Conversation

Brave has always been a sketchy browser reeking of desperation. I've taken issue with their usage of DRM, their decision to have a hard dependency on Play Services and their sketchy cryptocurrency activities including their very likely illegal ICO launch.
Quote Tweet
I used to be optimistic about Brave, but I no longer consider it to be a good project. It has had some serious issues with security and the intent behind it is starting to seem nefarious. Monetizing other people's content was always sketchy and their DRM is going far beyond EME.
Show this thread
5
66
Replying to and
They also build with a GCC-based toolchain which loses important security features like type-based CFI. There are other problems with how they build it too. You are better off using a proper build of Chromium, although most Linux distributions lack the competency to provide that.
2
1
This Tweet was deleted by the Tweet author. Learn more
Replying to and
They think they know better, but they don't. By using GCC, they're losing type-based CFI and other security features. By using additional system libraries, they're weakening CFI and losing important changes. Inadvisable changes are often made due to lack of care / understanding.
2
Replying to and
The bulk of the changes being made by these forks are just changing defaults or removing optional features. There are few changes with real substance. Most of those are just changing where static assets are fetched, etc. There aren't any leaks of data for them to remove anyway.
1
Replying to and
how about ungoogled-chromium ? Keeps up to date and seems to have somewhat shared analogous goal in removing Google telemetry/dependencies from Chromium as GrapheneOS does in removing Google Play Services from Android
1
AOSP doesn't have any analytics/telemetry. Chromium analytics/telemetry is gated behind a toggle for submitting usage stats. The same goes for all the other Google services where data is submitted to them. Network connectivity checks and static asset downloads don't have toggles.
2
These forks of Chromium are largely just changing default options and removing the option to use these features. You're not giving any addition data to Google by using Chromium with the Google services disabled in preferences. You just download component updates, etc. from them.
1
1
Show replies