Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Employee here- I haven’t seen an official comment here yet

The JSON file that was linked to does have partner domains which (when the header is present) the website will provide a specific integration. When those specific partner sites are visited, the headers are sent with the request

An example someone mentioned here already is marketwatch. They have a promotion where you can sign up for a free subscription if you use Brave

The browser is open source and nothing is being hidden- although this and the whitelist (used for a better webcompat experience) could be better documented

Should these lists be shown in the UI and configurable? (ex: disableable?) I wonder what a better experience would look like for people that don’t want this functionality



Changing the code where it can only inject headers that start with "X-Brave-" would eliminate one class of concerns.

It leaves others, but perhaps your idea of a UI to disable it addresses that somewhat.


This is a great point-

I reviewed with team and created https://github.com/brave/brave-browser/issues/3301 to track this (folks are welcome to give it thumbs up). The fix for this should be something we can deliver in our next product release (0.60.x - 9 days from now)

edit: issue is now fixed! https://github.com/brave/brave-core/pull/1633

I also captured feedback on being able to customize/opt-out of this functionality with https://github.com/brave/brave-browser/issues/3302 (thumbs up and comments appreciated!)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: