2 ms·
TL;DR: Brave lied about blocking 3rd party JS and I no longer trust them. The main reason I don't use Brave anymore is because I don't trust the Brave team to
by lasmellslikepee 8y ago
TL;DR: Brave lied about blocking 3rd party JS and I no longer trust them.
The main reason I don't use Brave anymore is because I don't trust the Brave team to be transparent about what they're doing. I remember switching to Brave a year or two ago really rooting for them and the model they were positing. I though that blocking third-party JavaScript by default was a great idea - no more Firefox plugins! Well, I soon realized that Brave did not block all third-party JS and instead let "whitelisted"(by whom?) JS through. When I asked one of the Brave team members why this was so and informed them that I found this practice misleading at best I was given a song-and-dance about "rescuing the industry" instead of a technical explanation for the issue at hand(blocking third-party JS essentially didn't work).
I can't be bothered to use a browser who's developers can't be bothered to be honest about the feature set and how they work.
- jonathansampson 8y agoBrave doesn't promise to block all third-party scripting; that isn't necessarily a bad thing. If we were to block all third-party scripts, the web as a whole would largely crumble. Instead, we are judicious about which scripts we block, and which ones are harmless. As for transparency, we couldn't be more open. Take it from me, an ex-Microsoft engineer, Brave is an open book. We talk about features before they're shipped, our source is open to all (github.com/brave/browser-laptop, github.com/brave/brave-browser, github.com/brave/browser-core, etc.), and we regularly host AMAs. The openness of this company still, to this day, gives me wonderful culture shock. With regards to your conversation with one of the Brave team members, do you have a link? I'd love to gather context and establish a frame of reference. The only white lists we have in brave are for ua-strings and siteHacks. For some websites, we'll identify ourselves as "Brave". To all others, we identify as Chrome. This is for many reasons (which I'm happen to discuss if you're interested), but this is the first white list. The second "white list" would be our siteHacks.js file. This file contains special logic to repair sites which are broken as a result of ad/tracker blocking. But again, this isn't letting flagged scripting through to the user, this is laying our own custom logic on top of an otherwise broken experience. I hope this explanation helps shed some light on the matter. If you have any questions, comments, or feedback, please do not hesitate to reach out. Again, we're open and eager to share.
- jonathansampson 8y agoCorrection: The third GitHub link should have read github.com/brave/brave-core (instead of "browser-core").