Brave’s use of direct mailers
brave.com
brave.com
These little nudges and 'growth hacks' if you will including that mailing campaign is exactly what I don't want in software that allegedly puts the user first. It doesn't seem like there is genuine innovation in Brave, they still rely on ads, and sending people physical spam in the mail or showing you 'privacy respecting' ones online obfuscated with a bunch of attention tokens doesn't really change anything.
I don’t get what the issue is with the mailers. The names being present or not isn’t really important as they just bought distribution lists and mailed stuff to them. Whether they print the name or not, they know them. This seems pretty normal and reasonable for a “growth hack” and still preserved privacy.
Based on my understanding they didn't even buy distribution lists. They just told USPS to deliver their ad to every house in a given zip code.
The scenario is something like this:
Random person: recieves a physical mail right after installing Brave.
Brave: we are so so private and don't ever sell or use your data.
Random person: how did you get my address then right after I literally installed Brave?
Brave: you see, it's very private because we can't see the address or who the mail is going to go to. We just contracted a mailer who sent this marketing newsletter to everyone in their database.
Random person: ...
Brave: maybe you didn't understand but we, the brave company, didn't see who the mail would go to. That's privacy right?
Random person: deletes Brave
The problem here is that a privacy oriented company is accepting and making use of a very non-private method to spread privacy and Brave. Contradictory in it's core.
I still like Brave and what they represent. I am a fan. They do a lot of things right but this was baffling. I don't know how they could allow something like this to pass through the filter...
Because that is not even remotely the case as is clearly stated in the article in the first few sentences.
How many people would read the article? How many people would simply run away from Brave due to this? How many people would care to research it a bit more?
Privacy is such a sensitive topic for privacy-respecting people that most of the time even a little doubt blows up the ship. This was a huge risk taken by Brave and unnecessarily so because they didn't do anything extraordinary by sending people mail.
Moreover, can this one article stop the negative sentiment from spreading? I don't think so.
> Since 2020, Brave has been experimenting with direct mail via the United States Postal Service’s Every Door Direct Mail (EDDM) program. EDDM allows businesses in the US to create and distribute mailers to addresses across one or more ZIP Codes.
I'm not sure where you got "tracking" from, but they're just sending mail to every address in a zip code.
This whole idea was simply bad. Billboards, TV, and stadium advertisements would have gone over much better if they wanted some old-school methods. It gets in front of a lot of people with no questions about privacy or targeting involved.
One of the more amusing principle/principal mixups I've seen. (Their principals must indeed be brave if this is a potential outcome).
>Brave: we are so so private and don't ever sell or use your data.
>Random person: how did you get my address then right after I literally installed Brave?
Can't you make the argument for any sort of ad? eg.
>Random person: sees a static banner ad[1] right after installing Brave.
>Brave: we are so so private and don't ever sell or use your data.
>Random person: how did you know to show me a brave ad right after I literally installed Brave?
Are you basically arguing that brave shouldn't advertise at all?
[1] static in the sense it's placed there by the publisher for all visitors, rather than through some sort of ad network
Say you want to advertise to your potential audience, what do you do? You have very few privacy respecting methods.
1. You go with passive advertising like billboards, TV ads, blog ads etc. Not particularly effective since you can't do it across the world.
2. You go with something like Google with a huge ad network. But if you go with Google...you are tapping into and making use of personal data of your very own privacy respecting people. In a way, you are feeding the beast.
Which method should such a product go with? Which method would conform with their privacy respecting model best? Which would bring in a lot of users?
Not all ads are bad. Not all ad networks are bad. Some, very few, do it ethically. I think Brave itself is one of those. But these networks are very, very small compared to Google.
At all time the temptation is there to go with targeted ads because it's the most effective & affordable way to get potential users. The moment you do, are you still privacy respecting?
Edit: as to your question about banner ads. It depends. If you are using Google's banner ads they aren't static by any means. Google targets and rotates based on their huge database of user data. But if you just put a banner ad somewhere on a blog etc, that comes under the category of passive/non-targeted marketing.
I think it's pretty reasonable to suggest that exposing that they do so via a third party marketing distribution network which uses personally identifiable information to target ads may have been a misstep without arguing that means they can't advertise at all
Particularly when the "but we don't see the personally identifiable information that the third party we paid used to advertise to you" applies to everyone paying Facebook or Google to show ads too...
>I think it's pretty reasonable to suggest that exposing that they do so via a third party marketing distribution network which uses personally identifiable information to target ads may have been a misstep without arguing that means they can't advertise at all
But in this case there's no targeting involved? They just told the "third party marketing-distribution network" to send ads to every household within a given zip code.
In Germany "you" (probably needs to be a company of some size) go to "the post office" (actual delivery probably directly to a distribution center), give them a stack of flyers, and say "one of these into each mailbox in this ZIP code, please".
The mailman then takes a stack of said flyers and starts stuffing mailboxes as he goes along his route (excluding those mailboxes that have "no ads" stickers).
This avoids the need to treat the spam as addressed mail, because you don't really care which person gets which of the (identical) flyer. This makes handling much easier and as a result, cheaper.
I haven't done any of the extreme privacy things, but I do use a PO box for almost everything, and thus I really don't ever get anything addressed to my name sent to my actual residence.
Does it bother me? Not in the slightest. It's a community notice, and the Brave thing would only annoy me if it hit the levels that AOL CDs were at in the 90s.
Probably based on a mix of local laws and/or how profitable each city is to market to.
None of them are addressed to me personally by name.
If I'm understanding the EDDM tool correctly, the data broker appears to be the USPS.
For a privacy-focused browser, that is definitely odd.
The story seems like trying to make lemons into lemonade. "Well, we wasted money, but maybe we can get a bit of privacy protecting glow from this cock-up anyway."
I wonder if growing wealthy inequality means that consumers simply don't have enough wealth to make honest exchanges worth while. The powers-that-be look for ways to "grow" and consider making an honest product and simply selling it, but the common people don't have enough wealth to give in exchange for an honest product, so instead they put their money into advertising and other "growth" efforts.
Brave may be an example of this, what if consumers simply don't have enough wealth to finance the development of an honest consumer focused browser? In that case you would expect to see companies like Brave, even if their intentions are good, turning to less honest sources of income.
Consumer focused software seems to be on the decline, and for the first time I'm wondering if this is due to large scale economic reasons.
Take for example Diablo Immortal. Blizzard and Diablo have tons of fans. People want an old school Diablo, a game that puts the player first, a game they can buy for a flat fee and then have and enjoy for decades like they have the others in the series. But Blizzard doesn't care, consumers can't pay enough to make it worth their while, so instead they'll deliver a thin veil over gambling and exploitation and call it Diablo Immortal.
This seems like an indication Brave is actually out of touch with what consumers want: less obnoxious ads. They’re so focused on tracking they’re willing to annoy people with junk mail.
If you want to go deeper: https://optout.lexisnexis.com/ https://risk.lexisnexis.com/prescreened-offers-optout
It's like making a misleading advertisement, but instead of misleading the users to trust them, it shocked the potential user base into a false sense of insecurity.
But they always seem to be "asking forgiveness rather than permission".
Simply put, Brave takes calculated risks to expand its revenue/marketshare. I only hear about it when things go wrong. It must be worth it, because it keeps happening.
If one wouldn't trust a particular company with their data, I don't see why one would be any more likely to trust a company simply claiming they're not collecting said data.
I do appreciate the few features designed to make it technically impossible for Brave to collect some/most of that feature's user data from, though.
Something is fishy here. This doesn't seem to actually be through EDDM, but through some mailer vendor.
This sounds more like a traditional direct mailer through a vendor rather than EDDM.
Brave is in a weird market. Unless you pay for it, you're still the product.
The best thing Brave or Mozilla could do would be to legislatively kill Chrome (and perhaps the iOS Safari-only policy).
With control of browsers out of the hands of advertising agencies (Google), these companies could then raise their rates on an acceptable ads program sans the tracking. More revenue, sustainable market, and better for the world.
Did you really think that? I would have considered it to more likely be a coincidence.
Brave is reaching the people who may not have done this, to the end of getting regular folks to know their alternatives against big tech companies.
I guess don't get the ire, or what the expectation is for them to grow. Would you rather them take out Google or Facebook ads? /s
Which seems more likely? The USPS is delivering spam mail against the wishes of the recipient (I still get spam mail weekly despite opting out) or a privacy-focused company is snooping on your devices to steal your personal info (so they can send you mailers?).
I never said that. I don't want Brave on my devices due to their past bad behavior: lying, stealing money from creators in their affiliate program, redirecting legitimate links to shady crypto sites, running a crypto pyramid scheme, and so on. This is just the latest in a long list of reasons not to use their software.
"Stealing money from creators" is quite misleading. When Brave held its token sale in 2017, we allocated 300M tokens to the User Growth Pool. Shortly thereafter we began staking Brave users with tokens to identify creators for whom they would like to offer support. Brave's UI showed a check-mark for verified creators, and nothing for unverified creators (we naively followed the Twitter model).
Some users took the BAT they received from Brave, and attempted to tip it to unverified creators (which landed those tokens in an omnibus settlement wallet). The UI/UX caused a great deal of confusion towards the end of 2018, leading to monumental feedback from several content creators, including Tom Scott of YouTube. Tom's insights gave us the direction we needed to overhaul the Rewards (called 'Payments' at the time) system in major ways. Ultimately, Tom approved of the changes. But note, no money was ever stolen from any creator. Additional details are provided in our 2018 blog post at https://brave.com/rewards-update/.
It was also never the case that Brave was "redirecting legitimate links to shady crypto sites," either. You're referring to our Partner and Affiliate Links in Suggested Sites. That is, if you typed "bitcoin" into the address bar, prior to any network activity, Brave could list (among other options) an affiliate link to binance.us. The user could then decide to visit the bitcoin-related property using Brave's affiliate link, or disregard the suggestion entirely. This feature is off by default in Brave today, but you can read more about it on our blog at https://brave.com/referral-codes-in-suggested-sites/.
Brave has never been "caught" collecting user data, or abusing user data. Not a single instance of this exists. We believe in "Can't be evil" over "Don't be evil," which means we aim to preclude the potential for abuse at the design stage of ever major effort tied to Brave, and our services/offerings. On the other end, the harvesting and leaking of user data is [standard] in all other major browsers.
Which Postmaster General did you speak to again?
> Which Postmaster General did you speak to again?
I filed a complaint here:
https://www.uspsoig.gov/form/file-online-complaint
And got a call back around 2015.
I'm really confused about what was going on here, what was the nature of the alleged mistake, and why it was a mistake or bad.
The USPS allows these mailers to be mailed to every address (by route) in a zip code. The USPS also allows you to filter by such things as "age, household size, and income" (again the route is the granular level), but there's no indication Brave used this filtering.
To use the program, you have to print your own mailers. Naturally, the mailers have to be addressed, or they cannot be mailed. The vendor Brave used to print the mailers included the resident's name, which is typical but not mandatory.
Some people saw this and got freaked out, thinking that Brave was tracking them or had bought their data, the implicit thought being it was from some company dedicated to that. Instead, the USPS just used the USPS EDDM program that anyone can use. Brave apologized, destroyed the unsent mailers, and reprinted new ones without names.
Basically, it looked bad to some people, but it's not clear to me that Brave did anything bad except from a publicity perspective. Most people regularly get such mailers through the same program. (Someone else says in this thread that they don't get them, but they also mention having a PO Box, which is a filter in the EDDM tool most people are going to use.)
The EDDM program website is here, and it walks you through the process: https://www.usps.com/business/every-door-direct-mail.htm
You choose a vendor to print your mailers: https://printerdirectory.usps.com/listing/#/
Likely Brave did not communicate to their printer vendor the necessity of not printing names. But the vendor has them anyway. It's possible through the EDDM program to see your physical mail pieces (if you're doing the drop off), so hypothetically I suppose Brave could have collected this information.
Personally I think people are making a mountain out of a molehill - but I guess we such people are the demographic you signed up for. ;)
[1] https://www.newsweek.com/postal-service-photographs-every-pi...
Their spin control says they sent it to entire zip codes. Is there independent confirmation of that?
You're reading too much into this. If you look at the other elements of the ad, it's clear that the purpose of the ad is to get you to install brave, which makes you a "new brave user".
Lol the only people I've encountered in the wild who had brave on their systems were folks here in Aus who were deep down the rabbit hole of American Christian right wing nut job conspiracy theories, like full maga supporting fruit loops.
Would you like to expand on your "initial vibe" and Brave being "sketchy as shit"?