Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps this?

The Brave web browser is hijacking links, and inserting affiliate codes

https://davidgerard.co.uk/blockchain/2020/06/06/the-brave-we...

https://news.ycombinator.com/item?id=23442027



The phrase "hijacking links" is, in a word, a lie. Its standard meaning implies that Brave changes the URL loaded when you click on a link (any or many links) in a web page. That never happened, and would be fatally scandalous if tried by any reputable browser.

What happened was a bug in a keyword and domain autocomplete tier we added. Reminder for those not aware: all browsers add reference codes identifying the browser make (not the user) to keyword queries when you type words into the address bar. This is industry standard. See https://twitter.com/BrendanEich/status/1273327455105773568?s....

The bug in Brave was a flag set wrong for two domain names, which are not keywords: binance.us and binance.com. These should not have default-completed when typed into the address bar with a Binance affiliate code, they should have been suggested completions the user would have had to pick by arrow down and <return> or mouse equivalent. We fixed the defaulting bug and turned off the entire suggested completions feature. As noted by someone else in a comment nearby, we instructed Binance not to pay us for any referred new users who traded (Binance does not pay on the referral, they pay only after if the user trades, sharing a fixed proportion of trading fees).

So this was not "link hijacking" in any case. I'm sorry for the blunder, and we added a process step around any changes to address bar to audit harder.


Brendan Eich mentioned it was a default completion bug they got no revenue from, which was fixed:

https://twitter.com/BrendanEich/status/1270128401760743424


Please see https://brave.com/referral-codes-in-suggested-sites/ regarding this claim. It's important to note that Brave never hijacked links, modified pages, our injected codes into content. The browser offered a pre-search list of suggestions for a small set of keywords (see blog post for screenshots). Happy to answer any questions you may have beyond the contents of that blog post. Nothing malicious here; no data or privacy impact either. We were able to fix the behavior within 48 hours (IIRC), and burned the associated affiliate code.


> “Show Brave suggested sites in autocomplete suggestions” setting’s default to “off”

This may be the change I needed to know about to try Brave at some point.

Are there any plans to get into any Linux distro's repositories? Brave wasn't in Ubuntu's last time I checked, although that was a little while ago.

E: Formatting doesn't like asterisks.


I just added it to an Ubuntu (actually Kubuntu), very easy instructions, and familiarly default too - https://brave.com/linux/.

One slight gotcha, if you view the link from Tor it offers an .onion site for the apt repos string, but I wanted the regular repos as I don't use OS-level Tor but happened to be using tor-browser.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: