reSee.it - Tweets Saved By @gnukeith

Saved - January 20, 2025 at 1:48 AM

@gnukeith - Keith

Protect your privacy/security, anon. https://t.co/incLaMGu5v

Saved - January 20, 2025 at 12:24 AM
reSee.it AI Summary
Brave effectively detects and blocks CNAME cloaking tactics used by trackers, outperforming traditional ad blockers like uBO on Gecko-based browsers. Its Shields feature blocks ads at the browser level before they load, conserving bandwidth and battery life by preventing unnecessary network requests. Brave also offers native protection against local network exploitation and implements ephemeral storage partitioning to manage third-party data. This advanced storage management and network-state partitioning provide robust defenses against sophisticated tracking techniques, minimizing the overhead associated with extensions.

@gnukeith - Keith

Brave can detect and block trackers that use CNAME cloaking tactics to hide their true origin and bypass traditional ad blockers, this is something that uBO is better at on Gecko based browsers, but Brave Shields isn't an extensions. Fighting against CNAME-based tracking is something people don't understand how important it really is: https://www.helpnetsecurity.com/2021/02/24/browsers-anti-tracking/ Brave Shields blocks ads at the browser level before they are even loaded onto a webpage, rather than blocking them after loading. When content is blocked at the browser level before loading, it prevents unnecessary network requests entirely. https://brave.com/blog/brave-saves-batteries/ This means that it doesn't waste bandwidth downloading ads, trackers, or malicious scripts that would be blocked anyway, this also helps with battery since resources don't need to take it into account since it's blocked before the page loads. Native protection against websites attempting to interact with local network resources, blocking attempts to scan ports or identify running services. https://github.com/brave/adblock-lists/blob/758de6cf238840e5741261a2796d57a90274bfc1/brave-lists/brave-specific.txt#L1-L4 Browsers without proper local network protections could be exploited: https://www.helpnetsecurity.com/2024/08/09/0-0-0-0-day-vulnerability-affects-chrome-safari-and-firefox/ This requires low-level access to the network stack that extension-based blockers cannot achieve. There is also ephemeral storage partitioning, so implements a unique ephemeral storage system that automatically deletes third-party storage while maintaining site functionality. This level of storage management requires native browser code access. Network-state partitioning that protects against sophisticated tracking techniques that attempt to abuse network caches and connection data. This partitioning occurs at the browser's core network stack level. https://brave.com/glossary/partitioning/ Extensions take memory and OS overhead too.

CNAME-based tracking increasingly used to bypass browsers' anti-tracking defenses - Help Net Security CNAME cloaking evades anti-tracking measures on most widely-used browsers and introduces serious security and privacy issues. helpnetsecurity.com
Significant Battery Savings with Brave on Mobile: Brave Consumes 40% Less Battery than Other Leading Browsers | Brave Brave mobile users can expect up to two and a half extra hours of browsing per battery charge. brave.com
adblock-lists/brave-lists/brave-specific.txt at 758de6cf238840e5741261a2796d57a90274bfc1 · brave/adblock-lists Maintains adblock lists that Brave uses. Contribute to brave/adblock-lists development by creating an account on GitHub. github.com
"0.0.0.0-Day" vulnerability affects Chrome, Safari and Firefox - Help Net Security A "0.0.0.0-Day" vulnerability affecting Chrome, Safari and Firefox can be - and apparently has been, for years - exploited by attackers. helpnetsecurity.com
Partitioning Meaning & Definition | Brave Online privacy can be confusing. In this easy-to-read list, you'll find short definitions of essential privacy and Internet terms including Partitioning. Check out the Brave Privacy Glossary here. brave.com
Saved - January 19, 2025 at 10:57 PM
reSee.it AI Summary
Brave utilizes a modified version of Chromium, removing unwanted features and integrating patches from the ungoogled-chromium project. Its Shields block network requests from extensions, offering enhanced tracking protection through CNAME uncloaking and Sugarcoat technology to counter anti-adblock scripts. The Shields are built in Rust for improved performance. Brave also employs Farbling, which randomizes browser APIs to prevent fingerprinting, ensuring different fingerprints for each session or site. Additionally, Brave has created a Private CDN to safeguard user privacy while accessing content.

@gnukeith - Keith

Brave is using a stripped-down version of Chromium with the bad bits removed/nullified. https://github.com/brave/brave-browser/wiki/Deviations-from-Chromium-(features-we-disable-or-remove) Brave has an issue captured for pulling in relevant patches from the ungoogled-chromium project. https://github.com/brave/brave-browser/issues/1431 Brave shields can blocks network requests from extensions, which uBO cannot do as an extension. Implements CNAME uncloaking directly at the browser level for better tracking protection. Features Sugarcoat technology to defuse anti-adblock scripts more effectively. https://brave.com/privacy-updates/6-cname-trickery/ https://brave.com/privacy-updates/12-sugarcoat/ https://brave.com/privacy-updates/10-custom-filter-lists/ https://brave.com/privacy-updates/1-web-resource-replacements/ Apart from Brave Shields being a full stack, it's written in Rust. https://brave.com/blog/improved-ad-blocker-performance/ https://github.com/brave/adblock-rust Farbling is Brave's technique of adding subtle randomization to certain browser APIs to prevent fingerprinting. Randomization is based on a seed that changes per: > Session > Site (eTLD+1) eTLD stands for "effective Top Level Domain" and eTLD+1 refers to the effective top-level domain plus one level down - essentially the registrable domain name that a person or organization can directly register. > Storage area https://github.com/brave/brave-browser/wiki/Fingerprinting-Protections Visit a site like https://browserleaks.com/canvas, note the fingerprint, and then visit the same site in: > Private Window > Private Window with Tor > After restarting the browser > In a different profile You should get a different fingerprint each time. Here's another test: https://dev-pages.brave.software/fingerprinting/farbling.html Not to mention that Brave has developed a Private Content Delivery Network (CDN) to protect user privacy while delivering content. https://brave.com/blog/brave-private-cdn/ Prevent users from touching yet another Google endpoint: https://github.com/brave/brave-browser/issues/1715

Deviations from Chromium (features we disable or remove) Brave browser for Android, iOS, Linux, macOS, Windows. - Deviations from Chromium (features we disable or remove) · brave/brave-browser Wiki github.com
make sure we have necessary fixes from Ungoogled Chromium · Issue #1431 · brave/brave-browser People often ask how Brave compares to https://github.com/Eloston/ungoogled-chromium. This is a tracking issue to go through all the patches and options set in https://github.com/Eloston/ungoogled-chromium and make sure we have any that ... github.com
Fighting CNAME trickery | Brave Trackers are constantly working on new techniques for evading privacy tools, and keep deploying new ways to evade privacy-protecting tools like the Brave browser. This post discusses a recent technique trackers use, CNAME cloaking, and a new feature in Brave that keeps Brave users protected. brave.com
Brave and UC San Diego announce SugarCoat, a new solution to strengthen the protection of Web users’ privacy while not breaking websites | Brave Brave is pleased to announce SugarCoat, the result of a year-long research collaboration with University of California San Diego to create a new system to improve Web privacy without sacrificing compatibility at Web scale. brave.com
Custom filter list subscriptions | Brave Starting in version 1.31, Brave will support custom filter list subscriptions, allowing users to further control how unwanted network requests and in-page elements are blocked in Brave. This work is part of Brave’s goal of providing best-of-breed content filtering tools, and keeping people in control of their Web browsing. brave.com
Web resource replacements | Brave Problem: Blocking Trackers Sometimes Breaks Sites. One of many ways Brave protects your privacy on the Web is by blocking requests to trackers. By blocking these requests, Brave prevents you from being followed around the Web, and from ad companies, data brokers, and other privacy-harming parties from recording your online activity. brave.com
Brave Improves Its Ad-Blocker Performance by 69x with New Engine Implementation in Rust | Brave Brave Shields, which protect users’ privacy from trackers and ads, are one of the cornerstone components of the browser involved in handling every single web request made for loading a website. brave.com
GitHub - brave/adblock-rust: Brave's Rust-based adblock engine Brave's Rust-based adblock engine. Contribute to brave/adblock-rust development by creating an account on GitHub. github.com
Fingerprinting Protections Brave browser for Android, iOS, Linux, macOS, Windows. - Fingerprinting Protections · brave/brave-browser Wiki github.com
Canvas Fingerprinting Canvas fingerprinting is a tracking method that uses HTML5 Canvas code to generate a unique identifier for each individual user. The method is based on the fact that the unique pixels generated through Canvas code can vary depending on the system and browser used, making it possible to identify users. browserleaks.com
Brave Private Content Delivery Network | Brave Brave is a company where privacy isn’t just a feature; it’s a requirement. This is perhaps most obvious in the Brave Browser, where we block trackers, prevent fingerprinting, and include a privacy-preserving, opt-in and user-first ad-system, but Brave’s focus on privacy goes far beyond the browser. brave.com
Prevent connection to gstatic at startup · Issue #1715 · brave/brave-browser Description Prevent connection to gstatic at startup Steps to Reproduce Launch new profile Use Charles Proxy to capture network events gstatic shows up which should have been blocked with #1684 Actual result: Expected result: All gstatic... github.com
Saved - January 19, 2025 at 6:21 PM

@gnukeith - Keith

@qeldegna @lossofclarity @xvfos Brave Rewards are moving to on-chain which doesn't require KYC. Brave has never mined crypto/anything off peoples computers. Brave Shields actively blocks them.

Saved - January 19, 2025 at 6:18 PM

@gnukeith - Keith

@ConvxO2 @lossofclarity @xvfos Make sure you have Cookies and other site data toggled off when clearing things on exit. brave://settings/clearBrowserData Check if you have FMWICTS on: https://t.co/eNkZy9BMkI

Saved - January 19, 2025 at 6:03 PM

@gnukeith - Keith

@lossofclarity @xvfos Not to mention: https://www.bleepingcomputer.com/news/security/tor-says-its-still-safe-amid-reports-of-police-deanonymizing-users/ This is essentially a small-scale proof of concept. What occurs when it's implemented on a much larger scale? https://www.tagesschau.de/investigativ/panorama/tor-netzwerk-100.html

Tor says it’s "still safe" amid reports of police deanonymizing users The Tor Project is attempting to assure users that the network is still safe after a recent investigative report warned that law enforcement from Germany and other countries are working together to deanonymize users through timing attacks. bleepingcomputer.com
Ermittlungen im Darknet: Strafverfolger hebeln Tor-Anonymisierung aus Das Tor-Netzwerk gilt als wichtigstes Werkzeug, um sich anonym im Internet zu bewegen. Behörden haben begonnen, es zu unterwandern, um Kriminelle zu enttarnen. In mindestens einem Verfahren waren sie erfolgreich. Von R. Bongen und D. Moßbrucker. tagesschau.de
Saved - January 19, 2025 at 6:00 PM

@gnukeith - Keith

@lossofclarity @xvfos TOR and TOR browser are two different things. TOR is well aware of Firefox's (Gecko) limitations. https://web.archive.org/web/20241225063856/https://gitlab.torproject.org/tpo/applications/tor-browser/-/wikis/Hardening

Hardening · Wiki · The Tor Project / Applications / Tor Browser · GitLab Tor Browser aims to make all users look the same, making it difficult for you to be fingerprinted based on your browser and device information. Release calendar is... web.archive.org
View Full Interactive Feed