How would that be? AFAIK, trivalent has no fingerprint protection, and ublock is comparably weaker than Brave’s. Also, most telemetry that brave collects is anonymized.
And please note that this comes from someone that really wanted to use trivalent, if not for these reasons. Secureblue is great but it takes inspiration in only the secure part from graphene, mostly putting privacy aside.
UblockOrigin lite is weaker than brave’s adblocker. I believe traditional UblockOrigin is about the same as braves adblocker in strength.
So yes since Trivalent only supports MV3 UblockOrigin lite, the adblocking capability is more limited than Braves AFAIK.
If you listen to people who actually study fingerprint protection, they will tell you that it’s mostly a mirage, and that the relatively weak “protection" provided by Brave is mostly a marketing gimmick. If you need fingerprint protection you need to be using Mullvad Browser or Tor Browser (honestly, probably just Tor Browser). The difference between the little protection that other browsers might provide is minimal.
It is true that Brave claims they anonymize their telemetry. It’s also true that Brave has been caught purposely lying to and taking advantage of customers on multiple occasions. In addition, they regularly add additional privacy disrespecting settings and rely on users to know they were added and go in regularly to change them. Do an experiment. Take a screenshot of your Brave settings. Set yourself a calendar reminder to go back once a month and compare what the settings page looks like from month to month. In my experience, browser updates with Brave would literally sometimes change some of my settings back to the insane default.
It might be one of the better mainstream browsers available, but I would not touch it with a ten foot pole.
Are you currently running SecureBlue as your main daily driver distro?
Yes, that is a more correct way to phrase what I wanted to say. Thanks.
On the matter, even with ublock origin I feel the cookies popups appear much much more in comparison with Brave. Just sharing my cents, could be some configuration issue.
You are correct on the matter of the anonymizing claims. No guarantee at all, but they can be disabled. On the settings reversal matter, I have a similar problem that I lose my cookies and sync settings once every other month that is related to the Linux keyring. I wasn’t really able to solve it consistently, but no more toggles were changed. Yeah, the protection is weak but it really is better than nothing for someone who wants a “just works” browser with good privacy.
What do cookies popups have to do with fingerprinting? Are you assuming that if a site can fingerprint you then they won’t show a cookies popup? FWIW using Trivalent I get a cookies popup on almost every site.
That would be an offtopic comment directed to @seize. Not really related to the fingerprinting thing.
But yes, Brave is arguably much better and private after some manual, easy GUI hardening and debloating.
Just to understand it better, are we saying that PG should recommend one single Chromium browser that requires people to use one specific operating system and one single “flavor” (distro)?
Is that really realistic? I mean that is nice that Trivalent is a good desktop browser but is it something that we can expect mass adoption?
Helium.
Well, I wouldn’t recommend using this browser unless you’re fine with giving up some security.
As you’re probably aware, Helium is a fork of Ungoogled Chromium, and therefore it unfortunately delivers subpar security practices:
1 - UC deployment is inconsistent, with days, and sometimes week, of severe CVEs going unpatched. This was a hard lesson for me, as you can see in my earlier discussion on the topic here: Ungoogled Chromium - #13 by WhiteMoose
“To tie it back to UC, that project is much more likely to inadvertently do what you assumed Trivalent did, since instead of source code changes being entirely comprised of git diffs that generate visible merge conflicts when relevant, they use scripts that edit source code as well. This could lead to unnoticed conflicts, including those involving CVE fixes.”
2 - Updates for UC are already slow, can you imagine how it is for Helium? We’re talking about Chromium → UC → Helium. Not a carved rule but with good ferequency tools that are further removed from the upstream source generally introduce additional security risk.
3 - UC/Helium rely on third-party scripts: Ungoogled Chromium - #3 by dngray
“We won’t be adding that. Builds are managed by untrusted third parties.”
Also: ungoogled-chromium
4 - There are additional concerns discussed here: Browser Account isolation (with seperate browsers) - #4 by dngray
All of this information can be found on the forum. Brave is open source, regardless of what we think about it. People adopt Brave not because it is necessarily the best Chromium-based browser (although I think it might be), but because it is the least bad option.
Yeah, dude, of course I care about UC’s builds. You probably think Helium is built on top of his builds instead of the source code?
Not to mention that Helium made a lot of changes to the UC code, rather than just blindly using everything on top.
Try doing a little research before you post about something instead of just trying to rage bait.
Could you just tell us what modifications have been done to improve it? Because I can’t think of a single thing that’s going to make the situation any better. It’s still rearranging chairs for better feng shui on a sinking ship.
I’m looking at how it’s updated right now and it seems to be heavily fragmented. There is some sort of auto updater for macOS, which seems to be the best option right now, and I use the term best very loosely because it looks like there’s still patch lag on that. There’s also a supply chain weakness I’m seeing here for macOS and Linux, and Windows is even worse. This updater still doesn’t fix or solve the actual architectural problem.
You’re still relying on a small team to merge upstream patches, compile them on third party cloud servers, and push them out after a vulnerability is public. And I’m pretty twitchy about trusting an updater that pulls binaries from a small dev team’s cloud infrastructure. I’ve seen so many hobby project forks come and go, and my own personal threat model relies on being extremely secure as well as private.
I don’t know if I’m missing something here, but given the fact that they seem to be brand new, a very small team. Not to mention, they aren’t providing any sort of solution for MV2 (unless they have money to burn). That single issue is creating a massive domino effect of other problems, so I just don’t see the value in it personally.
Giving the reaction I’d not entertain the discussion any longer. It is better to like his comment and let it be. They are looking for virtual points.
What is the problem with reporting a vulnerability if you already see it?
So? You’re always relying on someone, and everything is built solely on trust, unless it’s Google Chrome, from a major company that’s also the developer of Chromium.
I’m sorry, what? What third-party cloud servers? What do you consider first-party?
What does that mean? Is MV2 supposed to be in the browser or not?
Classic. If they add a new feature, it absolutely has to be enabled by default. It would be fine if it were some kind of useful feature, but it’s always just garbage that violates user privacy and security. Also there’s Brave’s famous Variations feature, which lets developers run A/B tests and remotely change a user’s settings at any time. Obviously, there’s still no option to disable this.
Who are these supposed people? Brave can protect in a similar fashion as Firefox can with FPP.
I wouldn’t go as far as to call it a mirage or a marketing gimmick, that is being hyperbolic. Brave’s fingerprinting protection certainly does have its uses. But it’s very weak when compared to the protections you can get in something like Firefox when it comes to these 10 thousand dollar systems that some services used to fingerprint you.
Brave struggles pretty badly on some of the more advanced fingerprinting techniques, however, I think that’s intentional, because the way they implement it, it’s not supposed to break the web. But from my own use case of visiting almost every site known to man for development, I’ve never had anything break with advanced fingerprinting enabled on Firefox, so I’m not exactly sure what Brave’s game is here on that.
But again, if you’re a purest, you’re obviously going to use Firefox, but Braves protection are adequate for your everyday needs pretty much. Unless you freak out that fingerprint.com can identify brave users every single time, there’s no need to switch.