6 ms·
I support Brave's vision for the Web, but it currently seems to represent a step backwards for privacy. Making payments to providers essentially involves sendin
by ohmygodel 8y ago
I support Brave's vision for the Web, but it currently seems to represent a step backwards for privacy. Making payments to providers essentially involves sending your Web browsing history to Brave. The FAQ states that "we do not know which BAT wallet is associated with the lists of sites that you choose to support". I believe that is false.
I think it works like this: (1) Brave Browser submits its transactions to a Brave server to exchange a BAT for an Anonize ballot (anonize.org), (2) each ballot has the name of a site you visited randomly added by the browser with probability proportional to the frequency of site visits, and (3) the ballots are sent to a Brave server. Key here is that the token and ballot submissions are sent directly (e.g. not through a proxy or Tor). In addition, I believe the ballots may be submitted as a batch (i.e. at one point in time). Therefore, it is easy for Brave to see your votes for your visited websites, all coming at once, all from your IP address. That IP address may well be the same one used to exchange the BAT for ballots as well.
There are additional problems regarding visits to unusual and identifying websites that I feel like Brave hasn't begun to consider, either. Suppose that every and only time that Brave receives a ballot for your personal website, they also receive a ballot for some unpopular and sensitive website. They can then conclude that the owner of the website also visits that sensitive site.
These problems must be addressed before Brave can be considered seriously by privacy-conscious users.
- BrendanEich 8y agoNo history sent to Brave - did you assume this, or read it somewhere? We use ANONIZE2 based on https://anonize.org/ https://anonize.org/ to blind ourselves to your history. Can’t be evil > Don’t be evil. We see only zero-knowledge proofs that say how many votes go to sites or YouTube or Twitch accounts. These proofs do not link to user id or to ine another (so no fingerprint by clustering). They go over an IP address masking service to our accounting server, while your monthly budget goes in a single token transaction. Note Google and other ad tech powers do track your history. Logging into Chrome even gives your history over for ad targeting. Blendle, Flattrplus, other such services also see your history. But we do not.
- ohmygodel 8y agoI understand that Anonize is used for anonymous ballots. I understand that Brave used to submit its ballots via a single-hop proxy. My understanding is now that Brave no longer uses this proxy, which wasn't a good solution anyway because the proxy sees the user's entire set of ballots (aka browsing history). Thus Brave is now given all the ballots directly from the user, and thereby learns the user's browsing history. I do agree that other browsers and services also track users around the Web. Eliminating that is a goal that I support and that I think Brave does as well. I think that it is failing to achieve that goal. Either you don't realize the technical reality of your solution, or you are being misleading.
- BrendanEich 8y agoNo, we do not see any user id. IP address we do see for any “tokens sent to user wallet” cases, for antifraud and per terms & privacy policy, but that is not a useful id and (more important) we do not use it for other purposes per GDPR. See GDPR’s “purpose limitation”. We would face 4% of global revenue fine if we violated this, and we are holding FB, G, and others to same standard. For IP masking in the case where you buy your own tokens, we have two options: 1/ relaying at IP level where we would not see your IP address and the partner would not see any encrypted payloads; 2/ Tor, which is already integrated. More to do but you led with “we see user history” and that is just false in all these cases. We do not see history of sites visited or supported on a linkable to user basis.
- ohmygodel 8y agoAn IP address is an identifier. If it weren't, there would be much less reason to use a VPN or Tor. Suppose I understand you correctly and you do see the network IPs and timestamps of submitted tokens and ballots. Is your argument then that you can be trusted to follow your privacy policy? If we rely on trusting you to follow policy, then why not get rid of your zero knowledge proofs entirely? By saying that you "have two options", it sounds like you are saying that there are two mitigations for the privacy problem that you could use but do not yet. (1) is the one-hop proxy, which used to be used in the form of Private Internet Access service, but it seems like it is not currently being used by Brave. If you did use such a service and encrypted the publisher identities under Brave's public key, then that would be a improvement, although still not really private because Brave would receive the results in a batch from Private Internet Access. Browsing histories are essentially fingerprints for each user. The ten sites I visit each week are almost certainly not shared by any other Brave user on the planet, and moreover they are frequently identifiable (consider sites for individuals, companies, sports leagues, scohols, etc.). From [0]: "Our results show that for a majority of users (69 %), the browsing history is unique and that users for whom we could detect at least four visited websites were uniquely identified by their histories in 97 % of cases." (2) has the same batching problem as (1). It would be superior, though, because it would be harder for Brave and the proxy system to collude or (more likely) be forced to cooperate with some authority. To handle the batching problem, you should at least choose to upload each Anonize ballot at a uniformly random time in each month and on a separate connection (i.e. TCP connection or Tor circuit). You should also explain how this works in a technical document to give people the ability to understand what exactly they are signing up for when they enable payments in Brave. Ideally you would use a cryptographic protocol more suited to strong anonymity than a proxy network, such as a verifiable mix network or a secure-multiparty-computation protocol. [0] Olejnik et al., "On the uniqueness of Web browsing history patterns", 2014, <https://link.springer.com/article/10.1007/s12243-013-0392-5> https://link.springer.com/article/10.1007/s12243-013-0392-5>