Deviations from Chromium (features we disable or remove)
github.com
github.com
Why would Brave disable this? In my opinion, this is one of the most useful additions to browsers in recent memory, and it's quite annoying to click a link expecting to go a specific section and just be put at the top of the page. I noticed this was broken in Brave, but I never would have imagined they intentionally broke the feature.
It IS an interesting question. But you should simply upvote it, if you have nothing at all to add.
I remember seeing it for the first time and thinking, “oh here we go. Google needed browsers to have a feature to make its search engine UX better…” But I also cannot deny just how useful it is.
If videos can be timestamped for links, why not webpages? Linking to automatic content-indexed excerpts shows respect for the time spent by recipient and saves markup effort for the author.
The problem with "social media curation" as a qualifier could be interpreted as "a human is involved." Pretty much all forms of discovery, internet or not, requires either search or a human involved. Some services of course have broadcast mechanisms for curating an index but that's about the only exception I can think of for discovery that breaks away from these two qualifiers. To some degree, DNS is a broadcast system for discovery.
I've always been curious whether any search engine tries to index the "disconnected web" by just war-dialing domains/IPs like this.
> To some degree, DNS is a broadcast system for discovery.
Sadly, there's no real way to build a "DNS spider." You could if you could send DNS AXFR queries for arbitrary zones; but DNS servers mostly don't respond to these without authentication.
It looks like at one point, mozilla attempted to solve this with their context graph project as well as their acquisition of pocket. However, it does look like it has all the hallmarks of a technological solution to a societal problem. Solving the adverserial aspects as well as ethical concerns would require nothing short of a rethinking of how we use the web.
https://medium.com/firefox-context-graph/context-graph-its-t...
Why isn't only the FQDN sent?
Someone else went into detail: https://news.ycombinator.com/item?id=32742504
The password web page example is here highly unlikely: if the attacker injected his external content on the password web page, he has already a very strong position - getting users to click on links is not a logical next step, the attacker has far better avenues I would assume.
At least that's my understanding.
Not that you can't do that with a anchor, param, or an endpoint that can take arbitrary numbers/strings.
I'd love to know the explanation too.
In an extreme case imagine that someone sends you a password in a messaging app which is available via the web. If an attacker can trick you to open webpages (maybe they intercept a HTTP site and open a few tabs) they can detect if the page scrolled based on side channels (data transfer) or direct information (did you load a lazy-loaded image from their server?). You can use this to learn page content. This is vaguely similar to https://en.wikipedia.org/wiki/CRIME.
As a concrete example imagine that a webpage has something like this past the first page.
<p>Your password is 56acc1bc03298ec0</p>
<img loading=lazy src=https://cdn.example/secure.png>
If I can trick you to load #:~:text=Your password is 5 and observe that you looked up the DNS for cdn.example and loaded secure.png (especially if that resource isn't cachable) I have learned the first character of the password.If I do this 64 times (on average) I have learned the whole password.
This is a little hard to do, especially with pop-up blockers being built into most browsers so it is hard for a site to open many top-level windows (origin isolation of modern browsers will likely block this in iframes) it is not too extreme of a case.
Of course there are simpler attacks. Maybe someone can link to https://www.youtube.com/feed/history#:~:text=Voice+Feminizat... and they can tell if you have watched this video based on how many thumbnails have loaded. You load too many thumbnails and you get thrown in jail for being trans.
1. I think you could potentially embed an iframe on a page and use the scroll positions combined with this feature to read information on a page. Start with "a", check scroll position, then "ab", then "abc". Similar to a blind sql attack where you gather data/hashes by continuously adding to the SELECT query using a substring function and a sleep (to detect if the substring was found). You brute force character by character. I believe this is commonly called an "Oracle attack"
2. XSS/Phishing/Spam. You add a png with a "Your account has been compromised" or a "fake form" (think Google docs) or whatever your spam message is to a part of a page. You send an email with this special url that will cause it to jump directly to that location on load.
Just some theories. I'm pretty sure the first one would qualify for some sort of bounty, but my experience is most bug bounty programs wouldn't count the second one as valid (requires user interaction).
I guess the idea is, someone can derive data about what you clicked based on some side channel (DNS queries? wifi activity? power draw?).
In terms of this vector, I could imagine it leading to history enumeration when combined with CSS, similar to the classic “check the color of the link.” Or maybe some fingerprinting scripts could send signals to server-side traffic analysis heuristics by preloading a specific script based on which region of the screen is visible within the first second of loading the page.
That’s all speculation of course, but clearly the feature increases privacy attack surface, by giving an external observer more paths for potentially reducing your possible anonymity sets.
Seems pretty wild to me that a privacy browser is alright with having their own extensions run in browser without any way to disable them or even know they exist.
"But the extensions are open-source so that means you can audit them!"
Uh yeah... but maybe I just don't want them to run and put "Tip" links on everything. It doesn't matter whether they are secure or not, the user should get to choose what they run in their browser.
Brave is great (in my opinion), but the more you look the more you realize how strongly opinionated it is about how people should use the web which is pretty antithetical to what Brave says they are trying to do.
For a real world example: https://github.com/mozilla/standards-positions/issues/194#is...
See the stack overflow issue: https://stackoverflow.com/questions/67039633/get-the-text-fr...
(See also the currently "conflicting" library for URL fragment queries: https://github.com/Cyphrme/URLFormJS)
I think it can be easily fixed, using solutions like a delimiter, but that discussion probably needs to be apart of a wider discussion concerning URL extensibility.
Sometimes I wonder if people enjoy being blindly knee jerk reactionary.
Thankfully switching to Brave solved my issue and this stupid feature is disabled.
[0] https://perishablepress.com/disable-chrome-scrolltotextfragm...
I think most in the comment chain were thinking of the case of sending a link to a friend where you want them to be scrolled to some specific text. I often want to create these links for others when linking to long pages, or technical documentation.
I haven’t tried Brave (the crypto stuff puts me off), but if you’re interested in a good alternative to Google Search (that doesn’t link text fragments) you should check out Kagi. It’s paid, but it’s worth funding a Google competitor on principle IMO.
Only Google Search does that. What a knee jerk response...
Edit: this thing
https://www.w3docs.com/snippets/html/how-to-create-an-anchor...
It's the kind of thing I'd disable because of the privacy leaks it makes possible (Ctrl-F on the new page works just as well and keeps the user in control), but I can see how some people might like the extra convenience (when it's not being used maliciously to collect sensitive information from otherwise secure websites).
There's no for-profit entity behind it, so no perverse incentives to monetize either (but that also means they don't have a budget for proper CI, signing, distribution, etc.) so there's a bit of DIY work involved on less-popular platforms.
I use Ungoogled Chromium as a backup whenever a website makes the unfortunate choice of not properly supporting my main browser, Firefox.
Brave can be used by anyone, with the experience they expect from a modern browser.
No need for some weird workarounds to install extensions, no support for widevine, etc.
I used to use SRWare Iron on the desktop, but not for many years.
I have two installations of Firefox: a primary installation that has Enhanced Tracking Protection and privacy extensions enabled, and a secondary installation that has neither but clears all history when the browser is closed. I'll switch to the secondary installation when the primary one doesn't work with a site, usually because the privacy features interfere in some way. It's easy to do this with two editions of Firefox (e.g. stable and Beta/Developer Edition, or a fork like LibreWolf or Mull).
With this setup, I rarely ever use Ungoogled Chromium, and haven't used it for some time.
* Profile Switcher for Firefox: https://addons.mozilla.org/en-US/firefox/addon/profile-switc...
I've sadly felt like I had to switch to Librewolf, a fork of Firefox that resembles Ungoogled Chromium. Sadly because Mozilla really needs all the Firefox users they can get... to stay alive. But they make it hard.
What the hell, I don't want my logon cookies to expire so quickly.
A banking website? No, a quick automatic signout is obviously safe and correct.
An entertainment site, a forum, some kind of social media? Certainly I want to stay signed in.
I cannot think of a reason why I would want to loose my sessions every other day.
When I see cookies set by javascript, their primary purpose seems to be user tracking, not auth.
So they're asking users to trust that their servers don't track them? Has there been any audit done on their infrastructure (a quick Google search didn't reveal anything)? How are they making sure that there are no employees who enable some simple tracking on their proxies for some extra cash?
True, it's probably far-fetched, and one could argue that "it's still miles better than Google", but (as some others further down have noted) Brave didn't have the best track record in the past (they tried tracking their users too...)
Any centralized crypto company (Brave is considered a crypto company IMO) is less trustworthy than centralized non-crypto company.
I stand by this.
Also, the shady way Brave makes money should already warn you.
The Cluster Tab Manager extension has been good enough for me. I have to open it explicitly as a tab, but then I can easily see and manage all of my open tabs.
Edge has the best side tabs, closely followed by Vivaldi.
Releasing this list publicly on Github is an awesome move, especially given the links to the issues that explain the reasoning and discussion behind all of it. Kudos on this transparency.
On a related note I’m happy usb seems to be the general connector winner (though it’s certainly not without fault).
What would the average consumer gain if there were say, 10 different browser engines equally popular?
Chromium is open source and you can easily disable features you disagree with. Don’t see the downside. Fork it and add functionality you’d like, like Brave.
Which, hey, we do have and the more power chromium gets the more Google can just ignore that.
Would you prefer the 2000s when you had your choice of dozens of power connectors for cell phones?
There’s a reason the EU is mandating USB-C. Corporations have no reason and historically will not standardize amongst themselves for most things unless there’s a single winner.
when you can plug your USB-C internet into either chrome or firefox without thinking about it, you have standardized.
> The "fragmentation" you're talking about here is competition though, there isn't really any downside to having a bunch of different popular browsers and the upside is that none of them get to do anything crazy knowing there's no serious alternative so you can't leave.
If this is your opinion then what difference does it make if there’s a monopoly? You can use Firefox or Safari no?
Not to mention chromium is open source. Anyone can fork it, like Brave in FTA. I don’t see any downsides, given that you can disable and features you object to.
An implementation isn't a standard, though... and the concern is that Google are using their dominance here to push more half-baked ideas (some of which they then discard, see HTTP2 Push)
There already was single standard. I think your point is that you want there to be a single implementation. You can't really have that at this point without allowing powerful commercial interests to basically have free reign over what code is executed on your computer.
The argument is against monopoly, even an effective one. Chrome has about 65% market share (88.5% in India), I'd call that an effective monopoly (especially considering all the chromium based browsers). Large enough to dictate how things should be done and people will follow because they have to. It doesn't matter that it is open source, it matters that there is too large of a userbase that decisions fall into the hands of few. It's not like Microsoft's Internet Explorer abused this in the past and we have no precedence or anything...
I guarantee you that this will only lead to a fracturing of the internet, especially considering it is a global network.
I don't think you understand what a fork truly means. Blink, the web browser engine used by Chromium is a fork of WebKit. WebKit and Blink are now completely separate browser engines made and maintained by different companies.
Meanwhile, Brave is a skin on top of Chromium. They've patched Chromium to their liking. You can read the first paragraph in the link to confirm this.
People are really underestimating what hard forking a behemoth project like Chromium really means. I don't think anyone besides Microsoft has the capability to do it and they've already given up on that prospect.
We see similar issues with browsers actually. If other browsers could get name recognition, many would turn from Chromium. But I don't think that it helps that us nerds squabble about Brave v Google v Firefox and just call the one we don't like "trash" or "absolute garbage." Honestly, they are all fine.
But I would like to point out how there is a real world slippery slope. We all used to complain about how Apple products were too expensive for the hardware the sold. How the lock-in and fanboy-ism would affect the rest of the market. And that reality has come true (at least for phones). Apple sets a price and others follow. I don't really want a world where a singular company dictates how the web should work.
(You can buy adapters if you want, but it's generally not worth it).
It’s like electric cars having different chargers and no standard.
Even construction guys often have a huge mix of various tool brand and battery types and it's sometimes a minor annoyance.
And you'll notice that AA batteries are almost universally ... gone; replaced with built-in batteries or custom-wrapped lithium batteries.
Standards are great when things are calmed down, but when there's rapid advance they can cause their own issues (we saw this in the wireless world). Even the electric charger for cars thing runs into the limits of the standard (the fastest charging is almost always non-standardized).
Having a "baseline" standard for those could be nice, something like we have with USB, but even that has its annoying problems.
Ever open up a Dewalt battery pack? It's a circuit board and a whole bunch of 18650's. All of them are 3.7 V. What's different is the amount of power they supply and the energy they hold, how fast they can recharged, etc.
But we have that with the AA/A/C/D standard as well. Some batteries can hold more energy, some can deliver more current for a longer time, etc. NiCad, Alkaline, NiMh... etc.
Battery is the proprietary part. The engine (battery + motor) makes it spin, but for the purpose of making a hole or driving a screw one can use a wide array of standardized bits from various manufacturers. You may need an SDS adapter (one way or the other) and that's it. Same bits will even work with a hand cranked drill press built 100 years ago.
https://toolguyd.com/tool-brands-corporate-affiliations/
They still screw you on batteries and indeed would do so harder if there were fewer companies. Instead of incompatible batteries per brand it would be per year.
Sorry sir that's a 2022 tool it can't use 2021 batteries.
You can either ask congress to establish a standard, start a power tool company that supports more brands with adapters, or basically suck it up because selling batteries way over cost is extremely profitable and nobody wants actual competition in that space.
The one thing you don't want is consolidation. Likewise you think you want consolidation among browser engines but you really don't because it gives the vendor future leverage to fuck you.
If you want to reduce fragmentation while avoiding having one entity with too much control, the solution is fair setting of web standards and multiple browser implementations from different entities.
Requiring everyone to "just fork Chromium" would leave far too much power in the hands of Google (as if they didn't have far too much power already).
OK, but do you think you would be well-served if this problem were solved by there being only ONE manufacturer of power drills, take what they give you at the price they charge or nothing?
It would be one way of solving the problem of lack of standardization of power drill batteries.
It is the analogy of what you are speaking in favor of by analogy.
The better solution might be multiple drill manufacturers agreeing on a battery standard to all use together, so their batteries can be interchangeable, but you still have your choice of different competing drill and battery manufacturers. What would be the analogy with browsers, do you think?
It wouldn't be "use a single browser engine codebase owned by a single company", and that does seem to be the point advocated for here.
Imagine having 20 different gas guzzling cars with 20 different proprietary fuel inlets. If you buy an Audi say, you'd have to go to the Audi refilling station.
> What would be the analogy with browsers, do you think?
There's no need for analogy -- we've experienced this in the past, e.g., MS ActiveX and other Internet Explorer bugs (or features). There's also the proprietary web, e.g. SilverLight and Flash, before HTML5 Canvas came along.
And then HTML5 was a branding effort. Browsers needed to support it to be marketable to the general public. Things just started working again without needing to install plugins or to keep plugins up to date (Flash) -- it was a better web.
The W3C could do this if the web gets too fragmented again.
I don't really see any other way until HTML and the web is replaced by something else entirely.
Chromium is a ridiculously complex project. Most of these "independant" browser teams are simply not capable to create a browser from scratch.
I'm not saying people should praise Google or anything since they obviously have interest in it, But Google is still the one who (mostly) build chromium and leave it open source (I understand they have to since it was originally a fork of Webkit, but I feel Google can do it from scratch if they wanted). Without it none of these browsers would exist.
If anything, why almost no one uses Gecko/Firefox as a template/start point instead is a more interesting question, TBH.
That is not the reason I stopped being an advocate though.
Plus, as Mozilla has learned, nobody ever made money from selling web browsers. Costs a fortune to develop, makes almost nothing in return except for influence or protecting other businesses. Plus, why the heck would you do that if Chromium is open-source? It's completely pointless.
Building from open source mostly controlled by a big-ol company is the opposite of future-proofing, especially when "connectedness" is part of that company's bread and butter. Just having access to source doesn't guarantee much in this day and age.
Even if we don’t like it, the reality is what it is. Firefox is dead (about the same market share as ‘samsung internet’ these days). It would be best if we worked to make these web standards (chromium) bend to our collective will (like brave or Microsoft) rather than chasing pipe dreams of a Firefox return.
The standardization is in the standard, not the implementation. You do not need everyone to use the same implementation in order to have standardization: that just allows the implementer to bend the standard to his will.
They shot themselves in the foot every 6 months for 10 years.
I’m not trying to place tons of judgement on Mozilla though - just saying we all need to face the reality rather than living in denialism.
While I was the first to jump ship, when Chrome got released, I really tried to like Firefox in the last ten years, but in the end Mozilla failed on so many fronts, that they lost me to Brave.
I haven't seen this behavior on a Mac since Firefox Quantum was released, FWIW. It's what got me to switch back to Firefox in the first place. (Sidebery and a few other nice extensions have helped keep me there.)
I would use Safari on a Mac if there was a decent way to sync browser history, etc. to Firefox on Windows, but--welp.
I get the privacy angle, but I'm searching Google anyway. They have all my email since 2004, my photos since 2007. My phone is Android. Switching to Firefox alone makes a minimal impact on my overall privacy footprint and causes some websites to load slower.
In ye olden days you could make the argument that it was more customizable than Chrome, but since the shift to WebExtensions that differentiator is gone. What's wild is that they didn't think of the top 10 power user features (like Tree Style Tabs) and attempt native support for them, they just kneecapped extensions without offering an alternative.
I believe that Firefox's market share is greatly under-reported and Firefox's dying at least somewhat over-exaggerated. But then all the headlines get to people and it becomes a self-fulfilling prophecy in that way too that all the people that feel some pressure to abandon a "dying" ship only because everyone keeps telling them to.
Firefox doesn't block Google Analytics or other standard analytics providers by default: https://www.jefftk.com/p/firefox-does-not-block-analytics-by...
Enhanced Tracking Protection is one-click to turn on, and suggested as an option on first startup on a fresh install (modulo A/B tests and whatnot) and is a setting that syncs across your devices if you do turn it on just once. Anecdotally, most people I know still using Firefox as daily driver also have Enhanced Tracking Protection on. Enhanced Tracking Protection does block Google Analytics and other standard analytics providers. (So much so that some ad companies have started to treat Firefox as an "ad blocker" by default and have increasingly harsh warnings that sites are not supported in Firefox due to "ad blocker". ETP blocks zero ads, just trackers.)
And yet a ton of people here think there should be lots of people building lots of completely separate browser engines… that is certainly more difficult
To the point though - I think the threat of hard forking does something in and of itself to the chromium maintainers
That was mostly true until they came out with XHTML2, then the browser vendors were, like, “LOL, no, that’s not happening, here's what we’re going to do”, and thus was born WHATWG and the HTML Living Standard.
Yes, we need standardisation - that means we need multiple browser engines. You can't have a standardised web with a single browser engine. That's the whole point of standards.
Generally speaking, the W3C will only move a standard into the recommendation track if two competing implementations have been demonstrated.
If Chromium was the only browser engine around we wouldn't have web standards: we'd have Chromium features.
Chromium is so large that it cannot be meaningfully forked by anyone but the most well funded enterprises... Even M$ track chromium as upstream. There are no true chromium forks, they are all derivatives that track chromium - it's too much to maintain.
The problem is not merely a chromium monoculture and chromium specific historic implementation complexities, but the difficulty involved in building and maintaining a complete, modern and compliant web browser.
The state of web browsers is more comparable to derivative distros like Debian based or red hat based etc. They don't hard fork, they track upstream with a bunch of changes continually rebased on top.
> Searching Google will find a lot of people forking Chromium and adding their own changes.
Those aren't hard forks, they are derivatives, you wont see those people continually extending it with new features from W3, fixing zero days and improving implementations... they are the "debian based" in my analogy.
Isn't that Brave is doing here? There is NetSurf and others but the spec is complex because of standards committees, not because of Chromium.
The difference is that they can try and add and remove bits on each rebase, but ultimately it's beholden to the long term choices of the chromium project. Substantially diverging while tracking upstream incurs too much work on each rebase; Abandoning upstream to accommodate substantial divergence also incurs too much work due to taking on independent maintenance that increases the more the projects diverge... so as I said no one with substantial resources and a good reason would attempt to hard fork chromium.
The interesting question to me is...what happens if Brave gets bigger than Chrome. Like how Ubuntu did Debian, on the desktop at least.
Does Google nix Chromium? More restrictive licensing? Curious the outcome.
But honestly it already happened, Firefox is already irrelevant.
Mozilla is mis-managed organization that is funded to avoid anti-trust investigations, they dont fully push for privacy because they are afraid of google, do out of touch changes, and focus on political advocacy.
Compare that to brave, which builds its own independent search engine, ad network, and has privacy by default in its products.
There is no hope that Mozilla and Firefox will change the status-quo anytime soon, Firefox is losing users at crazy rate, and Mozilla is absolutely failing to do anything to change Firefox's destiny towards irrelevance.
Brave is almost everything Mozilla should've been.
Actually do what they sey, no hidden google analytics in their products, no unique ID for each installer downloaded, push for privacy by default and independence from big tech, not being shy from google, because they are their only income.
I would argue, that if Mozilla wants to turn its course around with their "limited resources" it should drop gecko, and anything irrelevant to the users experience.
Fork Chromium, the best web engine out there by a mile, and remove any anti-privacy / anticompetitive code, while still taking advantage of the huge development resources directed to chromium from many parties, and maybe Mozilla can also influence Chromium's development.
Start pushing privacy by default, its the reason brave is gaining users at such a rapid pace, its a browser I recommend to everyone, as just by installing it they already are much more private than with chrome.
What matters is the users experience, its why brave is growing.
And that's precisely why I use Firefox. In response to the comment you were responding to, I don't know why anyone should care about how relevant Firefox is. For every browser someone invents, there will be someone claiming how bad it is from a security standpoint because reasons. Whatever. I can't keep changing browsers every time someone on HN says my browser is flawed or that the company behind it sucks.
Unless things have changed, there are things about Firefox that I want that Chromium doesn't have. Can I disable history entirely in Chrome? Last time I looked, nope. Can I have multi-account containers? Nope. Can I block autoplaying videos? Nope. Can my ad-blocking not be nerfed? Nope. Can I not have the settings flags get taken away so frequently? Nope. I'm sure there's other things as well.
If Brave went the road of completely relying on its own browser engine or a fork of Chromium, I'd be all in. The longer Brave is around, the more likely I might make the switch. Another reason I don't want to leave Firefox is I've seen plenty of new and hip web browsers come and go.
> Can I disable history entirely in Chrome?
on brave, you can make it completely remove the browser history on every start.
> Can I have multi-account containers?
I agree, its a great feature of Firefox, the closet thing on chromium is multi profile windows
> Can I block autoplaying videos?
I think brave does this by default, not sure though.
> Can my ad-blocking not be nerfed?
Brave shields is based on ublock origin, and its a part of the browser, not limited by any extension API.
> Can I not have the settings flags get taken away so frequently?
Im not sure you can say this is am advantage of Firefox after the many settings they removed.
I guess that's fine, but what I want is no browser history at all except for back-forward navigation purposes. In Firefox, there's an about:config flag that completely turns off history when set to false. Not sure which one. The effect is that nothing ever shows up in History or History > All History, with the exception of the Recently Closed Tabs section, and the URL bar autocomplete doesn't reference anything that you've navigated away from.
Not that I'm doing anything bad on the internet, but what I found is not holding info about history in memory or on disk made things a little snappier and I just prefer what I do to be ephemeral unless otherwise opted in to. And yeah, I know that cookies and local storage are a thing, but that's really not the point.
> Brave shields is based on ublock origin, and its a part of the browser, not limited by any extension API.
Nice, I didn't know that.
> Im not sure you can say this is am advantage of Firefox after many settings theg removed.
Yeah, Firefox has a similar problem but my perception is it happens less often than with Chromium/Chrome.
For one, scrolling is just so much better than in any Chrome browsers, which I have noticed tend to drop frames and lag, regardless of the machine. Is it extreme? No, but for me, it is noticeable and Firefox just has that silky smooth scroll feeling.
Another big one is Manifest v3. I think Google may alienate a minority of their audience when it is implemented in January, and Firefox may see a bump in users. Having a kick-ass ad blocker like uBlock Origin work robustly will be a selling point for some people.
Another one I see people don't often mention is design. I may be in the minority of hardcore Firefox users, but I really have enjoyed the redesigns, and Firefox is still customizable enough for me to feel some joy using it.
Overall, Mozilla is definitely mismanaging and leadership needs to be turned over, but the browser is still in a good spot. If things turn around, I could see it becoming more and more popular.
The issue is that webpages are incredibly complex - they can be full-scale applications - yet they are expected to run the exact same in different browsers, down to subtle implementation details. So in order to make a new browser you would basically be reinventing Chromium.
Or you could start fresh with a new language to write websites in complete with a new browser engine. I would actually love this, web design today is a huge mess with HTML / CSS / JS quirks and backwards compatibility. But you still have the literally trillions of existing websites, which you’ll have to support with Chromium or Gecko until the end of time. And more importantly, you have the 99.9% of users who are still using Chromium or Firefox and won’t be able to use your new website, so you’ll have to backwards-generate HTML/CSS/JS from your new script anyways.
There are only three actively developed full browser engines (WebKit, Blink, Gecko) [1], and Konqueror runs on WebKit.
(It used to use KHTML, which WebKit began as a fork of)
IE6 still allows Microsoft to dictate a lot of the internet.
the more things change...
Even if Gecko was fully on-par with Blink (I keep hearing from Firefox users that they struggle with some websites, though admittedly very few, but Chrome obviously works fine with them), they'd have just invested millions in man-hours to get to the starting line, and have webpages not fail to render.
A lot of companies might switch to Firefox if they switched to Blink and webcompat was never an issue. I've argued before that Firefox would benefit from switching to Blink (and gain better security, webcompat, enterprise support, and on and on), save tons of manpower and money, and compete on privacy, features, integration, and things users actually care about, as well as keeping Manifest v2, and patching out other Chrome-badthings. But that's basically Brave.
Not always. Firefox lost much of its userbase not because it had less features or integration or was failing to render pages. In fact it was the preferred browser for most sites, with devs targeting it and testing on it.
It lost because the engine was just inferior, which made it slower than the competition.
My point (which I somewhat misstated) was that having the best engine is the bare minimum; it just brings you to the starting line. And if you don't have the best engine you'll always lose. (Sidenote: Evernote learned that lesson the hard way. Focus on core product, not marketing. Chrome's dominant, not just because of its marketing, but because it was a fundamentally superior product from the start; you can dominate a market with an inferior product based purely on marketing, as Evernote showed, but never durably).
Hence why trying to compete on engines makes little sense to me. Since so many top corporations are contibuting to Chromium (Samsung, Intel, Microsoft, more), it's difficult to call it "Google's browser engine" anymore.
The "engine competition" model makes sense if all engines are proprietary. Then, competition is the only way to push for improvements. But with every major browser engine open-source, it's better to concentrate efforts onto one engine. Imagine if every Gecko dev was contributing to Chromium instead of (somewhat) reinventing the wheel? Would Chrome not get faster/safer?
It's a bit like if there were "multiple Linuxes", developed independently, that all rigidly had to be compatible with the same APIs/userland (/implement web standards). No, there's just one Linux.
Google still wouldn't control the web (actually, they'd control it less if Mozilla's a stakeholder in Blink than with Mozilla doing their own thing and becoming increasingly irrelevant), since each browser dev can patch things into and out of Blink for their own browser (like Brave does); while still sharing all common contributions back with all other Chromium browsers. Win-win.
Would it not be better to proxy these through Tor? Brave already has support for Tor built in.
When it goes through a proxy, that becomes much more difficult.
The captured in our package.json text links to https://github.com/brave/brave-browser/blob/master/package.j...
But I think it's supposed to link to https://github.com/brave/brave-core/blob/master/package.json
1º Injecting affiliate codes into users url's without consent:
https://davidgerard.co.uk/blockchain/2020/06/06/the-brave-web-browser-is-hijacking-links-and-inserting-affiliate-codes/
2º Scamming people into thinking they are giving donations to content creatos:
https://web.archive.org/web/20190606100032/https://twitter.c...Brave is always behind in security patches to Chrome by design, Google first need to push the patch to Chromium, Brave need to grab that patch and adapt it to Brave.
Brave adds new potentially security issues with all the modificatios and code they add to it.
https://arstechnica.com/information-technology/2020/03/study...
However, you can have a good privacy record for protecting users from third parties and still make bad decisions. Not informing users about what websites do or do not take part in the crypto collection programme from the start was a bad decision IMO. Altering URLs to insert referrer codes is also a bad idea. This doesn't mean Brave doesn't try to protect your privacy, but it's still quite user hostile in my opinion.
I wasn't aware of this, thanks. It doesn't seem like such a good impartial reference now :/
> and still make bad decisions
Agree 100%. I hope the Binance fiasco scared Brave into being more honest, and resulted in more scrutiny of their codebase.
One more misstep like that and I'd consider Brave completely untrustworthy, regardless of privacy scores or research paper findings.
Don't ever link such biased website shilling for Brave.
You might also consider improving your tone.
https://www.theverge.com/2020/6/8/21283769/brave-browser-aff...
https://www.reddit.com/r/brave_browser/comments/a8d34y/youtu...
It's suspect to me that every thread that mentions Brave attracts such bizarre vitriol, with people who keep rehashing old arguments (which are off-topic and never with any actual context so people can make up their own minds). Haven't
We reduce Chromium attack surface while keeping up within ~12 hours of updates: https://github.com/brave/brave-browser/wiki/Deviations-from-...
If I want to flash an ESP32 through the web browser, my only choice (besides installing Chrome) is to boot up Windows and use Edge.
It's one of those silly features that you use maybe once or twice a year at best; same with WebUSB and WebBluetooth.
Also WLED and now Squeezelite-esp32
Yes it seems trivial vs just downloading the bin and flashing it from the terminal, but the authors are throwing extra conveniences in to the web installers.
https://en.wikipedia.org/wiki/Advanced_Video_Coding#Patent_h... https://www.mpegla.com/programs/avc-h-264/
To get h.264 into Firefox, Cisco stepped up and offered to take the heat -
https://en.wikipedia.org/wiki/OpenH264 https://blog.mozilla.org/en/mozilla/royalty-free-web-video-c... https://news.ycombinator.com/item?id=25706252 (recent HN repost)
but that doesn't mean they can safely be in Chromium.
See also: The entire reason VLC can do MPEG-2 decoding being a French student research project.
If they made them toggle-able options, or added a global privacy mode switch to get them back, it would be a great browser besides the cryptocurrency stuff.
I left a year ago when the list of removed stuff started growing.
Scandals:
1º First scandal.
Source: https://archive.ph/cAGpe
2º Scamming people into thinking they are giving donations to content creators.
Source: https://web.archive.org/web/20190606100032/https://twitter.com/tomscott/status/1076160882873380870
3º Injecting affiliate codes into url's without user consent.
Source: https://davidgerard.co.uk/blockchain/2020/06/06/the-brave-web-browser-is-hijacking-links-and-inserting-affiliate-codes/
Extra sources: https://www.theverge.com/2020/6/8/21283769/brave-browser-aff...From a security standpoint, Brave is most of the time at least 1 to 3 days behind security patches from chromium plus they add a new superfice of security issues with all the changes they do to it, with chromium at least I know they are the first to patch things due to it coming from Google.
I welcome competition but I just can't see what the Brave browser brings to the table.
I personally use either Safari or Brave (for chrome extensions and debugging) exclusively
I don't really get the love for Brave. It always strikes me as being a completely opportunistic company (brave tokens were are particular turnoff).
Some users took the BAT grant they received from Brave, and attempted to tip it to unverified creators (which landed those tokens in an omnibus settlement wallet where it could later be claimed, similar to the PayPal model of sending money).
The UI/UX of this feature and process caused a great deal of confusion towards the end of 2018, leading to monumental feedback from several content creators, including Tom Scott of YouTube. Tom's insights gave us the direction we needed to overhaul the Rewards (called 'Payments' at the time) system in major ways.
Ultimately, Tom approved of the changes. But note, there was clearly no scam involved. Additional details are provided in our 2018 blog post at https://brave.com/rewards-update/. I hope this helps!
I've heard that the cryptocurrency features are disabled by default in Brave, but I've never used it.
Yes the button is there, but you can just hide it.
Under comments, rule #1, 2, 6.
No one benefits from your comment. If you think it's a scam, put some rationale. It's a lazy comment that adds no value.
Ungoogled Chromium is probably your best bet.
I think the solution is from regulations, like GDPR in Europe. It’s not popular to say that here, but at least you can think about it.
as far as I can tell the crypto settings are the only settings that don't sync across devices which I think is a pretty annoying and deliberate dark pattern.
Vivaldi is forked from Chromium directly rather than from Brave, but the similar pro-privacy stances mean that they remove or mitigate many of the same features. E.g. both disable FLOC, both have built-in ad-blockers, and both have committed to maintaining compatibility with ad-block extensions broken by Manifest V3. For what it's worth, Vivaldi is closed-source.
[1] https://addons.mozilla.org/en-US/firefox/addon/auto-reader-v...
Therefore not even remotely a replacement for Chrome, Brave or any browser really. Vivaldi is also some of the chattiest in a network analysis I saw, which does not bode well either.
Good UX is nice, but orthogonal to privacy, sane defaults and user freedom.
Then they completely Microsofted it up. More tracking than Google, with more opting out you need to do and no way to opt out completely. Even comes with an interest free loan plugin that sometimes alters the HTML of checkout pages.
Edge is the bloated corpse of what could be the best new browser from the last 10 years. A corpse that keeps coming back to life, trying to replace your default browser every other Windows update.
Chrome is a privacy nightmare.
In fact, I don't know of a desktop browser that requires account signin. Chrome encourages it, but you don't have too to be able to use the browser.
Was there some other privacy-touting or "alternative" browser that came out in the last couple of years?
One thing I did find annoying after installing it just now is that it doesn't import bookmarks from Safari, but rather only Firefox. It would be nice if it did; in fact it would be cool if some browser would do bi-directional bookmark syncing with Safari, to piggyback on iCloud syncing across devices.
But the browser itself, the sync features etc., none of that needs an account. The sync service doesn't even have accounts, just a long string of words to serve as a the fingerprint for a sync chain.