Brave has been in the business of blocking ads for a long time. Surprisingly it took them years to come up with cookie banner blocking, even though all they do is include a list maintained for free by easylist maintainers. This could have been implemented already 2 years ago without much effort.
What's going on at Brave? Is everyone busy with crypto-stuff?
Brave should work on detecting cookie-banners, even if they are not blocked by some list.
The Brave Browser looks like they abandoned many important things because they are focusing on crypto - the UI is very basic, the customization is not better than Chrome, and due to the addition of many optional features, some users have reported the browser slowing down significantly. Maybe they should offer different installers for different audiences.
People have asked about new-tab page customization for a long time. People have asked to have the uBO-functionality ported to the built-in Brave Shields, including cosmetic filtering, and granular control. People have asked for Brave to not activate the new-tab background sponsored images by default, which is in conflict with their user-first ideology. The VPN ad for guardianapp on iOS is too prominent and shows that they try to push it to increase revenue.
If Brendan Eich is worried about ROI, he should start putting contextual ads on his search engine, instead of focusing on in-browser ads.
Emphasis added. They're asking in the context of cookie banner blocking. You didn't answer the question rat asked.
> Brave has been in the business of blocking ads for a long time. Surprisingly it took them years to come up with cookie banner blocking, even though all they do is include a list maintained for free by easylist maintainers.
Brave has been sponsoring Fanboy's work as an Easylist maintainer since early 2019 via an employment contract. This "list maintained for free" you're talking about was originally "Fanboy's Cookie List" and was promoted into Easylist as of November 2019 [1].
> This could have been implemented already 2 years ago without much effort.
Indeed, it was available through the brave://adblock settings menu 2 years ago. Building a new filter list is really difficult though - not only do you have to cover enough websites for it to be useful, but you have to make sure that important functionality doesn't break when it's applied. Multiply that by approximately every website on the internet and you'll have some idea of how difficult it is.
The list is finally comprehensive enough to be rolled out to a much wider audience - which is exactly what we're doing.
> People have asked to have the uBO-functionality ported to the built-in Brave Shields, including cosmetic filtering, and granular control.
Not sure what you are referring to here, but we do have cosmetic filtering and the ability to add custom filters or subscribe to anyone else's list with auto-updates. Procedural filtering is the main missing feature, but I'm actively working on that.
[1]: https://github.com/easylist/easylist/commit/f479000932294df0...
This feels unnecessarily conservative for a browser trying to achieve literally any market share; nobody's got only Brave installed and those who have it at all are those most likely to understand if a site is broken because of its blocking measures.
If Brave isn't going to be the one to push privacy features over compatibility, who is? I mean, you didn't name it "Caution".
Honestly, building any browser software that relies on filter lists takes some appetite for risk. By definition, the lists are reactive and so there's always going to be a gap in compatibility in sites which have updated recently enough.
Was Firefox's plan publicly documented before Brave's feature was publicly announced? I heard about them in the opposite order; Brave first. It seems to me that Firefox is reacting, not innovating.
FWIW since these conversations are often tribal, I use Firefox.
It seems Firefox’s cookie consent blocker automates clicking Reject after letting consent-management-provider(CMP)-scripts load.
https://searchfox.org/mozilla-central/source/toolkit/compone... (shared above already)
It looks like the code also injects opt-out cookies too, may sometimes do both click and cookie injection. Session cookie, so has to inject recurrently.
The Brave approach blocks the CMP scripts that pose these bono-consent dialogs in the first place. One reason we favor this approach beyond simplicity: many consent frameworks, besides being found illegal already in EU courts (going to top court soon), do dark deeds: extort from publishers, lie to and track users no matter what the user clicks. See
https://twitter.com/nataliabielova/status/157038509625910886...
Not sure what you mean with that. Checking code[1] it apparently uses a rules list (can be found in [1]) to function on site-by-site basis. This is the same approach utilized by popular "I don't care about cookies" add-on.
[0]: https://searchfox.org/mozilla-central/source/toolkit/compone... [1]: https://github.com/mozilla/cookie-banner-rules-list
I think they believe that "human interaction" (like a click) somehow gets them around browser protections. I think they are wrong, at least as far as my browser (Firefox) is concerned.
Legislation seems somewhat effective, but many websites purposefully won't adjust to comply, just to see if the law will actually be enforced.
Cookies and JavaScript were a mistake.
They know that most of their website readers haven't paid; I'm sure there are managers who want to extract money from those web visitors. But monetizing web-visitors promises diminishing returns - the harder you try to force visitors to cough up, the more they'll stay away from your site.
If I see an interesting-looking link from washpo, for example, I'll usually walk by, and find the story elsewhere, rather than paste it into archive.ph. I'm simply not going to subscribe to every site that asks me to; I visit about 30 sites a day. I'm a pensioner, and I'd go broke.
I understand the "cookies and javascript were a mistake" posture; mostly they're useless to me. There is a handful of sites that are useful, but are completely dependent on Javascript. And anywhere that you have to login to, you need something equivalent to cookies (like, my bank).
I block ads because - well, I don't consume food that I picked up off the footway. They run scripts in iFrames, they auto-run videos, they try to set cookies, I don't know what they do. I don't know where the site sourced its ads. Perhaps they want to use my computing equipment to mine bitcoin for them, or try to actually take over my network.
Ad-blockers work fine (unless they have a pay-to-play whitelist). Cookie management is more problematic, because (a) the variety of different kinds of cookies, (b) the fact that most users don't really understand the different ways cookies are used, and (c) the lack of clarity and granularity in cookie controls. Users can't exercise informed consent unless they can understand the information.
The vast majority of "consent management platforms" fail at this even if they otherwise appear to be compliant (no dark patterns, etc).
The CMP should essentially be the one managing the tracking libraries after correct consent has been collected, yet most websites still embed tracking libraries directly or using something like Google Tag Manager (which itself is a tracker and would require explicit consent).
It's always an arms race between the assholes and everyone else.