more feasible when paired with the first attack mentioned above.
https://www.telegraph.co.uk/technology/news/8438461/BT-and-P...
Hoarding itself is beyond the sophistication of most service providers in the present day.
Also many ISPs are also carriers, which makes things worse.
Source: worked for telecos, have seen a lot of shady stuff myself.
Now they might think differently because there is a market for info. Thank you government...
IMO: what's left of that issue is getting solved.
Ten years ago you’d be right, but right now that business is dying rapidly.
There is also hardly anything you can do about from your side. Using a vpn or similar solutions is only shifting the problem from one provider to another. You can reduce the exposure with some measurments, but they are also expensive and complicated.
But for this (and other) reasons companies have started to fix it from the server-side by offering encrypted connections and working on ways to hide your trail from the middleman and their attatched agencies.
An ISP might not know what a user does at pornhub.com, but the ISP does know when and how often the user visits pornhub.com and how much data is exchanged when they do. I'm sure someone would pay for that kind of fingerprinting.
It's profitable enough that there seem to be ads for it baked into everything. I won't repeat their name here, but have you avoided that "Sponsored by NxxxVPN" all over the Internet/baked into every YouTube video that has sponsored videos?
https://old.reddit.com/r/privacytoolsIO/comments/nvz9tl/_/h1...
https://old.reddit.com/r/brave_browser/comments/nw7et2/_/h18...
https://old.reddit.com/r/brave_browser/comments/nw7et2/_/h1f...
Another thing I’ve noticed in security (and I actually work in this field) is that if a project makes some progress but doesn’t address all the things (e.g. Signal end-to-end encryption for the masses but it uses a phone number or isn’t federalized), people criticise so strongly. It’s like, ok, but give some (actually a lot) of credit because it’s literally the best option right now?
Colorful and emotional language gets attention. Dispassionate writing doesn't. Whenever I see people criticize an author for a little rhetorical flair, I play the famous "Pirates of the Caribbean" scene in my mind:
Hacker News: "Your article is the most strident and obnoxious piece of technical writing I've ever heard of"
Author: "Ah, but you have heard of it!"
Also, I am not sure people do remember these types of articles. Perhaps they remember some notion of the content, but I'm doubtful many detractors would remember the author.
The main thesis is that: Brave's adblocker is just uBlock Origin and so it's better to just use uBlock Origin on FF.
But Brave's adblocker is not just uBlock Origin so the entire article falls apart.
Everything else is just trying to misrepresent everything in the worst possible light.
> It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities.
Righttt... we're not children, we all know what you're trying to do here.
Don't use Brave. Tell others not to use it.
Brave runs on the exact same ad model as Chrome, they just inserted themselves as the middle man. There's no actual value provided here and it's basically just "big corporate bad" marketing
You couldn't be more mistaken here. I covered the history of digital advertising and the introduction of Brave's model here: https://www.youtube.com/watch?v=LsrrT502luI.
In short, Brave's model is largely the inversion of Google's model. With Brave, users must opt-in. Google doesn't ask you to opt-in. With Brave, user data remains on device. Google requires the remote collection of your data, as well as the broadcasting of it to third-parties. With Brave, users decide when and how many ads they will be shown. Google shows you as many as they can get away with. With Brave, user's collect 70% of the revenue for their participation. Google gives you nothing, but takes quite a bit. With Brave, Brave Software learns nothing about you, your interests, or your browsing history. Google learns quite a bit about you, harvesting as much data as they can get away with, and using it across contexts and domains.
And as to Brave's model of pooling users and preserving anonimity, isn't this exactly what Google's FLoC is? As far as I'm aware the dreaded third party cookies seem to be on their way out. I'll give Brave props for being a frontrunner on this, but that's not an inversion of Google's model, this appears to be exactly where everyone is going.
I think you're misunderstanding how Brave's anonymity works. We don't rely on something like k-anonymity where we hide users behind some common cohort ID. Suffice it to say, we're not big fans of FLoC: https://brave.com/why-brave-disables-floc/. Brave's anonymity is based on the inversion of the flow of data. Rather than collecting information about users, Brave transmits data from advertisers to the user's device for local scrutiny.
Google is in no way moving towards the Brave model; it they are far too dependent on user data, IMHO. Brave, on the other hand, was born with a Can't be Evil mindset; every step of the way we have built the application and service to preclude abuse and overreach.
Out of all chromes of Chrome I have sampled, Brave has the best visual polish. Best regards to your UI/UX design team.
>What happens if you send a tip to an unverified creator?
I click “tip” for my YouTube channel, and the screen below comes up. The “Learn more” link goes to the Brave FAQ, which says that no funds leave the browser until the creator verifies — but admits that previous versions of Brave worked differently, and sent the tokens to Brave in the hope that the creator would sign up at some point.
It would seem this is possibly no longer the case, I'd love an update on it.
I prefer the orgs I interact with to be perfect and never make mistakes and when they do (but they don't because I only interact with perfect institutions) I prefer them to double-down instead of improve.
He is expressing skepticism towards their original intentions and you like how they responded. No need to talk past each other.
Worth pointing out that part of the reason it was hard to just refund people who donated to non-verified creators was Brave actually caring about privacy, so the donations in question were completely anonymous.
So when it was pointed out that it's still a problem, they came up with a solution that I think strikes a good balance.
Fair enough.
To me, it couldn't have been more obvious that collecting "money" in creators' names and also misrepresenting that was Bad™. I'll try to be gracious and chalk this up to "lack of common sense" instead of "part of the evil plan".
But I'm still willing to forgive if I think the course-correction is adequate, which in this case it was.
We identified verified creators as such, but didn't make the non-verified state as explicit. We largely followed a similar pattern to that of Twitter (checkmark for those who are verified, and nothing for those who aren't).
When you visited a YouTube channel, website, etc., we would show you the name and favicon for that resource in the tipping UI. In the case of some YouTube channels, the page name was just the YouTuber's name, and their favicon was a picture of their face.
The changes that Tom Scott and others suggested back in 2018 were ground-breaking. They helped us realize some naïve decisions in the UI/UX of the tipping process and more. We moved quickly to implement those changes (https://brave.com/rewards-update), and the entire system is now substantially better as a result. But there was never any ill-motive involved. We had BAT, and we wanted users to give it to their favorite creators. Tom Scott approved of the changes at the time, which was a nice way to wrap things up
Just because someone can collect the money/currency at a later date doesn't make it fine. If I collected money on behalf of charities yet only gave the money to the charity if they explicitly asked me for it, I doubt that would go down well with donors.
I could even use the situation to my advantage by gaining interest on the donations in the time between it is donated and I pass it on. I suspect Brave was benefiting in a similar way - all the donated money would not be traded while Brave were holding onto it, creating a scarcity which would benefit BAT's prices.
1. Do something shady and/or incompetent to make money
2. Ignore an internet backlash calling them out for it
3. "Fix" said shady thing
4. From then on out, aggressively deny doing that thing everywhere it's mentioned, without acknowledging that it used to be the case
Brave seems like an adequate browser for some niche use cases and probably has some cool tech. I do not trust the company or people behind it to have my best intentions in mind.
It definitely feels like they like to constantly push boundaries, and not in a good way.
Of course brave markets to you with ads. That's the entire point of the web browser. To ad-block, but then to replace it with a suitable privacy protecting alternative to the point that Brave (and everyone else) has no idea which ads you were served and what your browsing history is. The entire point is to mot just be an ad blocker, but to be private, and to provide a workable alternative to the ads that track us on websites.
Furthermore... brave lists on their website what they collect in analytics programs. And... it's not much. They also send the answers in what they call 'low resolution', which basically means multiple choice with ranges making it a lot harder to identify you compared to a specific number. Sure, it's not no tracking at all, but it's probably pretty close to the least you can get to serve relevant ads while serving a general populous.
It is true that it'd be nice if they forked off Chromium at some point so they are less in Google's hands. We can all use more of that.
So, at least for me, this kinda falls on deaf ears. It's missing the point as to why Brave does what it does.
Take a look at https://brave.com/brave-ads/
Brave goal is to acquire as much users as possible to sell them to advertisers. They are no different from Google. Might as well use Chrome with ublock origin and farm crypto on your own.
And then you have Chrome sending data directly to Google, the auto logins, dark patterns, etc, which you don't get with Brave or Vivaldi.
I was looking at their media kit[0]. They link to a presentation[1] which mentions that the ads are sent to the browser and then the browser itself picks the ones that should be shown to the user.
If this is really the case, then the browser isn't sending that information to the ad server.
Yeah, maybe. I was just pointing out that it doesn't send the user's preferences to a server.
Exactly, "seems". Once again, good marketing from the Brave team. Heck, they even sponsored chess grandmaster Hikaru Nakamura on his Twitch stream.
It's not utopian, but works from a capitalist's standpoint. And a lot of real users like it!
I guess my point is that not all tracking or ads are the same. You can track clicks and views of a banner without profiling users across multiple sites and apps, learn all you can, and then let advertisers target them.
What matters to me is how much data they collect and how they use it. It seems pretty clear to me that they go out of their way to collect less data, and try to be very privacy concious about it.
Do you think they are lying about that? I personally don't, and the code is there for us to audit (the only closed source part of the browser is the part that guarantees it's a human not a bot viewing the ads as far as I know). So I think it's pretty safe to call them much better than Google and their revenue model is certainly a lot more stable than Firefox's.
This is a big difference so using Brave vs Chrome doesn’t result in a company having a record of every site browsed.
Brave lets you turn off the ads. They also pay you cryptocurrency if you decide to turn them on.
I, for one, wouldn't complain if some financially solvent (self-sustaining, money-making), reasonably ethical and non-exploitative web browser existed (the same for search engine, OS etc.). In the economic system that we have it could be more efficient in marketing -> market share among privacy-unaware people and so on.
So maybe we should strive to have a reasonable, analytic discussion what business practices are acceptable (rationally, if not emotionally at first glance) and which are not. This does not mean that we should just eat up whatever "privacy entrepreneurs" think of. But the tone of TFA feels a little less convincing because of the sprinkling of phrases like "their shitty program", like expecting you've already made up your mind.
Nobody in the ads industry wants this, and a good 90% of the privacy sector is watching Brave in horror. Creators will make less money and be exclusively paid in a fiat currency, which probably won't appeal to anyone either. If nobody can reconcile Brave's existence, it will always be a second-class citizen on the web, even if it is forked from Chrome.
Okay, so which 5 extensions? There has to be more information on this somewhere. Article seems kind of lazy and definitely loses steam after the second half.
"Many people are saying this. Note that I'm not saying it, I only say true things. But I want you to think it anyway."
Really?
* https://spyware.neocities.org/articles/brave.html
... which doesn't really add anything to the original assertion as we don't know what the extensions might do. The statement is all all there is.
The only other thing I could think of is "chrome://components/" which also exists on Chrome and updates some browser components.
I downloaded and extracted the files. They look like helpers or partials for Brave internal extensions.
All of them include manifest files with their names:
- 1_0_14: "Brave HTTPS Everywhere Updater extension". Contains a 1MB ZIPped database of https domains.
- 1_0_21: "Brave NTP sponsored images component". Contains three photos (to display in their new tab probably).
- 1_0_22: "Brave Local Data Files Updater extension". Seems to contain whitelists and blacklists for extensions, autoplay, referers, trackers, etc.
- 1_0_498: "Brave Ad Block Updater extension". Contains a 2.4 MB filter list for their adblocker implementation.
Nothing seems to be harmful at all. This mechanism is used by almost all Chrome/Chromium based browsers to update their internal extensions and components.
But, if the poster cares about backdoors... Well, every major browser out there has features that could be used to backdoor their users like Firefox Telemetry Experiments (which download xpi files) and Chrome Components. They also can change properties at will unless its disabled (via flags, about:config, recompiling, etc).
Note: I'm a Vivaldi and Chromium user. I only use Brave with iOS which is kind of a different beast (since everything has to be implemented on top of iOS provided WebKit) since it somehow blocks ads better than stock Safari with AdGuard filters. For stuff like banking (on iOS) I use Safari.
Note 2: Blink and WebKit have deviated quite dramatically so they are indeed different browser engines (like Gecko is) with different implementations, quirks and bugs.
This article is incredibly slanted. It takes every single possible fact it can and spins it into "Brave Bad."
Something like this:
> Brave is just another Chromium skin. So at the end, when using Brave or any other Chromium based browser, you’re giving marketshare to Google and supporting their evil web empire.
Is simply not true. Every browser that isn't Chrome, every search page that isn't google.com, sends a message to not just Google but other competitors in the space that users want change.
In addition, in an ideal world Chromium would be able to build enough momentum through community support (or support from MS or others) to provide a healthy fork, free from Google's clutches.
I agree that Firefox is better - it is my personal web browser of choice - but that doesn't mean that Brave is bad software, or that the people behind it are evil, and anything that tamps down Google's monopoly is good in my mind.
I assume most users here understand this and would be able to fix the page, but the average user doesn't know how to do that. But then more advanced users should use uBlock Origin too, which lets you block Facebook, Twitter, Disqus, etc, too, so I don't think it's a major issue for us.
There's a long road ahead to cleaning up the Brave name, if it's at all possible in the first place.
[1]: https://madaidans-insecurities.github.io/firefox-chromium.ht...
I really like that madaidan keeps it updated.
The reality in any case is that in every pwn contest every year, all the major browsers are exploited, usually with full sandbox escapes; Chrome has better security implementation but a huge install base that makes effort to crack it worthwhile, while Firefox is easier but has trivial market share.
Maybe you are not valuing your own resources enough. Ads draw time, concentration and other mental resources. So i can only believe that it will be a net-negative in the end. It can feel rewarding, but financially, the advertiser can't pay you enough.
On another note, I've always thought the idea of constructing your own ad profile could be interesting. Like selecting the types of products and related content that you'd want to be pushed.
From my understanding this is kind of the goal of social apps but it's obviously not self-directed. I guess it is in some capacity based on your behavior but it's not like you're intentionally clicking selecting you'd be interested and actually would maybe buy.
- The built-in blocker, just like the blocker on Firefox, Edge or Opera, isn't that good. That's why you should install something like uBlock Origin on top.
- If all scripts from Facebook and Twitter are blocked, you'll end up with broken pages. Some pages have Facebook comments, which won't load if you block all Facebook domains. Embeded tweets also won't work if Twitter is blocked. Not everyone is an advanced user, so I understand why they decided not to block everything (they give you the option to block this - check your settings).
- Brave Rewards... for users: you don't have to use it. Independently of the DNS queries, you won't see any ads if you don't opt-in. If you decide to join, you'll get some BAT at the end of the month. It's not 100%, but it's more than the 0% you receive from Google Adsense.
- Brave Rewards... for website operators, youtubers, etc: I think this is where we sometimes miss the point. Users are already blocking your ads! Even if they don't use an extension for that, the built-in blocker in Brave, Opera and Firefox already block some or all of your ads. That revenue is gone.
So, and if users opt-in, you'll be able to make some money via Brave Rewards (we just have to confirm that we own the site, like a Google Webmaster Tools verification). Again, users already block your ads. Between no revenue and some revenue, what's better?
We should also keep in mind that by default, the money users receive is then shared among the sites they visited. In practice, users are sending you a small monthly payment/donation for using your site, viewing your videos, etc.
- "You may have seen in the past a fork of Brave which removed telemetry and other shady practices from Brave. It was called Braver."
Not sure what's the surprise here. We can't create a Firefoxer or Edgier without getting in trouble with Mozilla or Microsoft. Being able to fork doesn't mean that we can use the same name.
Decoupling software from the people behind it may be a good thing, but I don't want to support people that work against my interests.
You mean the same board that appointed him?
Yes, a number of board members stepped down around that time, but a couple of those were coincidental timing.
https://www.reddit.com/r/privacytoolsIO/comments/nvz9tl/brav...
Anyway, I don't really find any of this that egregious tbh.
Personally, I'm layering with nextdns to drop all the crap, and vpn over that, maybe solely depending on any one solution is the failure?
Also the "use Firefox" would be awesome if we could rely on Mozilla! I have always wanted them to succeed but recently they've been stumbling so hard and it doesn't look so promising.
So does Firefox, yet this blog post suggests it as a replacement.
>Brave isn’t more than Chromium with another skin and a built-in adblocker with reduced functionality.
As far as I know it includes additional functionality such as build-in support for tor and ipfs. (and while it might not be the best choice if you want privacy, it at least makes onion sites accessible for normal people)
>This means that you need to update the entire browser to fix a bug in the adblocker
Just like for bugs in the firefox tracking protection and the dev tools in most browsers? It is like they are trying to include as much nitpicking as possible.
>However, it seems to have a contrary effect, since it sends requests to fetch the information required
Just like firefox.
>Brave uses Google’s gstatic, which is btw using Cloudflare.
Firefox uses Google analytics in about:addons.
>Hostility towards forks
looks at iceweasel
>The only browser that does not use Google’s web engine (blink) is Firefox
I would include Safari, at least from the popular ones.
(disclaimer: I am a Firefox user)
You picked apart the author's narrative pretty nicely here. I provided 3 comments (quite long ones) as well with more detail: https://news.ycombinator.com/item?id=27552530.
I can think of unique script URLs, but if it's coming from an edge cache, presumably it's not that unique.
And maybe some sort of JS-based fingerprinting? But since Brave controls the browser, it's within their control to try to make the browser environment homogenous across users. I think Tor Browser does something like that, not sure about Brave.
Any other attacks I'm not thinking of?
edit: oh, if the script makes a request back to FB, then I suppose your IP address is available...
I wish some nonprofit would make a Chromium browser with sane defaults and take my donations. That's all I need.
I'm not sure what you're talking about; this may be the case several times in the past, but you should check again because this is a thing that constantly changes. Firefox performance today doesn't really leave a lot to be desired IMO
> Microsoft Edge got a decent native vertical tab solution before Firefox did! Edge!
Tree Style Tabs has been around since like… 2007?. Or does the "native" part somehow make it a whole lot better?
Sadly I recently left Firefox after having used it for 20 years (Phoenix/Firebird days).
The performance degradation was becoming too noticeable. I switched to Brave (of all things), but that's only because I could no longer fight the real performance that a Chromium-based browser has.
I hate doing this, because the last thing I want is a browser engine monopoly. That's why I started using Firefox in the first place, to help get rid of IE.
ducks
Firefox has had the "down-arrow" Tabs menu, which does exactly the same thing, since, uh, about forever.
1. Compatibility with Google Chrome Extensions. This is sine qua non (though I'd settle for compatibility with FF extensions).
2. Ad-blocking and reasonable-effort script blocking by default.
3. No apparent performance issues for my usage (YouTube, clicking links on HN, GitHub).
4. Integration with Tor, IPFS. Not a deal-breaker, but I do like it.
> On March 3, 2021, Brave announced that it had acquired search engine technology from the former browser manufacturer Cliqz for its own search engine, Brave Search. The former owner, the German publishing house Hubert Burda Media, has held shares in Brave since then.
Hubert Burda Media is a traditional publisher, owner of well known German publications as well as hardware stores. They also own XING, which is the German version of LinkedIn which nearby everybody uses here.
Hubert Burda was the president of the VDZ (=Verband Deutscher Zeitschriftenverleger, Association of German Magazine Publishers), so it's safe to assume that he is against internet user privacy.
I'm not sure if they are able to legally access user data through this "partnership" with Brave.
I mean chrome and firefox both update pretty much every time I open them and they are only like 50-100mb? Why would I be upset that my browser updated? OP Made it bold too they must think its a real gotcha!
Later in the article they are again grinding that axe against auto updates, that some how having an up to date browser hurts privacy?
Op must be the one last IE6 stan.
They complain about BRAVE ARE SCAMMING PEOPLE! and that they COVERED UP PEOPLE THAT EXPOSED THEM! It turns out to be an ad on the home screen for a crypto currency exchange... Scam exposed LOL
The article rehashes some FUDy and misleading comments which have been knocked down years ago.
Brave's not perfect, but for different reasons than this author raises.
I am absolutely inclined to believe that Brave is not as private as it appears.
What also comes to mind is that Brave's founder Brandon Eich is a homophobe who donated to ban gay marriage in California (Prop 8, https://slate.com/technology/2014/04/brendan-eich-why-mozill...). That alone is sufficient to doubt the integrity of his organization.
I don't have Brave installed because I am not overly concerned with privacy and the other browsers seem fast enough. I have ublock origin, noscript, and privacy badger installed on Firefox. That is good enough for me. I also think BAT is not really worthwhile.
Any better options out there? Been thinking of adding protonvpn
Some people will be uncomfortable with this default, but it's a step up from consumer ISPs who _will_ track you, to a 3rd party who Mozilla says wont.
I add Mullvad VPN (because wiregaurd is frickin awesome), which also allows you to use their DNS servers, but for this you actually have to turn off FF's DNS over HTTPS to allow the wiregaurd interface to pick up the DNS requests - they have a really good "leak" checker page while using their servers to check for various protocols https://mullvad.net/en/check/
Yes yes I know, VPN doesn't unbreak the internet, but here we are.
So I have to continue to use Firefox's DoH to prevent my university to occasionally take a peek at my traffic. Assuming they don't bother reversing IPs to domain names.
If you use Linux you don't even need an app (not Firefox's or Mullvad's), you can just pop one of the wiregaurd configs (mullvad.net can generate them for you) into /etc/wiregaurd and then use the super simple wg-quick cli interface to bring it up. You can also tell systemd to bring up a specific interface at startup with one line.
Just checked & mine was off. Not that I mind since it's supposed to hit the local pihole anyway
Edit: !m or !gmap for Google Maps, !a for Amazon
Also if you use DDG as your main URL search engine, they have bunch of "bang" shortcuts that redirect your query to online searches. For yt you'd use "!you gangnam". Others can be found here: https://duckduckgo.com/bang
1. Add YouTube as a search engine (visit YouTube, click on the + in the search box and click 'Add "YouTube"').
2. Open Firefox Settings > Search > Search Shortcuts (near the bottom)
3. Set a keyword "you" for YouTube in the table
4. Search by typing "you" + Tab in the address barWell, Safari is a thing on MacOS and is the only browser engine on iOS. StatCounter[0], the data source behind caniuse, says it has nearly 19% marketshare as well.
Everyone should take the post with a mountain full of salt (just look at their post about systemd).
The latter felt more convincing, so I don't see it as an argument for distrusting the one on Brave.
I have like 30 chrome extensions... Most of which get used at least weekly. Many of them do things like prevent sites from blocking text select or copy paste, things like that. I believe extensions are the mechanism of agency that enables a browser to be an "user agent" again.
As someone who's used Chrome exclusively for the good part of a decade and has been using Firefox again for the last several months, I don't get this criticism at all. It seems…fine? In any case it's radically better than it was when I initially switched to Chrome from Firefox.
Maybe I am looking at the privacy policy too simply, but why not prefer to use private browsing tabs? With auto fill password support, it is really not inconvenient.
I am now, with no actions on my part except running the betas for the new iOS, iPadOS, and macOS, using Apple’s new Tor-like system. I have no comment on this yet.
https://github.com/michael-rapp/ChromeLikeTabSwitcher
Latest chrome and it's derivatives(except brave) have removed this in favour of grid layout which i dislike(they also brought in tab groups which i despise entirely)
I know that brave has shady stuff like blockchain and ads, but they can be turned off. On desktop, i use firefox and i want to use firefox on android too but i find android firefox(fenix) janky.
Please suggest me good browser and also a suggestion to chrome developers:
Please don't remove things that we like. atleast provide option to enable it
Brave on mobile still blocks all that crap so I've transitioned to listening to YT content on my cellphone, propped up on my desk, while I browse the Internet on my desktop.
Many argue that "They'll pay to have ads removed", but that doesn't seem to hold true when services offers that exact option.
I would pay for ad free Youtube, if it was an option. Even with Youtube Premium, included promotions continue to be shown
That really not okay when you actually pay to have no ads.
The last thing YouTube wants to do alienate the technically literate minority who use adblocking, because these are the people who could establish an actual competitor. These folks still put money into the creator ecosystem anyway, through patreon and direct sponsorships, which funds creators to make more content. YT wins either way, honestly.
I've heard some negative things about Brave but i'm willing to give it a try now because it may just be noise. I can imagine the advertising industry being very motivated to keep people away from Brave.
Incorrect. Isn't true now, and has never been true in the past.
"Then there was that one time they started inserting their own affiliate codes into web pages."
Also false. Not true now, and was never true in the past.
"No surprise they replace the trackers on websites with their own tracking, too."
Still false. You're 0 for 3. Please consider downloading Brave and actually trying it for a day. It seems you have been quite misled on this topic.
See a more detailed response here: https://news.ycombinator.com/item?id=27552530
> Brave's adblocker is uBlock origin
It's not[1].
> Brave Today can't be disabled
Currently called "Brave News" if you're looking for it. And of course it actually can be disabled[2].
> Rewards is used to track you
A request being made to a URL does not mean you are being "tracked". Brave ads are the most privacy-preserving ad architecture[3] I know about, and they are the only people trying to make a better funding model for the web that still has a lot of the upsides of ad-driven content (mainly that it is not a regressive funding model). FF is worse in this regard because Mozilla gets most of their revenue from adtech giants that clearly don't give a flying fuck about your privacy. If you think Mozilla's funding model isn't a conflict of interest and makes the web more privacy-conscious, I have a bridge to sell you.
> Telemetry automatically violates your privacy
Not really? Of course, someone very concerned with privacy should opt out of telemetry, and Brave lets you do that.
> Auto-updates violate privacy
How so? As I point out later, the most likely result of auto-updates is that they help preserve your privacy by getting bugs patched faster.
> Affiliate codes
Yes, Brave had pre-programmed history items that were affiliate links to a crypto exchange. This harmed nobody in any way and the backlash was over-the-top. But they disabled in response to user feedback. I kinda liked this idea, as it is another way Brave was trying to fund themselves without being beholden to the Googlopoly which is an endeavor I very much support (with the caveat that it can't hurt users, which again this did not).
> Uphold doesn't care about your privacy
Uphold is a financial institution based in the US (as Brave is) which by necessity needs to comply with KYC/AML regulations. That means they need to collect your personal info. Take it up with the US government if you're unhappy.
> Tor tabs leaking DNS
Was fixed fairly quickly[4] and I think worth pointing out that no other browser even bothers trying to do something like this (integrating Tor for better privacy). Conveniently left out of the part where the author made the claim that "Brave isn't better for privacy than FF because it's just uBlock origin". Clearly brave is trying things that are not just adblocking to increase user privacy.
In general with this point, kinda funny that apparently the author of this article wants Brave to be the only software engineering org in existence that never has bugs. I guess if that's your stance though it makes sense that you wouldn't want auto-updates. For everyone else that lives in reality, auto-updates are a good thing for security (and therefore privacy, as made clear here when a privacy-related bug inevitably happens).
> Chromium and Google’s monopoly
Yeahhhhh, using FF isn't the silver bullet you think it is, as again, Mozilla gets the vast majority of their revenue from being paid by Google. What happens if that dries up? Seems unlikely that maintaining Blink without Mozilla will be easier than Brave maintaining a privacy-centric fork of Chromium (which will presumably continue to get not-privacy-related upstream improvements from Google/Microsoft/etc in perpetuity).
> brave-core-ext.s3.brave.com fetches 5 extensions and installs them. It is said that this might be a backdoor. But I don’t want to get conspiracist. I prefer giving you verifiable facts. I’ll limit myself to inform you about suspicious activities.
This is worse than all the Bitcoin maximalists / shitcoin pump-and-dumpers with their "this is not financial advice" shtick. We know what you're doing, it's pretty transparent. Especially when you do it twice:
> They were also accused of theft with BAT but this isn’t verifiable so I’ll only link the source for you.
In summary, I disagree with basically all of this article, significant parts of which are just factually wrong.
[1] https://github.com/brave/adblock-rust
[2] https://support.brave.com/hc/en-us/articles/360056341952-How...
Does the browser not at all work then?
A competitor maybe? Someone with an agenda against Eich because of the donation debacle?
Privacy-wise, either Firefox or Brave are better than Chrome.
Ads are annoying but they do fund the net.
>Ads are annoying but they do fund the net. This is a complete lie. If your website can not survive without ads then it shouldn't exist. Running a website takes almost no capital. Only people who are afraid about ad insdustry being destroyed (expect of course the people running the industry) are shitty blogs and useless news sites, because the truth is their content is so sub par that no one in their right minds would pay anything for it, but at least they can scam people into being sold onwards to advertisers.
Everyone should be running uBlock Origin. Everyone should be running ad blocking DNS. Websites that don't allow adblocks aren't worth visiting in the first place.
While I did not appreciate the tone of the article, there are some valid points there. Brave may be better than Chrome but there are still better options. It might be better to get a common cold virus than it is to get covid-19, but I'd still rather not get any virus. Sites that don't work right when you block all of the tracking lose me, I won't capitulate.
Elaborate, please. Brave's ad model is built for privacy and security. User's must first opt-in. Your data remains on your device. Ad catalogs are downloaded and reviewed locally. You are rewarded when you see an ad notification. I repeat, rewards are granted when your attention has been spent; no clicks necessary. I discussed the model further in this recent 5-minute video: https://youtu.be/LsrrT502luI
If I want to skip out on Brave Ads then I don't really need the Brave browser.
What about Brave itself? Brave Ads offers a lot of IAB advertising categories for sale to advertisers. If everything is pushed to the client and happens on the client, how does Brave Ads even know which IAB categories might be missing (and not exactly for sale in its network)? How would an advertiser know if/when an ad was even served?
The model still relies on assessing the folks that install Brave to know what you have to sell, and advertisers at least feeling like they are getting value from that advertising, most want some kind of measurable result. It would seem that some information is flowing back to Brave to allow for attribution and payments. Why do I trust anyone to hold this information? How can I know what happens to this information in the future? I can probably be deanonymized from Brave data.
I'll be honest, I have no idea what that means, other than data going from the Brave browser going to the Brave Ad network. And I cannot see or verify that data. I don't want a browser that is a browser and an ad network, in which case I don't need Brave.
I'm interested in how you define 'user data'. Do you mean PII? In my opinion, if I interact with the Brave web browser and Brave creates a log of that then that is 'user data', its not browser data or advertising data. PII is one kind of user data. Data I enter into browser windows is another kind of user data. My interactions with the browser, as generated by me the user, generate user data too.
I have been using many of the items before I came across the list, and started using some after going through it.
Many items on the list are viable and practical alternatives to proprietary products commonly used.
"Their adblocker is just a fork of uBlock Origin…"
Claims like this should be supplemented with links to our source code (see https://code.brave.com), if true. I'm not sure what gave the author this impression; Brave's built-in ad-blocking does use public lists in addition to our own efforts, but that isn't the same as being a fork of uBlock Origin. That being said, uBO is a fine extension, and you should definitely be using it (if you're not using Brave).
"They’re whitelisting trackers from Facebook and Twitter, so they can use scripts in third parties' websites to track you across the web."
This is also quite misleading. It stems from a claim made back in 2018 about our now-retired "Muon" build of Brave. We had a file which listed third-party scripts which shouldn't be blocked (so as not to "break the Web"). Among these were particular Facebook and Twitter scripts, because Facebook and Twitter content is embedded all throughout the Web (think of embedded Tweets, posts, videos, etc.). As such, it's important to permit this content to load, but to prevent it from utilizing any persistent storage (e.g. cookies). Not only were these scripts prevented to accessing storage, Brave also modified or discarded the referrer header on these request. This wasn't ever a case of "whitelisting trackers".
"They’re blatantly lying to their users. Anyone who knows a bit about how JavaScript…"
Responding to a previous explanation for the "whitelist", the author emphatically claims the engineers at Brave don't understand how JavaScript works. If I'm not mistaken, the author is responding to Brendan Eich (Brave's CEO), who happens to also be *the creator of JavaScript*.
"Another problem with their built-in adblocker is that it’s better for extensions to be separated from the core of the browser, since they don’t follow each other’s update cycles. This means that you need to update the entire browser to fix a bug in the adblocker. Stupid, isn’t it?"
Agreed, which is why Brave's ad-blocking logic is broken out into a distinct component. You can see it enumerated on brave://components, and even request updates from that page as well. It would have been very unwise to require a full browser update just to deliver updates to ad-blocking rules, etc.
> Note: By this point, it should be clear to the reader that the author is unqualified to conduct such a review. A cursory review of Brave's source (both in the archived 'Muon' repo and our active code.brave.com endpoint) would have answered many of their questions. A review of Brave's network activity, such as the one I conducted this year (see https://brave.com/popular-browsers-first-run/), would have addressed many claims to follow.
"It’s important to bring focus to the fact that Brave isn’t more than Chromium with another skin and a built-in adblocker with reduced functionality."
Wrong, again. Brave is a heavily patched version of Chromium, deviating in many ways (see https://github.com/brave/brave-browser/wiki/Deviations-from-...) from the base project. Again, this would have been quite clear to the author if they compared the network activity of Chrome and Brave (see https://brave.com/popular-browsers-first-run/).
"Rewards is their shitty program that will replace ads displayed on websites with their own."
Another easily-disproven claim, showing the author likely has never used Brave. Brave *does not replace ads on websites*. Brave's Ad system is opt-in, user-configurable, and displays ad notifications as native system notifications. These appear as prompts on your desktop or screen, outside of the browser itself.
"…they’re tracking you with Rewards…"
Again, where is the network analysis or source code to substantiate this claim? The author doesn't provide anything, because it's simply not true. Brave Rewards is designed to preclude tracking. Rather than having user data flow out to remote servers (the way Google Ads and more work today), Brave Rewards keeps the user's data on their device, and routinely downloads a regional ad catalog. This inverts the traditional digital advertising model. I covered this system in a bit more detail recently in a 5-minute talk on the history of digital advertising, and how Brave is fixing the industry. You can watch that talk at https://www.youtube.com/watch?v=LsrrT502luI.
Continued below...
The author then takes a jab at KYC, the process of confirming your identity by providing ID and other information. No user of Brave Rewards is required to do this. Users are able to opt-in, participate, earn, and pass along rewards to content creators and publishers. If a user wishes to "cash out," however, they do have to verify their identity in compliance with relevant laws and regulations. But this is not handled by Brave; we do what we can to stay away from your data. Instead, Uphold (and soon Gemini) handles this process.
"Contrary to popular belief, Rewards isn’t opt in."
The author here conflates calls to certain endpoints with program participation. They are correct that Brave would make calls at times to our own rewards server, but not because the user has been auto opted-in. Those calls would attempt to locate rewards for the current user, and they would respond with an error or an empty balance, since the user hasn't opted-in. We've been working on cleaning up these types of unnecessary calls; I think this one resulted when the user clicks on the Rewards panel. By default the panel would expand and ask the user if they would like to opt-in. If the user were already opted-in, the panel would expand and attempt to retrieve their balance. The buggy behavior here was the attempt to retrieve a balance in both states. If you ever spot an issue like this, please do let us know But again, no ad notifications are shown, and no ad catalogs are downloaded until a user opts in.
"…they fetch affiliates for Brave Rewards, with pings such as Grammarly, Softonic, Uphold, etc."
Another basic mistake from this author. They're referring to custom headers. These don't ping anybody. We document the headers on GitHub (see https://github.com/brave/brave-browser/wiki/Custom-Headers), explaining there that these serve as a substitute for a custom user-agent string (which Brave lacks). These don't identify the user to anybody, make any bad-door network calls, or anything. Again, the user is clearly not qualified to discuss these technical topics, and has done little (if any) homework on the matter.
"They also make requests to various domains… There isn’t a way to opt out from sending this requests."
A few domains are shared, but these again aren't explored any more deeply. I covered these endpoints in my network analysis (see https://brave.com/popular-browsers-first-run/); many are also covered in the document detailing proxies (see https://github.com/brave/brave-browser/wiki/Deviations-from-...) we have setup with Google services to prevent users from making contact with Google. This is yet another example of where the user could have opened a Web Proxy Debugger like Fiddler or Charles and examined the network activity to understand what's going on.
"Brave has built-in telemetry. …a lot of people believe in their marketing and think that Brave is private out of the box."
Telemetry and Privacy aren't necessarily at odds with one another; it depends on how your telemetry is implemented. We have detailed our approach in detail on our Blog (see https://brave.com/privacy-preserving-product-analytics-p3a/). We also document the questions and possible answers on GitHub at https://github.com/brave/brave-browser/wiki/P3A.
"Suspicious behavior which installs 5 extensions"
The author is, again, showing their lack of experience and effort in this area. Again, they could have found this information covered in our source code (see https://code.brave.com), in my network analysis (see https://brave.com/popular-browsers-first-run/), or even by inspecting the CRX files themselves in something like Rob Wu's CRX Viewer (see https://robwu.nl/crxviewer/).
"There is a ton of criticism about Firefox’s Pocket. But Brave has something similar, which is called Brave Today."
Brave Today is available on the new tab page, but doesn't actually make any network calls unless you open it up. This was important to us, since we aim to keep Brave as clean and quiet as possible. From a new tab page, you have to scroll down to trigger network activity. But this deferring of request isn't all we've done to make this system as private as possible. Brave also drops request headers, pads resource bytes, and more. The padding of resource bytes is really neat; no matter which image is being requested from the Brave CDN, its file-size is always the same (meaning no network-connected sleuth can infer your network activity by watching image file sizes). We talk about this system in greater detail on our blog. See Brave's Private Content Delivery Network (see https://brave.com/brave-private-cdn/).
The author then takes aim at Brave’s “SafeBrowsing”. Brave uses Google's SafeBrowsing service to protect users from harmful sites and more. Similar services are used by practically all major browsers today (many using SafeBrowsing). What matters most here, again, is implementation. SafeBrowsing has a LookUp API and an Update API. One of these sends data with each request to Google for their judgement. The other routinely downloads a database of potentially harmful URLs and performs the lookup locally, on the user's device. Brave takes the latter route. And the routine database updates are proxied through Brave server's, meaning users aren't making any direct contact with Google. This was also covered in my network analysis (see https://brave.com/popular-browsers-first-run/) earlier this year. Compare and contrast with something like Opera to see how others perform similar lookups.
Continued below...
The author here is referring to proxied URLs, which were already addressed. They claim these are "telemetry," which is absurd. Telemetry is about understanding how users and products intersect. To suggest Brave is doing any telemetry here, or assisting Google/Cloudflare with Telemetry, would require the author to provide something substantive. They don't, however, because they aren't technically qualified to conduct this type of review in the first place. Also, they note receiving a 404 when attempting to access these endpoints. This is because the user failed to note that these receive POST requests, rather than GET requests. The latter results in a 404.
"Brave will check for updates every time you run it. …Brave’s dedication to privacy is truly amazing /s."
Yes, and? Software that remains up-to-date typically remains safer and more secure. We're not about to have our 30+ million users running outside, vulnerable, and brittle versions of Chromium which have known, published exploits in the wild.
"Brave has been caught inserting affiliate codes…"
Not much of a scandal here. Brave shipped an update which would offer users affiliate-versions of particular URLs. The goal here was to detect pre-search input (no network activity involved), and offer up an affiliate link if one was available. The user could then decide to visit a URL with or without traffic attribution. We blogged about this in "On Partner Referral Codes in Brave Suggested Sites (see https://brave.com/referral-codes-in-suggested-sites/)". As stated there, the intent was to offer referral options during searches. Our mistake was also matching fully-qualified URLs. Once the issue was found, it was quickly resolved. It's important to note that traffic attribution is not necessarily malicious, anti-privacy, or a matter of security. The author has been suggesting users switch to Firefox; has the author conducted a search from Firefox? Is the author aware, as revealed in a network analysis (see https://brave.com/popular-browsers-first-run/), that keystrokes are asynchronously fed to Google, and that each request is marked with a Firefox identifier for traffic attribution?
"Who the fuck implements Tor but doesn’t change the DNS?"
Ah, that issue. Again, the user hasn't done their homework. What they're referring to here was the recent bug with Brave's Tor context which would emit a DNS lookup, potentially exposing your traffic to your ISP. Let me be quite clear, that is bad. Really bad. Which is why we fixed it without hesitation. That said, was this an example of Brave not knowing how Tor works? Or how DNS works? Not at all, as the author seems to have left out some important context.
Brave has supported Tor for a long time, and without any DNS lookup issue. So what caused this issue? It was actually Brave's effort to remain ahead of the industry in terms of security and privacy, believe it or not. In late 2020 we blogged about Fighting CNAME Trickery (see https://brave.com/privacy-updates-6/), and the growing trend of third-party trackers finding ways to plant themselves on first-party domains. To combat this, Brave added a DNS lookup to resolve first-party endpoints and evaluate the endpoint with our block lists and more. This gave Brave the unique ability to identify third-party trackers even when they masquerade as first-party requests. But, we failed to limit this feature only to standard browsing contexts. Having a feature like this makes you one of the most secure and private browsers on the market. Having it in a Tor context, however, means potentially leaking some network activity. This was not a case of Brave failing to understand how Tor or DNS works; this was a case of Brave taking the initiate to do something bold, and stumbling in the process. When you lead, everybody gets to see your mistakes.
"Possible scam and theft?"
Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no." One issue the user does bring up here (by link, not explicitly) are a set of changes made to Brave's UX/UI following feedback from content creators in 2018. We blogged about this in greater detail at https://brave.com/rewards-update/. In summary, our UI/UX was somewhat confusing. We made a few rapid changes, which resulted in a substantially much better system. This was, in my opinion, a stellar example of how crucial community feedback is to developing a solid product.
"Hostility towards forks"
More nonsense. Brave has no problem with forks; we do have a problem with those wishing to copy and paste Brave under the name "Braver". That should be quite obviously a bad-faith gesture. The individual(s) behind this proposed browser (there were at most 2 or 3 people) soon realized how much work goes into developing a browser, and the effort fell apart. But forks of Brave exist today; Dissenter (don't use this browser! (see https://twitter.com/BraveSampson/status/1350685642846572546)) and PreSearch for iOS being a couple examples.
In summary, if you want a technical review of Brave, don't get it from randos on the Internet Look instead to competent engineers, such as the work done by Douglas Leith (see https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf) and others at Trinity College in Dublin. Their abstract is as follows, "We measure the connections to backend servers made by six browsers: Google Chrome, Mozilla Firefox, Apple Safari, Brave Browser, Microsoft Edge and Yandex Browser, during normal web browsing. Our aim is to assess the privacy risks associated with this back-end data exchange. We find that the browsers split into three distinct groups from this privacy perspective. In the first (most private) group lies Brave, in the second Chrome, Firefox and Safari and in the third (least private) group lie Edge and Yandex."
Fin.
Besides, I have once witnessed a conversation between Palemoon developers and some distro's packagers about usage of palemoon logo or trademark or something like that. The developers spoke in a very entitled tone and it was quite off-putting.
Having thought this through long ago, I have never understood why people behave as though a chat client or browser that they download from the open internet would be meaningfully secure.
Security is about identifying and mitigating threat models.
For example, if you're concerned with mass surveillance an encrypted messenger will stop that.
Just because something doesn't protect against CIA 0days doesn't make it worthless.
Besides, unless you've built your own encrypted messenger, you're still putting trust in several agents that you have no reason to trust.
Having a different engine is really more of an inconvenience than a strength - it means that sometimes pages will not work in Firefox. Having an independent engine was important when it was IE6 vs the open web. It doesn't matter much when the engines involved are BSD license vs GPL.
If Chrome was all proprietary licenses then having an independent engine would matter. But the internet likes to standardise on one, open, technology.
That wouldn't be possible if web developers could simply rely on undocumented quirks of a sole browser.
It's possible that FF will die. But I think that would be extremely sad. For one, Manifest V3 would be forced upon the entire web => no more uOrigin.
Well, that is kinda the point. No, it doesn't. It might be worse than having one great de-facto standard engine. Having 2+ splits web developers in what they choose to support.
In this instance, we literally have a young company (Brave Software, Inc) that chose to go head-to-head with Google. Their CEO is deeply entwined with the history of first Netscape then Mozilla/Firefox. They went with Chromium.
That is a pretty searing indictment of the "an independent engine is important" argument. If Eich doesn't think Firefox is up for the challenge, what exactly is the gameplan here?
Nobody is saying Mozilla has to die, whatever that means. But if there is an advantage to its existence that advantage is difficult to spot. Firefox doesn't even have the thriving extension ecosystem it could once boast about - they killed most of it off. There is nothing useful there except a different set of quirks.
To die means having so few users that development is abandoned and the teams disbanded. It could happen; I wish it doesn't; you seem to wish it does... because it would make the life of web developers a little simpler?
But I don't think that's true; I think it's the opposite: web development would be a little more difficult if/when everything is controlled by just one company who decides unilaterally what can be done and what can't.
Observe that Brave, inc is using the chromium engine in a way that opposes Google.
Mozilla has developed a bunch of great features in the last few years. If they were developing on Chromium, most of the internet would have access to them. Instead, only a minor subset do. This is a bad strategy.
E.g. Brave opposes Google in some ways but they have no say in the development of Web standards implemented by Chromium.
Mozilla's Gecko has been beaten down to sub-double-digit market share, they're less relevant right now than when IE6 was >75% of the market. They have no power to influence the direction the web moves in. And yet life is going on better than ever.
If you want a counterbalance to stop Google making the important decisions, Firefox has failed spectacularly. And yet Google doesn't have any power to move the web in a direction it doesn't want to go - because their engine is open source and that is what actually matters here.
Mozilla's influence over the Web platform is much lower than it was but it is also far from zero. Lots of major sites still test in Firefox. Apple has even more influence. That is why Google doesn't yet has absolute power over the Web platform.
This is fundamentally wrong; at any point anyone can hard fork chromium and then the long term costs of maintenance and rate of code change are completely out of Google's control.
> In practice browser vendors...
This is because Google generally makes great choices with Chrome that don't need to be second guessed. One of the reasons for Chrome's ubiquity is Google makes a great browser.
Same argument applies to Gecko, but if people want to get in to the web browser game it makes a lot more sense to start with a de-facto open standard - which is Chromium. There are already a lot of browsers based on that engine, which is apparently named Blink according to Wikipedia, with backers who could easily choose to maintain an engine if they wanted to.
If the world ends in 12 months then sure, no-one is going to fork Chromium. But in the future, at some point Google will start doing a bad job maintaining it and Chromium could well be forked. If someone decides they need a browser engine to maintain full time they're probably going to fork Chromium as the technically strongest starting point and start maintaining a branch themselves. Forking Gecko would get them ... not much useful. Maybe some PR points.
The Blink license says people can fork it. There isn't any legal or technical reason that it is unforkable. At some point, it will be forked.
Plus, when Brendan started Brave, Firefox was further behind in performance and architecture than it is now.
Plus, Brendan's departure from Mozilla was somewhat messy and I don't blame him for not wanting to keep a Mozilla dependency.
> Having 2+ splits web developers in what they choose to support.
Having one engine, Chromium, would mean Google gets a completely free hand to make almost all decisions about how the Web works. Also, Web sites would have no chance of noticing they depend on Chromium bugs --- very bad for the future of the Web (and for Chromium).
Now, Webkit is also a very viable engine. The problem with relying on Apple is that they have a powerful disincentive to let the Web platform be a viable competitor to iOS.
This is why Mozilla matters.
As a result, what have we seen? Safari has added new privacy features, that should have been obvious, before Firefox. DuckDuckGo, which Mozilla staff generally recommend, isn't the default which is odd for how vocal Mozilla likes to be about how we're great for your privacy and an open web.
The point is that by receiving >90% of their funding from Google, Mozilla can continue existing. And also be a hypocrite in their actions.
Firefox has added plenty of "obvious" privacy features that no other browser has. Container tabs are amazing (and incredibly useful even apart from maintaining privacy).
Where is uBlock Origin or uMatrix for Safari? They can't exist because Apple doesn't really care about the browser extension ecosystem and doesn't implement the APIs. Apple has very different priorities than Mozilla does, and that's not a dig at either of them.
Given that, I'm not sure it's a great idea to assign ulterior motivations to the delay, especially since Firefox does eventually get those features.
https://techcrunch.com/2021/02/24/mozilla-beefs-up-anti-cros...
Without a competing engine, Google is free to cease development on Chromium and start a new private fork, and autoupdate all Chrome browsers to that new fork. Then they can add all sorts of web features that only they support. Every browser dependent on Chromium will fall behind in security updates and web features, and become more unusable than Firefox is today.
The erosion of interest in Firefox over the years raises a pretty basic question: if Google followed through with that scenario, how effective would Firefox be? They're got steamrolled in the last decade with massive amounts of funding (from Google).
Brave is literally showing that if someone wants to compete with Google, they're going to start with chromium as a base. Your argument is similar to "if someone wants to compete with Google, they need to be able to use Gecko/Webkit!". People with skin in the game are saying whatever the theoretical merits are to your argument, it is wrong. Gecko isn't part of the competitive equation any more.