Brave appears to install VPN Services without user consent
ghacks.net
ghacks.net
You have a service thats installed for one-click operations from Brave customers that want to use their VPN. The VPN service doesn't run in the background post-installation and no tunnels are established.
I see the customer experience reasoning here. Can someone explain the actual risks - I'm not seeing any.
Unsolicited, a company, whether I trust them or not, has said "Hey, I'm gonna install this network interface on your computer. Don't worry I won't turn it on unless you tell me to, but if I do, then all your traffic will pass through me. It's there just in case you need it. But don't worry, I won't flip the switch until you tell me to. I can, but I won't. It's not a big deal. Trust me."
I'm really not keen on this. In order to install a service, Brave's update agent must have Administrator level privileges on the system, which is how it is setup on the default system-wide install. I didn't install a VPN Provider when I installed Brave, I installed a browser. The action to, by default, add additional network interfaces to my machine, that given that the updater has the permissions to install, also has the permissions to activate, could at any point send all traffic on my machine through that Wireguard tunnel that I did not knowingly authorize the install of.
We all assume risks when we install software made by other folks, regardless of whether we can view its source or not. We have to provide some implicit trust to the makers of software to make choices that are inline with our desires and interests as a result of that. For me, this is a choice that is in violation of that trust, and that's not acceptable to me.
I'm not sure I'm going to die on this hill, but Brave has certainly reached a new level of the trust thermocline, and like others, I'm going to be evaluating whether I keep their browser on my systems going forward.
- librewolf (Desktop) [1]
- Mull (Android) [2]
- Iceraven (Android) [3]
- Mercury (Desktop) [4]
- Pulse Browser (Desktop) [5]
- Waterfox (Desktop) [6]
- Floorp (Desktop) [7] --> This submission
- Pale Moon (Desktop) [8]
- Mullvad Browser (Desktop) [9]
- Tor browser (Desktop - Android) [10]
This list is not inclusive. It probably contains the famous forks.
[2] https://gitlab.com/divested-mobile/mull-fenix
[3] https://github.com/fork-maintainers/iceraven-browser
[4] https://github.com/Alex313031/Mercury
At that point, Mullvad Browser would be a better choice.
That's not accurate. LibreWolf has an automatic updater for Windows.[1] On Linux, updates for most applications are handled by the operating system's package manager, and LibreWolf also maintains a Flatpak.[2] On macOS, LibreWolf has a Homebrew cask.[3] Flatpak and Homebrew can be configured for automatic updates.
I've been very satisifed with LibreWolf and haven't experienced any significant issues.
> Mullvad Browser would be a better choice
Mullvad Browser is a nice fork, but it doesn't include any syncing (like Firefox Sync), which makes it a non-starter as a primary browser for anyone who uses that feature.
[1] https://librewolf.net/installation/windows/
>The ideal situation would be to move these services to be installed when VPN is first USED (post purchase) and not at install time.
That seems somewhat shady, unless there was a credible explanation?
If anything, by leaving it open that would have advertised how attentive their employees are.
If you actually care about privacy rather than want to pay lip service to some marketing, then there are better options.
I dearly wish I had an option for a non-shit ISP. But my only option is Comcast.
All a VPN does is either move a bit of trust to the VPN or move your apparent IP to another ASN/location. The first of those can be helpful for dealing with some ISPs,
I split tunnel Fortnite, though.
On Macs, Safari.
On all platforms, Firefox. Firefox is a little disppointing in that it’s still bundled with stuff you probably don’t want, but it’s far far less objectionable than Chrome, Edge, Brave.
On Macs, Safari
Could you inform me how to get uBlock Origin working on Safari? Or any other adblocker that isn’t a joke?1Blocker is also well respected, but not free.
If uBlock Origin is a hard requirement, Firefox is available for the Mac.
Chromium: Vivaldi
https://help.vivaldi.com/desktop/privacy/is-vivaldi-open-sou...
FF installs plugins without your consent. Brave installs software which can circumvent security controls without your consent.
Safari has no plugins and is Mac/iOS-only. Chrome is designed to be as privacy invasive as humanly possible. I think Edge is right behind it and has the added insult of looking like a Fischer-Price toy.
Arc, Vivaldi, Orion, and Opera are irrelevant jokes. I wouldn’t trust Pale Moon, Waterfox, Ungoogled Chromuim, etc. because I still remember Iron Browser.
I can’t use Google Meet on Lynx. Even if I could use Google Meet on Surf, I wouldn’t want to because the authors are Neo-Nazi trash.
And Ladybird isn’t anywhere near done yet!
What browser am I supposed to use??
Safari has plug-ins, Apple just calls them extensions.
I know Safari has plug-ins, however the ones I use are not available for Safari and I would think most popular extensions aren’t.
I've never heard about this, can you elaborate? Are you talking about the Pocket stuff that comes built-in?
Another comment pointed out since the browser is in beta, this might be premature judgement. That’s a good point.
From my experience it's the only browser that tries to improve UX on desktop. And it seems they do care about privacy.
I disagree that it's lip service Brave has a ton of engine level privacy patches https://github.com/brave/brave-core/tree/master/patches
To my understanding you can't match it with just js extensions.
Only firefox on the highest security mode comes close I think?
Or ungoogled chromium? (brave has most of their patches IIRC)
Are there other options that have this number of patches? I'm not saying I like the company but I think it's incorrect to say they don't do anything for privacy.
EDIT: better link - https://github.com/brave/brave-browser/wiki/Fingerprinting-P...
I remember quite the slap fight in the Github issues section.
Also surprising to hear Eich playing fast and loose with licensing since Firefox benefited so much from Netscape's open sourcing itself.
Now if they start routing all of your traffic through their VPN, that would be news.
I don't think every new feature an application depends on needs user consent to install.
"Do you want to install Brave Vpn with your update?"
That's not hard.
"you gave me permission to come in your house, and I was always capable of defecating on the floor, so..."
Well sure, but we should, and I do, expect more.
There's "new stuff" [nods head] and "new stuff" [shakes head].
Very disappointed.
Not yet uninstalled, I mean, I still have Firefox (but have finally got around to moving my data away from their sync).
Really? Unsolicited bundling is not okay.
It's now possible for them to start proxying traffic through their servers, also without disclosing it to you. While this is likely just a case of them aggressively bundling their paid service bloatware, the fact that it's built into the app should be concerning.
I think that's the gist. Tbh, just installing a service that's disabled is, by itself, not that scary to me. If they were to ever turn it on without my consent, that's a real problem.
No, it is more that any one company that installs unwanted stuff on my computer is probably not some thing I trust as a privacy-focused software. Besides that VPN services have extremely broad permissions to look at or modify traffic, so it might be a attack target if not properly secured (which it might not be if it was "accidentally" installed). It also might signal that brave is looking to become a much broader company besides their current browser-crypto-ads thing, which is worrying for privacy.
There are many reasons for an accidentally or not-really-accidentally vpn service being installed behind the users back is alarming.
Soft agree, while noting that from their perspective, browsers are not a profitable offering, so they likely _need_ to expand to a broader product offering, without grant funding. Google has their obvious reasons for being in the browser market, Firefox receives grants if I remember correctly, Safari I assume only exists so Apple can attempt to keep people in their walled garden of software offerings. How do the maintainers of Brave get to make a living? Either by selling you something or selling you. I'd rather them try to sell me something, personally.
That said, I'm a current Brave user that still has one foot in the door for Firefox. If they keep this up, I might be back.
Either way I think a privacy-focused company not making enough money to survive on their (hopefully privacy-focused) products is not a good thing. Brave has been going through this for quite some time with BAT and crypto ads, mozilla has been going through it even longer with bloating expenses and google income.
Or without nefarious intent. I find it sketchy regardless of the intent behind it.
> just installing a service that's disabled is, by itself, not that scary to me.
It's not that it's scary, it's that it's intrusive. If you want to install stuff on my machine, get my consent first -- even if it's disabled by default.
I assume from their perspective, they have your consent, as you downloaded their browser install wizard and installed their product, including its widgets. But I agree, they should itemize all their widgets, and not install them by default. Though I am a bit jaded in this area, as most desktop software seems to come with widgets that install by default.
Goodness! It's a dumpster fire. Wallets, crypto, and what not - all over. I scrambled around and disabled, fixed some and all that but then things kept happening and I panicked and immediately uninstalled it clean and then installed Firefox. I will keep cursing Mozilla for actively and consistently ruining Firefox but this really is the better browser out there, even now. Unless there are others that I have not tried. Vivaldi, Opera? Are they good now?
Is Camino living in shape or form even now? I would not mind a Mozilla blessed theme/extension pack that turns Firefox into Camino of olden times. But the best would be forcing Apple to open the OS' browser gates.
Anyway that’s what I meant and I was wrong. My bad.
- Project and source: https://github.com/ungoogled-software/ungoogled-chromium
- Binaries: https://ungoogled-software.github.io/ungoogled-chromium-bina...