What does "Copy clean link" mean?
support.brave.com
support.brave.com
(disclamer: I still use Firefox and recomend you do so as well).
Another Firefox user
* "Allow Firefox to make personalized extension recommendations"
* "Allow Firefox to install and run studies"
* "Block dangerous and deceptive content"
* "Pocket" add-on installed by default.
I don't recall opting in to any of these things when I installed firefox. This isn't some conspiracy or hard to understand concept. They are right there in the settings page, not in the config flags, and I don't understand why it's so difficult to believe this or just look yourself.
So there are five settings that you believe are set to the wrong default. This causes you to mistrust firefox in total and want to use a fork that you deem more trustworthy but haven't mentioned any fork or how you decided that they are more trustworthy.
That is all 100% totally and utterly reasonable and we can take it on board and use it to adjust our views or not now that we know what you're talking about.
Thanks for posting it clearly that is worth the time it takes. The inital comment is mostly noise and in my view, not worth posting.
Would I prefer Firefox had different defaults? Yes. But, I will reserve the word shady for the products actually doing shady things like telemetry in Windows that requires jumping through hoops to turn off.
It is shady because new settings appear with updates. Surely you don't expect users to trawl through all settings for each browser update to see if Mozilla didn't sneak anything in there that undoes part of their previous choices?
Anyway. why does the installation of the Pocket seem so shady to you? There are a number of other features in the program you just installed that you probably weren't aware of. I mean, I didn't read the full source of Firefox before installing it, so there are many features now on my computer that I didn't know I was getting into when I installed Firefox. Is it the fact that Pocket (which Mozilla bought) has a premium tier that causes you to classify it as "shady"?
By my measure, any telemetry sent back that wasn't explicitly opted into is shady. Once data has left my machine, it's out of my control and anything can happen to it.
We may not have time to fully audit the source, but individuals and groups I trust have, and have made forks that cut out this telemetry as well as other potentially unsavory features. One can also monitor network traffic in and out of an a browser app to understand what is being sent.
I'm using Bromite on my phone right now to type this.
Of course there are real mistakes, but this one was quite difficult to make…
Seems perfectly reasonable to me and everyone over reacted so they took it off.
Hold what data? The affiliate ID?
> 1/ We made a mistake, we're correcting
[0] https://twitter.com/BrendanEich/status/1269313200127795201
It's the same thing as when FireFox adds it's referral code when going to Google Search, I believe that's most of their revenue...
TLDR: the bug was the referral code was being added in the autocomplete. It should have only been added to the exact affiliate address, such as "binance.us".
OP said "Mistake was getting caught" which to me implies that he is using the word "mistake" to reduce accountability rather than increase it. I think it's the latter: he's using the word "mistake" to take responsibility for having made a decision his users disagree with (whether or not it's objectively bad, I think is a moot point given the backlash from users).
Same clarification he makes in this tweet:
"I think you used "mistake" where you meant "accident". I never said it was accidental. We were treating it like a search query (which all big browsers do tag with an affiliate id to get paid from by the search provider). But a valid domain name is not a search query. Fixing."
https://twitter.com/BrendanEich/status/1269421487011713030?s...
The browser injecting a referrer header seems less transparent than it being in the link, no?
I've seen too many instances like Google Chrome still tracking you in incognito where companies just come back with they were doing it "by mistake" to believe any of them were really saying the truth.
When was this?
[0] https://dockets.justia.com/docket/california/candce/5:2020cv...
[1] https://www.reuters.com/article/us-alphabet-google-privacy-l...
The lawsuit doesn't say Chrome is doing anything. It's claiming that websites, including those owned by Google, are tracking things in incognito sessions. This is because there is no flag that says "this is an incognito session" sent to the site, and the existence of any such flag would be a bug. There's a constant arms race between sites trying to detect incognito and browsers closing the holes.
https://fingerprint.com/blog/incognito-mode-detection/
Plenty of sites try to do this.
https://www.theverge.com/2019/2/18/18229124/chrome-incognito...
In any case, it doesn't look like it was a privacy issue, they just wanted the affiliate revenue from Binance.
Disclaimer: I am not a Brave user, or in any way affiliated with them.
that is not what happened.
on my google keyboard, "fuck" autocompletes to "duck" but I'm not claiming any grand conspiracy unless it was a duckduckgo keyboard.
User types a full url: binance.us -> Brave doesn't suggest shit, user goes to whatever they wrote.
User types a partial url/keyword: binance -> Brave shows a suggestion from a local list of partners that match, with the suggested url being basically binance.us/brave. Not user tracking, just IDing that the click came from a campaign.
What the mistake was:
The user wrote binance.us -> Brave suggested the partnered link when it shouldn't have. That is literally it. And it got fixed within one day.
No, it was a mistake. We fixed it. If you expect perfection, stop using Firefox too because Mozilla has made mistakes, including some similar ones. (I don't think they are reasons to stop using Firefox, I'm just applying your fake standard.)
Brendan Eich is literally the guy who normalized letting websites run code on your machine. Even if we generously assume his intentions are good, the kind of thinking that brought us JavaScript is not even capable of grokking what I want from my browser in terms of privacy, security, and respect for my attention. Even if Brave's commitments to these values is genuine and not just marketing, they simply don't know what those values mean. Even if you trust their intentions, you can't trust their execution.
They started, right off the bat, by getting in bed with advertisers. That's their revenue stream. That's not how you fund a browser that serves users, that's how you fund a browser that serves advertisers. Even if their intentions are good, they don't know how to execute them.
"Mistakes" like injecting redirects into links are exactly what I'd expect Brave to do intentionally, not something I'd assume is a mistake.
And if you don't want the JS that Eich created to run in your browser, you can turn it off... most people like to run sandboxed code instead of installing native programs.
Mozilla makes most of their money from Google Search referrals.
Chrome was entirely built to put more eyeballs on Google ads and track you.
There's a lot more privacy features built into Brave than there are in other browsers. It's user oriented, not adtech oriented.
Of Brave, Chrome, and Firefox, who has the built in ad blocker?
That's a pretty confidently wrong statement.
You're aware of Wikipedia, right? More directly relevant: Konqueror?
And as is typical of HN, you seem to be unaware that people might be motivated by things other than money. Browsers are a large enough undertaking that you need some money to make one sustainably, but when money isn't your primary motivation it turns out you can do quite a bit with less.
> There's a lot more privacy features built into Brave than there are in other browsers. It's user oriented, not adtech oriented.
Brave is literally adtech. They sell ads.
To take a step back, which browser do you use? Did it come with an ad blocker?
Do you apply these same standards to all browsers and fiercely challenge them like Brave, let's say... Firefox?
> Do you apply these same standards to all browsers and fiercely challenge them like Brave, let's say... Firefox?
Firefox doesn't claim that they're trying to address the problem of ads on the internet, so no, I don't challenge Firefox's false claims. See how that works?
"Power and privacy to the people. No need to dig into your security settings. Fierce privacy is our default."
- Firefox on a recent update. You know, a browser that defaults to Google search and having search suggestions on. I know I'd have a couple privacy settings to change.
I don't want my browser to be a "product". If we didn't have people pushing for exponentially increasing complexity because they want the web to be an app platform then we could have browsers developed by individuals or groups in their free time.
But even if you insist on full time developers, there are alternative funding methods. Donations & grants being the most appropriate for something that benefits the general public.
> And if you don't want the JS that Eich created to run in your browser, you can turn it off... most people like to run sandboxed code instead of installing native programs.
The problem isn't being able to run sandboxed programs vs. native programs, the problem is that things that are supposed to be documents can run "sandboxed" programs where the sandbox is leaky and getting more leaks addded because perfect sandboxing is not what you want for applications that are supposed to be usable and therefore need to interact with the outside world.
Pointing at other browsers and pretending that them being ad-funded and/or also doing bad things makes any thing Brave does better is ridiculous.
Unbelievable. Now we're to be angry at (or at least, suspicious of) Eich for inventing Javascript? Because... it can used for evil? Is that really a path we should be going down? Is Tim Berners-Lee next? Come on.
>They started, right off the bat, by getting in bed with advertisers. That's their revenue stream. That's not how you fund a browser that serves users, that's how you fund a browser that serves advertisers.
This is similarly disingenuous. They started trying to solve the problem of facilitating an advertising model that respects privacy and rewarding creators (users) with revenue in the form of BAT tokens.
Say what you want about the execution, or the idea in general — but it's a noble goal.
I'm no fan of Eich's politics but your overall framing here is grossly misleading.
There is literally no good case for JavaScript. It's literally malware: code that runs on your machine without your explicitly installing it and does things that serves the website, not the user. The fact that it's in a sandbox to limit the harm it can cause is nice, but it doesn't really solve the fundamental problem.
Formats such as social media profiles, recipes, etc., would have been better served as document formats separate from or included in HTML.
More complex things like Google Maps could have been done as native apps--and still are, because the web app simply can't provide the same level of experience as a native app.
> They started trying to solve the problem of facilitating an advertising model that respects privacy and rewarding creators (users) with revenue in the form of BAT tokens.
If I want to reward a creator I can pay them without a middle man: BAT complicates that rather than simplifying it.
Advertising is a social harm. An advertising model that respects privacy, still disrespects attention, bandwidth, power usage, etc.
It should be clear that content creators aren't browser's target users, but since you brought it up: advertising generally creates a race to the bottom which incentivizes low-quality, low-effort content creation which creates a filtering problem: now it's hard to find the high-quality content amid the half-assed AI-generated nonsense. Publications which are high enough quality to be paid for, such as the NYT, have obviously been harmed by ad-based business models becoming the norm.
> Say what you want about the execution, or the idea in general — but it's a noble goal.
Their goal is to make money, and they've set it up so that their goal of making money is dependent on pleasing advertisers, not users.
The noble goals you're claiming simply are not true.
It's one thing to say that Javascript is massively over-relied on (I might even agree) but this is not anywhere close to a serious, well-considered argument. It's a joke.
I'm not interested in engaging further because extremist positions like this indicate that the speaker is not interested in meaningful debate.
> It's one thing to say that Javascript is massively over-relied on (I might even agree) but this is not anywhere close to a serious, well-considered argument.
Perhaps if you quoted past the first sentence you'd find the serious, well-considered argument you're looking for.
> I'm not interested in engaging further because extremist positions like this indicate that the speaker is not interested in meaningful debate.
Quoting a sentence out of context, calling it extremist, and then exiting without responding to any of the substance of my post makes it look awfully like you aren't interested in whatever you think "meaningful debate" means.
The extremist position is that visiting a website implies consent to the website running arbitrary code on my hardware. The only reason this has become accepted is that it's profitable to powerful people.
I didn't see anything you wrote that provides extra nuance to the statement. That is - nothing you wrote softens or modifies the quote. Am I right, or did I miss something? You were pretty clear. You even used "literally".
Sure... you went on to say why you see it like that, but that's not what being "quoted out of context" means. Is there some caveat, exception or nuance you were trying to express that modifies what you meant?
As for why I didn't engage further, let me ask you this — what if I tell you JS provides several good use cases for me and people I know? Will you then agree that some people do find good uses cases for JS or will you try to tell me I'm wrong? My impression so far is the latter.
You see what I mean? There doesn't seem to be any point in engaging.
As for the rest - I have no interest in debating BAT, or the advertising world. We largely agree. My point was simply that you misrepresented their value proposition by insisting there was never even a theoretical benefit to users and creators. It's a non-starter for having a useful conversation IMHO.
Brave private ads system is off by default. Users enable it voluntarily and get 70% of the gross without any data on our servers. Ad matching is done via a pushed ad catalog and local-to-browser machines learning. Impression counting for revshare payments uses a Chaumian blind signature protocol (same crypto as Privacy Pass). If I cold-read your comment here, I get the impression you think Brave's ads are on by default, or you want to leave that impression on readers. It's false.
We also do not inject ads into pages. The opt-in private ads go in your ad slots (notifications, new tab pages), not in any publisher slots.
Your last paragraph (a few other HN regulars do this too) uses dishonest language: "links" mean hyperlinks in pages, and we never added any affiliate code to those. https://news.ycombinator.com/item?id=31088549
https://privacytests.org/ is created by a Brave employee, so that doesn't count
For example; complaining about privacy, (which was entirely unaffected) or complaining that they couldn’t have possibly done it by mistake (which is not what they said happened).
When I see repeated comments saying wrong things emphatically, it certainly sets off a bit of a radar.
Source: I work in the same office as one of these companies. They don't work for Google but for another big, well known social platform.
The argument is that Brave should be considered referring users if you get to Binance (or other sites) via the Omnibox.. but it's disingenuous when it was suggested by the query "Binance", since the user already had the intention to visit and likely sign up for Binance. It would've been more acceptable if the omnibox only injected the referral code if you clicked 'Binance' when you tried to search "crypto exchange".
Yet the bug was not an privacy issue.
Brave still is the most private mainstream browsers. Bugs that were fixed do not reflect the present reality: https://privacytests.org/
Perfect is the enemy of good and all that jazz. It's basically impossible to try to be a good actor/explain a good thing without HNers throwing whataboutisms at you.
Of course maybe Brave is actually a bad actor, but none of the things people are calling them out for are meaningful evidence of that. The thing they did wasn't a tracking mechanism, it was just a sponsorship deal.
For my part in such comments (I think I even managed to catch a snippy reply from Eich once), I believe the Web3 vision is toxic to the possibility of a truly pro-user web, and Brave as a company is up to its eyeballs in the stuff. I've seen a rot of siloing, appropriation, and pervasive monetization consume the web in the past 20 years, and Web3 is basically about "democratizing" that rot instead of stopping it. It's a bit like offering sharecropping as an alternative to serfdom: one can argue all day that it's better (credibly, even!), but it's a far cry from being pro-farmer.
So when Brave stakes out the position of being pro-user and pro-privacy, I don't think it's meant in the ways that matter to me, and that feels like a kind of dishonesty. It's not that I envision the Brave C-suite gleefully rubbing their hands together like mustachioed cartoon villains at the prospect of deceiving people like me, but neither do I feel like they're being fully candid about the aims and implications of their project. In short, one might reasonably accuse me of viewing Brave's initiatives through thorn-colored glasses, but I think I came by it honestly.
Now an incumbent, that gives hope and disappointment.
I often manually scrub campaign-level stuff when sending links to friends just to have nicer, shorter URLs
I'm reposting my comment from a few days ago: https://news.ycombinator.com/item?id=34919771#34939391
> It wasn't 'caught' with anything, as much as those spicy news articles would have you believe. It was a URL suggestion bug. It was supposed to be turned off by default, and suggest content instead of replacing it.
The bug was fixed in a day after release, the PR is on GitHub. Brave is open source, unlike Chrome and Edge. Let's stop treating FOSS like the other spyware.
This also happened when Brave was like 5 months old. The feature since then has been turned off by default and the affiliate thing was shut down a long ago.
https://brave.com/referral-codes-in-suggested-sites/
So they did intend to put affiliate links into suggestions, and the bug was that it was accidentally applied to autocomplete in the URL bar based on the first suggestion.
I think the original intention was shady enough. It's good that they changed direction on this, but the damage on their reputation is well justified in my opinion.
and I fail to see how is that a 'threat to privacy' or something so outrageous that people are still holding a grudge after years.
Firstly, the feature was off by default, so that those who wanted to support Brave could enable it.
Secondly, the affiliate thing was only supposed to suggest the link and not replace it. Hence, the 'bug'.
Thirdly, this was not a privacy risk in any way. The affiliate link were only suggested for a few crypto websites and nothing else.
Fourthly, the bug was fixed in day. Years ago. Affiliate thing was shut down instantly and since then, nothing of that sort has been tried by Brave.
> I think the original intention was shady enough
Then I guess Firefox providing Google search as default, without asking you is shady too? or Firefox installing a whole extension for Mr.Robot without asking its users was shady too? what about Pocket? Featuring articles from partners.
I still don't see the outrage.
From the same Brave response:
> We have already fixed the issue in Brave’s open source on GitHub and in the Brave Nightly, Beta, and Developer release channels, as well as in the Stable (1.9.80) release of our desktop browser that just went live, by changing the “Show Brave suggested sites in autocomplete suggestions” setting’s default to “off”.
So no, unless I read it wrong, it was not off by default.
> Then I guess Firefox providing Google search as default, without asking you is shady too? or Firefox installing a whole extension for Mr.Robot without asking its users was shady too? what about Pocket? Featuring articles from partners.
Yes, Firefox also did a lot of shady stuff. Also mistakes of Mozilla doesn't absolve Brave from their own mistakes.
Google search being the default in Firefox is blatantly obvious, they don't try to hide it. Compare it to the affiliate link suggestion screenshot:
https://brave.com/static-assets/images/optimized/referral-co...
Yeah, there is absolutely no indication that this is an affiliate link suggested by Brave. It was clearly meant to fly under the radar.
There might be no privacy concerns here, but I still think this is a bit shady.
I wrote it wrong. The feature was 'turned' off by default after that bug.
> Compare it to the affiliate link suggestion screenshot:
Suggestion is not what's wrong. The suggestion replacing the URL was what was wrong.
> It was clearly meant to fly under the radar.
Just like how the rest of the things like Brave News, Brave Talk or Brave Search do. I don't see an issue here? They don't force a lot of stuff in your face, it's evident to anyone who uses the browser. They keep most things off by default, that's what their strategy has become.
When it was not the case (when the browser was like 5 months old), it was changed. I don't see why people are still holding it against them?
> There might be no privacy concerns here, but I still think this is a bit shady.
I don't think it was shady because, as discussed, it was a bug that was acknowledged by them, and they not only removed the affiliate links but also turned the auto-suggest feature off by default. https://github.com/brave/brave-core/commit/e8fdde70a3ac2c25e...
Now, it's up to your interpretation to classify this as shady or not, but I personally don't think this was as big of a deal. People still holding on to it is the reason I cannot take these comments seriously. Edge and Chrome with all that spyware are most HN users' favorite browsers.
Must be a responsibly release, don't want too many powerusers flooding the web at once.
I guess Power Users only use Mac.
Little Snitch and Audio Hijack/Loopback and Sketchapp and iA Writer and Inklet certainly think so. There are no Windows/cross-platform analogues for any of these. No firewall that suspends connections for an interactive prompt, no way to create virtual audio devices or route audio in Windows, no equivalent to Sketch (Figma comes close I guess) and the Windows version of iA Writer is pretty pathetic. And Inklet simply doesn't have a Windows equivalent even when I have an official Apple Magic Trackpad connected to my computer.
There's just a lot of cool stuff that isn't available for other OSes.
Oh, I know. Just cause nobody's done it yet doesn't mean it's not fair to say that macOS is the only operating system that has tools like these already made, though.
Didn't ZoneAlarm do that on Windows in the 2000s?
AFAIK those connections were blocked, not suspended, until you answered the prompt. Does ZoneAlarm still advertise this / is it documented anywhere? I can't find any info on it.
Ah right, very possible.
So the ironic part is that it's not as much about aesthetic or infrastructure or even ease of development as it is about economics.
Pure user application software is less reasonable, though.
Oh, I have no qualms about Little Snitch specifically being tied to macOS. I just find it annoying that this general concept of "a firewall that asks you before blocking a connection" has apparently never been implemented outside of macOS.
I don't want the network request to fail and the application to panic just because I had to be given a prompt with an "allow" button. Suspend the connection instead please.
Windows and Linux firewalls are not yet capable of this, as far as I can tell. If there is one that can, I'd love to replace Windows Firewall with it.
Could you confirm if Portmaster is actually completely free forever and doesn't lock any crucial features behind a paywall or different "plans" or pricing tiers? Is it actually just a local firewall? Because if so I might switch to it from WFC, it does look like it might actually do the trick. It has great documentation and seems to have a userbase too.
Edit 30 minutes later: I've been reading more about Portmaster and found this article: https://safing.io/blog/2022/08/17/portmaster-vs-glasswire/
"Many of the features mentioned by GlassWire, such as remote connection monitoring, Wi-Fi network monitor, Virus total scanning, and longer connection history, will cost you $39, $69, or $99 depending on your needs.
Portmaster, on the other hand, is both free in terms of freedom and free in terms of price. Safing makes money by charging a monthly fee for additional privacy features."
They will list every paid feature of Glasswire but only say "additional privacy features" for Portmaster? I am so sketched out right now. Are they trying to hide something or not?
Also, the docs don't mention connection prompts—how did you get them?
I am sorry this has caused confusion.
In principle it is very simple: The Portmaster software itself is completely free and there is no catch. The only thing we charge for is access to our VPN-alternative, the SPN. This is our business model in two sentences.
So, all local features are free. We are thinking about testing new features with the supporter subscribers in the future, but eventually these features will also become free. However, we will never put previously free features behind a paywall. (The software is open-source, so people will just grab the forks!)
> Is Portmaster actually completely free forever?
Except for the SPN, yes. (additional privacy features == SPN)
> Is it actually just a local firewall?
Not counting SPN, yes.
> Also, the docs don't mention connection prompts—how did you get them?
Set the Default Network Action to "Prompt": https://docs.safing.io/portmaster/settings#filter/defaultAct...
The whole thing raises big alarms of "there's a catch, there's a catch, they're doing the stupid thing where they put positive reassurances everywhere but don't actually explicitly tell you that there is no catch". It feels so untrustworthy.
I'll make sure to try it out sometime~
It does have quite a few usability nitpicks, and I don't know if it's appropriate to open GitHub issues over those, but if there's some way I can get them to you other than HN (because this is getting quite off-topic) I'd be glad to send them over.
One of my only non-nitpick gripes so far is the fact that I can't allow a connection to pass once without creating a permanent rule. Well, I can if I get a desktop notification (I can just dismiss the notification), but if the notification doesn't get sent to the desktop for whatever reason I cannot control, it shows up in the Portmaster interface itself which doesn't let me allow a connection once without creating a permanent rule.
Would love to chat with you more about this~
Almost every third-party firewall for Windows has been able to do this since at least the early 2000s. ZoneAlarm had this functionality in 2001, two years before the initial release of Little Snitch.
> no way to create virtual audio devices or route audio in Windows
This has been possible via third-party software since the mid-2000s (Virtual Audio Cable, VB-Cable, etc.).
The other things have equivalents in Windows, too, like Adobe Illustrator for designs, and trackpad vendor-specific software (e.g. Synaptic, Asus) to use it for handwriting.
ZoneAlarm is a whole antivirus afaik, not just a firewall. If there's something out there that can replicate WFC[0]'s functionality while suspending connections instead of blocking them, I'm all ears, since that's my biggest gripe with how Windows Firewall works (since WFC is only a front-end to it).
> This has been possible via third-party software since the mid-2000s (Virtual Audio Cable, VB-Cable, etc.).
By installing drivers and rebooting your computer and you get a fixed number of them.
On macOS with Loopback and Audio Hijack, you can create any number of virtual audio devices and route audio between them however you want with switches and filters and etc. in real-time.
> The other things have equivalents in Windows, too, like Adobe Illustrator for designs, and trackpad vendor-specific software (e.g. Synaptic, Asus) to use it for handwriting.
Adobe Illustrator is not the same type of software (this is why Adobe created Adobe XD). It's not usable for the reasons I used Sketch.
As for handwriting, Inklet was more advanced than that, it allowed you to scale and move the working area around the screen with gestures, and actually write into other applications instead of a dedicated signature window (which is what this "vendor-specific software" were designed for).
My point isn't that you can find some solution to create a similar result, my point is that the actual pieces of software that are available are quite unique and don't really exist anywhere else.
There's just something attractive about macOS being a true Unix with a huge userbase of people who will pay for good apps.
Used to use it to stream audio into a ventrillo channel lol
no... it doesn't. sure, there are programs you can install that will add virtual sound devices on Windows, but I can't find any program that will let you manage them dynamically, let alone do half the things that Loopback does.
VAC does actually let you restart the entire driver to change the number of virtual audio devices, if no programs are using any of them.
But another big selling point of Loopback is the ability to capture audio from applications without having to change the output device, which I believe is technically possible on Windows (Discord can do it sometimes) but there isn't a program that exposes it through a virtual input device yet.
Linux does seem good for this audio stuff specifically—there may or may not be pretty Linux GUIs for arbitrary audio mixing/routing—however on Windows there are no good examples of it. or, again, none that I can find. VAC certainly isn't one.
Of course, even on Windows, I use Voicemeeter on a daily basis and I have tried to fool around with VSTHost for real-time filters (like dynamic range compression, which I had used a lot on macOS to watch movies), but there's significant latency and I cba to figure out what the problem is. Voicemeeter is still useful for muting my microphone with a macro key though.
If I wanted to try to make something like Loopback myself I'd probably need to continue my months long search to figure out how to write userspace drivers. Because I still can't figure it out.
I'm not trying to shill Loopback here, I'm just giving it as an example of a Mac-exclusive app that does something that you can't easily get on another OS right now. Maybe it's just cause nobody's put in the time yet, but macOS still seems to have more power-user-esque apps imho.
You don't actually get any of the things that made iA Writer for macOS so great, and all the technical issues (such as broken trackpad scrolling) are incredibly distracting, defeating almost the entire point of the app.
lol
That's a showstopper right there.
EDIT: Correction, they are very conservative with which strings are filtered out. See here: https://github.com/brave/brave-core/blob/master/browser/net/...
They only look for specific KNOWN user-level targeting strings to strip. This is actually a very nuanced route for them to take. Other plugins will just filter out everything following a query.
Here is the fine details for those interested: https://github.com/brave/brave-core/blob/master/browser/net/...
As a marketer, they do mention that they retain Campaign level parameters, however the click ID is more than just a user-level identifier. Many times a click ID is the only thing that survives different environments in order to provide any attribution at all.
In fact, a click ID is much more privacy aware and anonymous in every circumstance than a website giving you your own user ID. All good web platforms generate a unique ID for you, which is not anonymized for the web platform. Whereas the click ID is always anonymized for the web platform. When you combine the two, you get a very basic piece of information: this user clicked this ad. Now those websites will still know who you are as a user, and still know which campaign you came from, but not when you specifically clicked. Wow, what a privacy save!
Removing it does very little to reduce what Google knows about you. Google does not need your click ID. The only time it is used is for conversion attribution, and it is completely anonymized between the ad platform and the marketers who run the campaigns.
So this is mostly just sticking it to the little guy, as large data platforms don't need ad-level click IDs to track you. But if you want to make sure that no marketer ever gets credit for driving you to perform an action, then this is for you!
I disagree. The good websites will not do this.
> But if you want to make sure that no marketer ever gets credit for driving you to perform an action, then this is for you!
Sounds good to me, and doubly so if I want to share the link with someone else.
Although I don't think this mechanism is good enough, actually. I'll just stick with manually editing the URLs.
You'll also want to make sure you don't own a smart phone, or keep your money in a bank.
Probably best to have your house owned by an LLC shell corp. Also register your cars under that corp as well. Unfortunately, you still have to have a license, voting record, and social security number. But there are creative ways to get around some of that.
For the extra committed, probably good to burn off your finger prints, just for extra security.
There's nothing wrong with doing what you can to keep the bad actors away even if you can't keep them all away.
Removing all query parameters might encourage that practice, and ultimately even push sites towards creating completely opaque, server-side resolved unique sharing URLs.
[self-promotion] My extension StopTheMadness does this: https://apps.apple.com/app/stopthemadness-mobile/id158308293...
The other extension I can absolutely recommend is Vinegar, which replaces hostile video players like the one on YouTube (which injects JS to close itself if you attempt to use picture-in-picture) with a native HTML5 video element.
StopTheMadness also does this. ;-)
It should be noted that while the effects are similar on YouTube, StopTheMadness and Vinegar operate in significantly different ways.
When youre on a video with forced ads where you cannot skip through them, go PiP on the video and use the arrow keys to scrub left or right...
I discovered this, then talked to a buddy at netflix, and he said that coding for PiP was a pain because PiP doesnt abide by DRM rules.
What would be cool is the ability to pipe a PiP to VLC and then use VLC to save out a video....
But if you have any idea how to "pipe a PiP to VLC" let me know...
I'd like to figure out how to "pipe a PiP"
"Stops URL shorteners. Checks the links you click in Safari for well-known link shorteners — bit.ly, tinyurl.com, t.co (used by Twitter), etc. — and loads the unshortened destination URL instead of the shortened URL. This occurs without setting any cookies or other site data, so you can't be tracked by your click."
How can you determine the destination without revealing any tracking info to the link shortening service? Unless you make the request from your backend, wouldn't the user's IP address be revealed to the shortening service, allowing it (or data brokers) to join it with other data about them?
I don't have any backend. The extension code is all local on your device and doesn't phone home to me. I don't aim to provide VPN service.
A lot of times, all that's needed is to insert a # character at the right place in the URL, then load that.
https://www.icloud.com/shortcuts/528c9af856fc46c9a3d164a85e8...
Bad that Twitter isn’t publishing such or is publishing it with tracking
Also, they do have an analytics dashboard: https://business.twitter.com/en/help/campaign-measurement-an...
https://github.com/arkenfox/user.js/wiki/4.1-Extensions#-don...
When you Copy Image... in Firefox, the URL is also copied to clipboard and then pasted around, see https://www.reddit.com/r/firefox/comments/wil262/any_way_to_... )
I suppose Brave went out of there way to tweak the cloudflare options to allow cross browser compatibility. I didn't know this was possible at all. I guess all the other sites on the web just don't care.
I came to use Brave via https://coveryourtracks.eff.org/. Their results on my brave browser instance are very good.
I'll admit I'm imbuing the EFF w/ a lot of confidence here, but a high confidence result from an EFF tool carries weight for me.
Brave is my compromise browser.
In other words, like switching an amazon link from:
https://www.amazon.com/dp/<product-id>
to a shortened tracking url like: https://amzn.to/<unique-id>Maybe facebook? Probably facebook...
Edit
It was facebook, https://tidbits.com/2022/07/19/facebook-change-ensures-track...
There's a discussion here, https://news.ycombinator.com/item?id=32129100
It might be funny (perhaps even educational) to rename "Copy link" to "Copy tainted link" when filth is detected!
If I could just import my Firefox logins, brave would be my default browser
For example, Facebook posts now have opaque IDs that are unique per-user. This makes it impossible to remove the tracking information and still keep a valid link. For a news site, where they want their content to be indexed by crawlers, it might not be possible to block all non-unique links, though they could certainly make it harder. We'll see what the future holds...
[0] Example of a Facebook post with an opaque per-user unique URL: https://www.facebook.com/pfbid02xQBbtJYKpp8V5j5my5jaWUVij7XC... ( Facebook will know which account shared this URL and there's no way for me to stop them o_O )
When I go to their website, they show this asinine comparison of what different browsers support out of the box, conveniently the list only includes things that Brave supports. That strongly suggests cherrypicking to me. I also want to know what a browser doesn't do, and they're conveniently leaving that out. And ok, Firefox does all of those with just a couple extra addons anyway. Comparing to naked Firefox just isn't fair.
This website makes me feel marketed to. That makes me implicitly distrust them.
https://github.com/brave/brave-core/blob/master/browser/net/...
https://github.com/brave/brave-core/blob/master/browser/net/...
It also works on iPhone via the shared Universal Clipboard
[0] https://addons.mozilla.org/en-US/firefox/addon/clean-links-w...
Why stop there? Why not remove the skin altogether :>
Nope, not "next", TikTok did that already
https://www.technologyreview.com/2021/06/10/1026074/tiktok-m...
* ClearURLs – Get this Extension for Firefox (en-US) | https://addons.mozilla.org/en-US/firefox/addon/clearurls/
* ClearURLs - Chrome Web Store | https://chrome.google.com/webstore/detail/clearurls/lckanjgm...
I've been doing this manually for several years now.
Is it possible to create a bookmarklet that does the same thing (i.e., via JavaSript)?
javascript:prompt('URL',window.location.origin+window.location.pathname)
Edit: But be aware that some sites (like this one) need the parameters in the query string. utm_medium=evil
garbage from links on ingest. On one level I wouldn't mind them knowing I find their content on their RSS feeds so they keep providing them, but I see duplicate articles because of this nonsense and also I was cutting them out manually when I posted articles to HN.Of course when I put that URL filter in, I also added
ARCHIVE_TODAY = "https://archive.today/submit/?url="
return ARCHIVE_TODAY + quote_plus(url)
for sites on a list of known paywalled sites so I don't have to do that one by hand.Some use sentence case, some title case.