Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)SL
Posts
3
Comments
54
Joined
4 wk. ago

  • I gave you the real reason it should be controversial. Brave's fuck ups have not been significantly worse than other companies'.

    re: open source In theory: yes. In practice: maybe. It'll probably eventually be caught by some researcher but unlike popular belief all open source code bases are not constantly being audited by the community. A random person can't just read Brave source code for all platforms and accurately gauge if they're doing something nefarious. It is very easy to hide stuff in code or misuse a protocol for evil purposes, etc.

    You can modify the source code but as evident by the fact that there's no Brave fork with crypto removed (there was one but their branding was too similar to Brave's so they got sued), it's not an easy feat to maintain that.

  • Running those adblockers on your devices is extremely insecure. They register as a VPN and intercept HTTPS traffic. They decrypt the encrypted traffic, filter it, and encrypt again meaning all your communications are signed by this single app's certificate. Not to mention any vulnerability would wreak havoc.

    https://grapheneos.org/faq#ad-blocking-apps

  • Can you really talk about E2EE on a closed source app? The whole point of E2EE is I don't trust the vendor. If they give me a blob as a client and tell me it's E2EE, am I supposed to just trust them all of a sudden?

  • I know Brave is controversial but they were the only ones (edit: not sure about Vanadium, I'm curious if they were vulnerable) disallowing JS to access localhost thus blocking Meta and Yandex's recently discovered spying.

    Sounds like such a no brainer to not allow random websites to communicate with the localhost and very easily circumvent all sandboxing you spent thousands of hours building. Looking at you Android (Google) and all the browser vendors (also Google?, huh).

  • I am happy they're giving people a choice. On the other hand, the fact is, (privacy respecting) telemetry is the only way to make a program as complicated as a web browser better. Especially important when your competition is a giant data hoarder with orders of magnitude more users. And people will just not turn on opt-in telemetry.

  • Anything is fine unless you're using the terminal very heavily. Almost all of my workflow is within the terminal so I want everything to be as fast as possible. I want a minimal, low config, fast terminal that has the exact same behavior when using the same config on Linux and MacOS (I know, fuck me, I have to use it for work). And those are Alacritty and Ghostty. I hate Alacritty's horrible icon so I use Ghostty.