Wish for "clean" Brave Browser

There are also some newer policies that are not included in the Anxarden’s list that might be useful to you. These two will enforce HTTPS only mode and enable “Forgetful Browsing” mode:

"DefaultBraveHttpsUpgradeSetting": 2,
"DefaultBraveRemember1PStorageSetting": 2,

2 Likes

Noooiiice. I hope they develop significantly more policies now that Brave Origin, a policy-configured app, is being developed. This will mean more Brave-skinned browsers too, akin to Firefox. Whether thats good or bad, idk.

Brave really should keep their policy list updated. I do not see those two new policies anywhere. How long ago were they released, if you know?

I hope so too.

I hope I’m wrong, but my read of the situation is that–unfortunately–their adversarial stance towards forks is exactly why we haven’t and likely won’t see them supporting a full range of policies settings.

Brave has historically been fairly hostile to community forks and debloated derivatives. People had been asking for group policies for years, and it kept getting delayed, and pushed back. There is more work on group policies now (which I’m happy about), but it seems geared specifically towards 2 things: (1) Brave Origin, (2) Adblock Only Mode – which appears to be an initiative geared towards business/enterprise that makes it easy for them to keep the adblocker but force-disable most privacy settings.

With that said, I could be misreading the situation, and even if I’m not misreading it, we are still have many more policy choices than we had a year or two ago, so that’s a win regardless.

Brave really should keep their updated. I do not see those two new policies anywhere. How long ago were they released, if you know?

Pretty recently (a month or two at most). There were at least a half dozen new settings in (iirc)the 1.86 release, but most of the new ones are intended to weaken privacy settings so aren’t relevant to us.

There is a list buried somewhere in their github that is more up to date than the docs on the website I think. I’ll see if I can find it for you.

edit: This may be the page I was remembering. The one’s starting with ‘default’ are new-ish as are some of the others.

2 Likes

Tbf it’s not all marketing. Here’s an independent comparison . Here

I also won’t have to, but it’s not like paying people to code a security-focused browser is free.

We’re so trained to get things “for free” that actually cost money to make, money which is extracted from our data later, that when the transaction is revealed to us, we recoil.

1 Like

Critical and basic nonprofits services, knowledge and products should be publicly founded by govs and PAs, international institutions and rich companies and citizens. Privacy and access to the internet and its tools should be a free human right if we want to evolve to a more equitable and sustainable society.

Just to remember that only the adults in 2024:

  • The super rich 1.6% (60m) owned 48.1% of global wealth
  • The very rich 16% (628m) owned 39% of global wealth
  • The middle class 41.3% (1.57b) holds 12.1% of total wealth
  • The bottom class 40.7% (1.55b) holds only around 0.6% of total wealth.

It’s not that easy for everyone to pay. That’s why many try to contribute in other ways. That’s why there’s communities like PG, to share the right to privacy with the world.
Source

3 Likes

Maybe I’m interpreting that chart differently than you are, but as best I can tell, the only sections of the chart I can see where Brave has a meaningful edge are the sections that could be addressed simply by installing a content blocker (like uBOL or Adguard) in Safari. In all other sections they seem to be roughly the same or trading blows. (edit: and Safari has the edge with 1st party tracking protection)

It’s worth remembering that all browsers on Safari use Webkit. The Desktop Browser comparison you linked to is not relevant to iOS, you need to switch to the iOS section of that website for a more accurate comparison.

FWIW, I actively use both Safari and Brave on iOS.

Try Firefox with Betterfox, uBlock Origin, and multi-account containers with Google and Proton accounts made for casual browsing. The first makes Firefox faster (although not as fast as Chromium-based browsers), the second blocks ads, and the third maintains site functionality and privacy.

First, for the tab thing. Okay, and? It takes literally half a click to toggle them off. If you’re not following the basic privacy guide setups to optimize every browser you use, what are you even doing? Complaining that a free browser has a sponsored wallpaper you can disable in one second is peak first world problems.

As for the twitter thread you linked, you’re playing semantics and ignoring the actual code. Yes, Brave intended to include affiliate links. That’s true. But here’s what you’re leaving out, it was supposed to be as optional dropdown suggestions. But a literal bug in the code mistakenly made the affiliate link the default completion when you hit enter. You can read the post mortem from their June 2020 blog where they explain the exact flag error, and the bug. The X thread is lacking critical context.

You can read about the bug here: On Partner Referral Codes in Brave Suggested Sites | Brave

And again with the fingerprinting thing you’re arguing entirely in bad faith by framing a necessary web compatibility fix as some privacy betrayal. They removed strict fingerprinting because it fundamentally broke the internet. If you completely block WebGL, modern websites just crash. Less than 0.5% of users even had it turned on because it made the web unusable.

Instead, Brave defaults to farbling, which adds cryptographic static to your browser data. Yes, your raw GPU model is exposed so your screen can actually render graphics properly, but the rest of your fingerprint is randomized every session to kill cross site tracking. They didn’t downgrade privacy. Oh no, the website’s WebGL API can see that I am running an NVIDIA GeForce RTX 3060 or an Apple M2 chip! It is the equivalent of trying to identify a specific suspect in a sold out stadium, and your only clue is the guy is wearing blue jeans.

Privacy by default because of telemetry just proves you don’t know the difference between Google’s personalized spyware and Brave’s P3A (which is award winning by the way). It doesn’t know who you are.

I remember years and years ago, this was a pretty decent amount of time after the Dark Angel boom, but Jessica Alba was still very much one of Hollywood’s finest and highly relevant in the mainstream. I had an encounter with her where she hugged me, complimented me on a project I had done for her, and called me sweet. Now, I was a young, naive idiot, and I totally thought she was into me.

I’ve never known such delusions until now.

If you are seriously suggesting that because Founders Fund made a seed donation back in 2016, before the browser’s inception, the CEO is somehow an employee of a global surveillance company, all because of one of their partners… well. I know who you’re referring to, and you know who you’re referring to. That partner had a fleet of investments across hundreds of capitalist firms that he wasn’t even aware of. This is a pretty big stretch for guilt by association.

Because that firm made a generic seed donation, you are trying to say therefore the Brave CEO is an employee of a global surveillance company. My friend, I have seen some insane mental gymnastics in my lifetime, but that rivals what I used to go around telling people about Jessica Alba having the hots for me.

You’ve got things messed up, brave-boy. The main problem isn’t that this garbage can be turned off, it’s that you came here to defend this browser with lies and misinformation, calling other articles “misinformation, or just completely a lie”. And now you’re confirming yourself that the article was true.

I don’t see much of a difference. Based on your own link, searching for “Ledger” only gives one result, and it has a referral code.

So? Was someone talking about blocking WebGL? It wasn’t necessary, and Strict mode didn’t block it since the GPU model was randomized, but now to hide that fingerprint, WebGL needs to be blocked, which will cause sites to break.

Do you realize that every fingerprint increases the accuracy of user tracking? In some cases, it could be “cyan jeans,” you know?

Google also claims that their telemetry in Chrome is private. There shouldn’t be any telemetry in a browser, especially if it’s a “private browser.” If telemetry is private, it should be opt-in, not opt-out.

To be honest, your attempts to justify this browser are already starting to smell like the “I have nothing to hide” argument.

Also, are you trying to tell me that he wasn’t an advisor for Palantir?

That’s basically what you’re doing right now anyway.

4 Likes

I can’t read @Menkork wall of text after a day of work. You force me to use AI just to read an opinion. Ups, Brave AI aggressively agreed with Menkork defending Brave. Stupid me, I should have used another AI with less bias on this topic :man_facepalming:

No matter, I don’t trust Brave since it’s becoming another greedy american company focused mainly on building its own wealthy and monopoly in the privacy niche.
I just use it until it is useful. ASA Cromite, Helium, Mojeek, Mwmbl or any other nonprofit/benefit clean and private Chromium browser and search engine invested in the FOSS ethics and privacy cause grow sufficiently.

Just a note: Brave fingerprint itself in multiple ways. It’s more focused on market itself and add heavy fingerprintable bloat than reducing the fingerprinting and the attack surface (I’m pretty sure that hackers like to exploit browser bloats).

A simple example: you have to rely on a FOSS independent solo dev extension like this (the only one existing AFAIK) to prevent Brave from telling others you’re using it… is that privacy by default?

Also, you have to manually remove all the installed search engines in order to not being tracked by those websites… is this privacy by default?

And yeah, anything connected to dirty companies should not to be considered “clean”, “ethic” and “neutral”. Who knows if that was the only money they got from that kind of groups.

1 Like

Brave is full of all kinds of dubious privacy practices. The tracking in their default search options is an especially puzzling one. The browser might be fine on technical merits, but it’s so confusing that people continue to trust companies like this despite the preponderance of evidence that they’re not trustworthy. I’d rather install and use an OS that includes an actually good Chromium browser that’s not trying to repeatedly force invasive defaults on me. SecureBlue and GrapheneOS come with Trivalent or Vanadium which basically are debloated Brave that come from ethical devs. (We can argue all day whether or not Brave blocks fingerprinting slightly better or slightly worse than those browsers, but if your primary concern is being fingerprinted, you should be using a browser other than Brave anyway.)

5 Likes

That one “should” is doing so much here.

I completely agree with you in theory. It would be lovely if non-profits focused on creating quality products without obsessive need to enshittify and focus on shareholder value, and took up spots in the usual for-profit space just to give people good jobs. Unfortunately, that’s not how many non-profits work.

Sadly, the typical pattern is that they hire young and inexperienced people too naive to see the red flags, pay them less than they’re worth because they can leverage ideological affinity to the work done, and then work them until they burn out. The ones that don’t burn out get rewarded by filling the voids left by senior staff that burn out on a slower fuse and aren’t invested in the comfortable nest they’ve made for themselves. I’ve worked at, and with, many, and the non-profit space is not without its flaws, across geography and across areas of work.

You and many other people without experience don’t see that you’re casually suggesting a totally new economic paradigm with that “should.”

Has anyone here tried using the Brave Beta browser? I’ve been testing it out and it’s fast!

Since it’s a beta app I’m concerned about the user telemetry being sent back to Brave.

Two weeks ago, the following link was posted in this very thread: GitHub - Anxarden/brave-debloater: Debloat Brave Browser by disabling AI, Rewards, Wallet, VPN, Telemetry, and other extras. · GitHub. I presume this works for the beta version as well.

Has anyone here tried using the Brave Beta browser?

Yes, but I wouldn’t recommend it as a daily driver.

IMO, the value of the beta and nightly channels is to preview and test upcoming features and fixes. And useful for seeing 4-8 weeks into the future. The current beta version of Brave (1.88) will become next month’s stable release. And the current stable (1.87) was last month’s beta.

You can read more about Brave’s release channels here and release schedule here, but this snippet is part of the reason I don’t recommend it as your daily driver:

(also fingerprinting considerations, and other reasons)

Since it’s a beta app I’m concerned about the user telemetry being sent back to Brave.

By default there is quite a lot of data collection in Brave, Including the stable release channel, (they do attempt to collect this information in a privacy preserving way)
2 Likes

Is this list some kind of sick joke? This amount isn’t normal, it’s hard to even just scroll through it. I don’t understand how this is still the recommended browser.

3 Likes

For stable, telemetry for Brave that you allow to collect is processed through P3A. The underlying technology for this system actually took home a major top award from the most prestigious academic cybersecurity conference in the world. It’s the most private data collection method of any browser.

Holy macaroni :sweat_smile:, I also had a hard time just scrolling through the list!

1 Like

Yeah, it’s quite a lot.

You should also be aware of and review Brave’s ad targeting and ad tracking pages for advertisers.

3 Likes