Of course, maybe it won’t work forever, but it works for now.
I’m not a crypto person and don’t use Brave’s crypto features, but I think it’s a more sustainable future than relying on Google’s largess.
That is just the browser part. The code on their servers that actually processes the data the browser collected is closed-source. In general, browser being open or closed source has no correlation with how privacy respecting it is. Chrom{e|ium} and Edge are another examples.
Pragmatically speaking there is only one thing that guarantees privacy and that is browser being zero-telemetry, regardless of if it is open source or not.
Of course, there’s nothing magical about open source that makes it more privacy respecting. It’s just that open source let’s me know what my browser is doing. For example, Chrome is reporting everything I do to Google. It’s possible to know that by looking at the code for Chrome. Brave doesn’t do this and it’s possible to know that by looking at the code for Brave.
That would be wrong. By Brave's own confession, there are 70 requests it sends "home" on startup [1]. Regardless of request payload, each of them contains your PII (IP address at the very least). There is plenty of opportunity for your data to be stored and used (not saying that it is).
If and how is that data actually used, we do not know, because this part is closed-source. When companies that are running advertising-based business models like Brave and Google are in question, this is the most important part users should be concerned with. Only way to settle this would be if the browser actually sent no requests anywhere, like you initially believed to be true. Indeed, a web browser has no business making requests anywhere without my explicit approval!
> It’s possible to know that by looking at the code for Chrome. Brave doesn’t do this and it’s possible to know that by looking at the code for Brave.
Do not want to be harsh but I assume you didn't actually look into the Brave's source code. You could have, but in reality very few actually do. Open-source "tag" on software can give this false sense of security because you rely on someone else to do the hard work and actually look through millions of lines of code.
The only way to actually trust a browser from a privacy standpoint is to check if it is indeed not transmitting any data. Instead of relying on source code, a much easier and foolproof way to check this is to use a network proxy, many are commonly available for all platforms. Then you can believe your own eyes vs marketing.
Disclaimer: I am in the business of creating a privacy respecting, zero-telemetry, browser. This topic is near and dear to my heart. More on this here [2] and here [3]
[1] https://brave.com/popular-browsers-first-run/
This is a weird assumption to make on HN. I have. I also didn’t say that viewing source code is the only part of understanding a browser’s security. It’s a useful portion. Network monitors are also good.
I’m not talking about startup telemetry, I mean browsing history and activity. Chrome reports this, Brave doesn’t.
I don’t think Brave is perfect, I just think it’s better than Chrome and Firefox.
"Confession" is a curious choice of words. You're correct that Brave issues requests on startup; this is necessary for a secure application. If your browser isn't updating its internal list of suspected-malicious domains and more, it isn't doing "security" properly.
> There is plenty of opportunity for your data to be stored and used (not saying that it is).
To what "data" are you referring? You cited my review of our (Brave) network activity, and that of many other browsers; which data/requests do you find to be worrisome?
A similar review was conducted in 2020 by Trinity College Dublin, which also found Brave to be the "most private" browser tested (even with these startup requests): https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf.
> …each of them [network requests] contains your PII (IP address at the very least).
An IP address is rather unavoidable. But whether or not an IP address constitutes PII is debatable—many users can (and do) share common IP addresses.
That said, we drop the IP address when and where possible. For example, usage requests are routed through a CDN which replaces the user's IP address with their inferred country.
Brave has no interest in trying to remotely monitor anybody's browsing habits; if we did, you (and/or those who actively monitor our project, looking for faults) would see clear signals in our network activity.
Instead, everything we do is designed from the outset to preclude this type of abuse. That's the case with our Privacy-Preserving Product Analytics (https://brave.com/p3a), our Private CDN (https://brave.com/brave-private-cdn/), and more. Brave isn't interested in your personal information; we have built a business model that doesn't rely on the harvesting of user data.
> The only way to actually trust a browser from a privacy standpoint is to check if it is indeed not transmitting any data.
This is a great point. Please review our network requests, and let me know which items give you concern. We're genuinely interested in your feedback.
> Disclaimer: I am in the business of creating a privacy respecting, zero-telemetry, browser. This topic is near and dear to my heart.
I'm curious how your product handles security; do you not maintain a client-side list of suspected-malicious domains (so that you can warn a user who might be stumbling into something harmful), or check for updates to patch zero-day vulnerabilities in the wild, etc.? Both of these (and more) require routine network requests if they are to offer any effective defense for the user.
"A privacy respecting browser has no business sending data on its own anywhere without the user being OK with it first."
This is true by the very definition of what privacy is.
If you want to check for updates - let the user initiate/opt-into automatic updates. If you want to update your malicious domain list (is that useful at all?) - let the user initiate/opt-into it. And so forth.
If you want to make these choices on the behalf of the user, and enable this and other things you do in those 70 requests you do on startup - that is of course fine. But you lose the right to call yourself a privacy-respecting product because Brave client just sent data to Brave servers without user knowing/consenting to it.
> which also found Brave to be the "most private" browser tested
A statement like "Brave is most private of the tested browsers" implies that privacy is somehow an analogue measure between 0 and 1, where Brave is for example 0.6 and Chrome is 0.4 or something.
But privacy is a binary measure, you (company/product) are either respecting privacy of the user or you are not. You can not respect it 'a little'. You look at your friends the same way - one has propensity to leak information and the other one doesn't. There is no category for friends who leak 'a little' information. Either they do or they don't. And frankly being called 'most private' in the company of those browsers is like saying a dog is 'most likely to fly' in the company of an elephant, dinosaur and a rhino. Be cool and be a bird to begin with.
> An IP address is rather unavoidable. But whether or not an IP address constitutes PII is debatable.
Kahm. IP address is rather avoidable - just do not send data without user's consent. It is that simple. We are doing it, so I know.
It is also not that much of a debate whether IP address is PII. It is.
Multiple court rulings such as State vs Reid [1], and Breyer vs Germany [2] as well as California CCPA act of 2018 [3] define IP address to be PII (w/ or w/o caveats) or at least a part of PII.
> That said, we drop the IP address when and where possible.
I never implied otherwise. What I did was to state the fact that Brave client sends data to Brave servers and that we can not tell for sure what is being done with this data because Brave's server code is closed-source.
Is this potentially a concern for the users? Yes. Can it be avoided? Yes - just become zero-telemetry by default. No need for discussion then.
A good relevant example is that Google advertises Chrome as a privacy respecting browser. Do you believe that based on what they say? Why not? Are there ways you could believe this? Yes, if no data ever left Chrome to Google servers without user explicitly allowing it first (by 'allowing it' I do not count accepting Terms&Conditions as those are never read by anyone and do not count as explicit/informed consent in this context).
> do you not maintain a client-side list of suspected-malicious domains
No we do not (could change in the future, in which case it will be opt-in of course). These lists in the current form are arbitrary, this hardly counts as security feature and there is very little chance the user will end up on a malicious website intentionally. Plus browsing the web is the responsibility of the user. The job of the browser is to stay out of your way, not make arbitrary decisions for you.
> check for updates to patch zero-day vulnerabilities in the wild
In Orion, user can check for updates manually or opt-in into automatic updates. So the feature is there. The key is however in "opting-in" because we want to have the right to call Orion a privacy respecting browser.
Orion does not even set a default search engine - otherwise the moment you start typing into address bar you would be leaking information (including IP address) to the search engine provider for suggestions.
To recap, Orion sends zero data to our servers or anywhere else for that matter (unless user first opts-in into it), on the first run, on any run or ever really. We call this "zero-telemetry by default" and we invite Brave to adopt this. Privacy is a serious matter, so let's treat it seriously.
[1] https://en.wikipedia.org/wiki/State_v._Reid
[2] http://curia.europa.eu/juris/document/document.jsf?text=&doc...
> "…you lose the right to call yourself a privacy-respecting product…"
I obviously disagree here. The problem is not _requests_, but rather the nature of the requests. You can certainly choose to not make any requests, but I feel doing so puts your users at considerably higher risk. I'd be curious how consistent you can be with this too; does your operating system and router also issue no requests on their own? Are users supposed to be capable of tracking security threats on those fronts too, as well as locate and install updates?
> "It is also not that much of a debate whether IP address is PII. It is."
It can be. I don't think this is a legal question, but rather an engineering one. You and I both know that this space is complicated by networks, NAT routers, and more.
> "Brave client sends data to Brave servers and that we can not tell for sure what is being done with this data"
What data? I understand that you have limited visibility into the server-side of things, but you can see clearly what data is being sent to Brave's services to begin with. What sorts of concerns do you have with what is being transmitted today?
> [Re: security lists] "Plus browsing the web is the responsibility of the user."
This is where we diverge even more. It sounds as though you're targeting super users who are very technical, and comfortable with monitoring threats, applying patches, etc. That expectation works for niche software, but not for software intended for _all users_. Brave absolutely should protect users from known threats. As we saw this past week, malicious ads on Google's search engine results were sending users to malware sites. Fortunately, we were able to get those URLs added to the SafeBrowsing service, and protect users of Brave, Chrome, Edge, and more.
> "Orion does not even set a default search engine - otherwise the moment you start typing into address bar you would be leaking information (including IP address) to the search engine provider for suggestions."
You don't have to perform live lookups. Brave doesn't send keystrokes for this very reason; users have to opt-in to that. Firefox defers sending keystrokes until 2 characters have been input. Most others just send the keystrokes (or pasted content) behind the scenes—not cool.
> "Privacy is a serious matter, so let's treat it seriously."
Expecting your users to opt-in to basic privacy features suggests privacy takes a backseat, IMHO. But then again, we may be targeting very different demographics with our software. It sounds like you're targeting power users who are okay with elevated risk. We're building Brave for everybody.
Thank you! If by power users you mean users who want to have their privacy on the web respected, then yes, we are building Orion for them.
> I obviously disagree here. The problem is not _requests_, but rather the nature of the requests.
But the problem _is_ requests, because each request at the very least carries IP, and IP is PII as ruled in multiple court rulings. I respect your decision to disagree with that, but that is the state of things.
> I don't think this is a legal question, but rather an engineering one.
There is no debate with court rulings.
It is also reasonable to assume that each court ruling involving this question involved dozens of engineers on both sides, probably more knowleadagable than you or me in this matter. And each ruling was made after careful consideration of evidence and with a lot at stake.
> It sounds like you're targeting power users who are okay with elevated risk.
I do not think you made a case that there is an elevated risk assigned with choosing to respect user's privacy in a browser. And if there is, and Brave has chosen not to respect user's privacy to include what it perceives as security features, I think you owe your users at least an explanation on your home page about that choice that you made for them.
Brave is a formidable competitor with devoted following and relevant and increasing market share. I enjoy the opportunity to discuss these important issues with you in a public forum.
Honestly, this is not what I expected from the "privacy respecting, zero-telemetry, browser" that you've been heralding here.
The Google Form alone is far more alarming than Brave's P3A (which is not connected to any Google Account, doesn't feed the data to a third-party, restricts user answers to category/range values, breaks up and temporally offsets delivery of feedback to prevent fingerprinting, etc.).
2) Perhaps you missed that we are in beta. You are opting-in your email in exchange for being invited to become a beta tester. You do not need to do that. And if you do, we are going to use your email only to send you the invite.
And the reason why there are so many questions in the form is that we want to deter as many people as we can, and get only the most determined beta testers. If somebody finds a 10 question form intimidating, their value to us as an active, contributing beta tester is likely to be small.
When we are out of beta you will be able to download the browser without submitting anything, and enjoy a zero-telemetry browser out of the box. Makes sense?
However we are OK to share it with die-hard fans who actually took the time to complete a non-trivial form, hence invite-only private beta. When we move to public beta, there will be no signup requirement.
> Bullish on macOS?
Yes we believe it is an OS and a platform with a bright future. Personally I enjoy it using a lot as a consumer, and I think it makes for a wonderful host platform for a new browser. Note that we also opted to use the WebKit rendering engine (fastest and most power efficient, at least on macOS) and built the rest of the browser from scratch.