As @Steve mentioned on the podcast, Chrome now wants to run just like an app on your PC. That is a really, REALLY, * REALLY! * bad idea. I want web apps to be the MOST restricted things on my PC, not the least restricted.
I am a firm believer in going through EVERY setting in a software program when installing or updating, to see what they've done or set wrong from a security or privacy point of view. They ALWAYS do stuff wrong.
Below you will find comprehensive documentation on around 65 settings in Brave that I have reviewed and, in MANY cases, set differently. They will BLOW your mind at how much the browser is trying to access or do behind your back. In some cases, I don't even know what the functions mean. If I don't use it, or know what it is, I turn it off. I turn everything strange off. Site wants to access my data - NO. Site wants to know my location - NO. Site wants to runs scripts - NO unless I really trust them. Site wants to run third party scripts - NO. Sites wants to access any parts of my PC - NO. Site wants to install "protocols" or "handlers" - NO. Etc. The answer is NO, NO, NO unless I have a reason to allow it. The default Firefox and Brave and presumably Chrome settings are WAY too promiscuous. Therefore, I have to reset a whole bunch of stuff. Every time Brave / Chrome updates, they tend to add things, so I have to go through the settings again. The same is true of Firefox.
My extensions in Brave are Privacy Badger, Ublock Origin, Ublock Origin Extra, Tabs Outliner, Lastpass, and H246ify (forces H264 playback on YouTube and optionally forces 30 FPS for lower CPU usage).
If you haven't delved into the Brave / Chrome settings, or haven't done so for Firefox lately, you should. I really think lots of this is stuff your listeners should know. I hope you find this helpful. Thanks for the podcast and for SpinRite.
Sincerely,
Ron
-----------------
Brave Version 1.9.76 Chromium: 81.0.4044.138 (Official Build) (64-bit)
Note how many settings you have to CHANGE when you go through them for the first time.
click lion icon in toolbar, click global shield defaults - goes to shields section of settings
--- shields section ---, select advanced view (This menu has changed a bit since this was written.)
block cross-site trackers ON
upgrade connections to HTTPS ON
block scripts ON
cookies BLOCK CROSS SITE COOKIES
fingerprinting BLOCK ALL FINGERPRINTING
--- social media blocking section ---
allow google login buttons on third party sites OFF
allow facebook logins and embedded posts OFF
allow twitter embedded tweets OFF
allow linkedin embedded posts OFF
--- extensions section ---
(WHAT the heck is all this? I don't want any extensions unless I add them!)
web3 provider for using dapps NONE
hangouts OFF
IFFS companion OFF
media router OFF
private window with tor OFF
web torrent OFF
widevine OFF
--- click additional settings ---
--- privacy and security section ---
(They keep making this harder and harder to access. Now you have to click arrows to open up sub parts of these sections or you'll never see them all.)
autocomplete searches and URL's OFF
webrtc ip handling policy DEFAULT
automatically send completely private product analytics to Brave OFF
use google services for push messaging OFF
remote debugging OFF
help improve brave's features and performance (crash reports) ON
--- clear browsing data subsection ---
(Each person's preferences will differ.)
on exit
browsing history OFF (ie don't clear on exit)
download history ON (ie do clear on exit)
cookies and other site data ON
cached images and files ON
passwords and other sign-in data ON
autofill form data ON
site and shields settings OFF
hosted app data ON
--- site and shields settings subsection ---
(NOTE I block anything and everything that the sites might want to do or access on the computer unless I specifically need that function. Then I turn it on on a site specific basis. The keyword in all of this is do you want a (random) SITE to access this or that or do this or that. The answer is almost universally (for me) NO!)
--- cookies and site data sub subsection ---
allow sites to save and read cookies ON
(subject to the block cross site cookies shield setting)
clear cookies and site data when you quit brave ON
--- location sub subsection ---
location BLOCKED
(Heck NO!)
--- camera sub subsection ---
camera BLOCKED
(Heck NO!)
--- microphone sub subsection ---
microphone BLOCKED
(Heck NO!)
--- motion sensors sub subsection ---
sites' use of motion sensors BLOCKED
(Heck NO!)
--- notifications sub subsection ---
sites' use of notifications BLOCKED
(Heck NO!)
--- autoplay sub subsection ---
ask when a site wants to autoplay media ON
(I am very selective about what I allow to autoplay.)
--- javascript sub subsection ---
(NOTE I have global shields set to block scripts. On a site by site basis, I click the lion icon in the toolbar and allow scripts if I want to, similar to the way noscript works. However, only the main site is allowed when I approve it. In some cases, some sites still break even after the main domain is approved. In such cases, I may go over to firefox and look at noscript, which I still run, to see what other domains might need approval. I can then add them in this subsection. Unless I add scripting either via the lion icon in the toolbar, or in this subsection, scripts are blocked. Sometimes I run sites that break in firefox instead rather than fiddling around here. The noscript interface makes it easier to add various sites to the trust list.)
--- flash sub subsection ---
(NOTE The screen says flash settings will be kept until you quit Brave. So, you cannot save the settings. Also, a banner periodically pops up in Brave that says flash support will be ending.)
ask before running flash ON
(I am very reluctant to allow this permission when asked.)
--- images sub subsection ---
show all images ON
--- pop ups and redirects sub subsection ---
pop ups and redirects BLOCKED
(Heck NO!)
--- sound sub subsection ---
mute sites that play sound MUTING ACTIVE
(Heck NO!)
(NOTE the language is confusing as the slider switch on this screen is off while muting is active. An icon pops up on the toolbar which I can click and allow sound when I want to. Or I can add the site in this subsection.)
--- automatic downloads sub subsection ---
(NOTE This is relevant to an issue you discussed in a recent SN episode. I have had a few times where I wanted to initiate a download and the site wanted to download multiple parts. This also disables that. I don't know for sure if this disables the 1st automatic download.)
(NOTE the language is confusing as the slider switch on the screen is off while download blocking is active.)
do not allow any site to download multiple files automatically ACTIVE
--- unsandboxed plugin access sub subsection ---
(NOTE again confusing language)
do not allow any site to use a plugin to access your computer ACTIVE
--- handlers sub sub section ---
(NOTE confusing language)
do not allow any site to handle protocols ACTIVE
--- MIDI devices sub subsection ---
(NOTE confusing language)
do not allow any sites to use system exclusive messages to access MIDI devices ACTIVE
(Heck NO!)
--- USB devices sub subsection ---
(NOTE confusing language)
do not allow any sites to access USB devices ACTIVE
(Heck NO!)
--- serial ports sub subsection ---
(NOTE confusing language)
do not allow any sites to access serial ports ACTIVE
(Heck NO!)
--- file editing sub subsection ---
(NOTE confusing language)
do not allow any sites to edit files or folders ACTIVE
(Heck NO!)
--- pdf documents sub subsection ---
download pdf files instead of automatically opening them in Brave ON
--- protected content subsection ---
allow sites to play protected content ON
allow identifiers for protected content ON
--- clipboard sub subsection ---
(NOTE confusing language)
do not allow sites to see text and images copied to the clipboard ACTIVE
(Heck NO!)
--- payment handlers sub subsection ---
(NOTE confusing language)
do not allow any site to install payment handlers ACTIVE
(Heck NO!)
--- insecure content sub subsection ---
Insecure content is blocked by default on secure sites. Exceptions can be stored here.
(now backing out of the site and shields settings subsection back to the main privacy and security section)
--- back in main privacy and security section ---
google safe browsing ON
send a do not track request with your browsing traffic ON
allow sites to check if you have payment methods saved OFF
preload pages for faster browsing and searching OFF
--- autofill section ---
(NOTE I don't autofill anything. I don't want my browser remembering anything. I use lastpass for passwords.)
--- passwords subsection ---
offer to save passwords OFF
auto sign-in OFF
--- payment methods subsection ---
save and fill payment methods OFF
--- addresses and more subsection ---
save and fill addresses OFF
--- downloads section ---
ask where to save each file before downloading ON
--- help tips section ---
show wayback machine prompt on 404 pages OFF
--- system section ---
continue running background apps when brave is closed OFF
(Heck NO!)
(NOTE I feel this is a critical security item. If I close the browser, I want everything related to it shut down, PERIOD.)
use hardware acceleration when available ON
Those are my settings. Hope this info is useful.
I am a firm believer in going through EVERY setting in a software program when installing or updating, to see what they've done or set wrong from a security or privacy point of view. They ALWAYS do stuff wrong.
Below you will find comprehensive documentation on around 65 settings in Brave that I have reviewed and, in MANY cases, set differently. They will BLOW your mind at how much the browser is trying to access or do behind your back. In some cases, I don't even know what the functions mean. If I don't use it, or know what it is, I turn it off. I turn everything strange off. Site wants to access my data - NO. Site wants to know my location - NO. Site wants to runs scripts - NO unless I really trust them. Site wants to run third party scripts - NO. Sites wants to access any parts of my PC - NO. Site wants to install "protocols" or "handlers" - NO. Etc. The answer is NO, NO, NO unless I have a reason to allow it. The default Firefox and Brave and presumably Chrome settings are WAY too promiscuous. Therefore, I have to reset a whole bunch of stuff. Every time Brave / Chrome updates, they tend to add things, so I have to go through the settings again. The same is true of Firefox.
My extensions in Brave are Privacy Badger, Ublock Origin, Ublock Origin Extra, Tabs Outliner, Lastpass, and H246ify (forces H264 playback on YouTube and optionally forces 30 FPS for lower CPU usage).
If you haven't delved into the Brave / Chrome settings, or haven't done so for Firefox lately, you should. I really think lots of this is stuff your listeners should know. I hope you find this helpful. Thanks for the podcast and for SpinRite.
Sincerely,
Ron
-----------------
Brave Version 1.9.76 Chromium: 81.0.4044.138 (Official Build) (64-bit)
Note how many settings you have to CHANGE when you go through them for the first time.
click lion icon in toolbar, click global shield defaults - goes to shields section of settings
--- shields section ---, select advanced view (This menu has changed a bit since this was written.)
block cross-site trackers ON
upgrade connections to HTTPS ON
block scripts ON
cookies BLOCK CROSS SITE COOKIES
fingerprinting BLOCK ALL FINGERPRINTING
--- social media blocking section ---
allow google login buttons on third party sites OFF
allow facebook logins and embedded posts OFF
allow twitter embedded tweets OFF
allow linkedin embedded posts OFF
--- extensions section ---
(WHAT the heck is all this? I don't want any extensions unless I add them!)
web3 provider for using dapps NONE
hangouts OFF
IFFS companion OFF
media router OFF
private window with tor OFF
web torrent OFF
widevine OFF
--- click additional settings ---
--- privacy and security section ---
(They keep making this harder and harder to access. Now you have to click arrows to open up sub parts of these sections or you'll never see them all.)
autocomplete searches and URL's OFF
webrtc ip handling policy DEFAULT
automatically send completely private product analytics to Brave OFF
use google services for push messaging OFF
remote debugging OFF
help improve brave's features and performance (crash reports) ON
--- clear browsing data subsection ---
(Each person's preferences will differ.)
on exit
browsing history OFF (ie don't clear on exit)
download history ON (ie do clear on exit)
cookies and other site data ON
cached images and files ON
passwords and other sign-in data ON
autofill form data ON
site and shields settings OFF
hosted app data ON
--- site and shields settings subsection ---
(NOTE I block anything and everything that the sites might want to do or access on the computer unless I specifically need that function. Then I turn it on on a site specific basis. The keyword in all of this is do you want a (random) SITE to access this or that or do this or that. The answer is almost universally (for me) NO!)
--- cookies and site data sub subsection ---
allow sites to save and read cookies ON
(subject to the block cross site cookies shield setting)
clear cookies and site data when you quit brave ON
--- location sub subsection ---
location BLOCKED
(Heck NO!)
--- camera sub subsection ---
camera BLOCKED
(Heck NO!)
--- microphone sub subsection ---
microphone BLOCKED
(Heck NO!)
--- motion sensors sub subsection ---
sites' use of motion sensors BLOCKED
(Heck NO!)
--- notifications sub subsection ---
sites' use of notifications BLOCKED
(Heck NO!)
--- autoplay sub subsection ---
ask when a site wants to autoplay media ON
(I am very selective about what I allow to autoplay.)
--- javascript sub subsection ---
(NOTE I have global shields set to block scripts. On a site by site basis, I click the lion icon in the toolbar and allow scripts if I want to, similar to the way noscript works. However, only the main site is allowed when I approve it. In some cases, some sites still break even after the main domain is approved. In such cases, I may go over to firefox and look at noscript, which I still run, to see what other domains might need approval. I can then add them in this subsection. Unless I add scripting either via the lion icon in the toolbar, or in this subsection, scripts are blocked. Sometimes I run sites that break in firefox instead rather than fiddling around here. The noscript interface makes it easier to add various sites to the trust list.)
--- flash sub subsection ---
(NOTE The screen says flash settings will be kept until you quit Brave. So, you cannot save the settings. Also, a banner periodically pops up in Brave that says flash support will be ending.)
ask before running flash ON
(I am very reluctant to allow this permission when asked.)
--- images sub subsection ---
show all images ON
--- pop ups and redirects sub subsection ---
pop ups and redirects BLOCKED
(Heck NO!)
--- sound sub subsection ---
mute sites that play sound MUTING ACTIVE
(Heck NO!)
(NOTE the language is confusing as the slider switch on this screen is off while muting is active. An icon pops up on the toolbar which I can click and allow sound when I want to. Or I can add the site in this subsection.)
--- automatic downloads sub subsection ---
(NOTE This is relevant to an issue you discussed in a recent SN episode. I have had a few times where I wanted to initiate a download and the site wanted to download multiple parts. This also disables that. I don't know for sure if this disables the 1st automatic download.)
(NOTE the language is confusing as the slider switch on the screen is off while download blocking is active.)
do not allow any site to download multiple files automatically ACTIVE
--- unsandboxed plugin access sub subsection ---
(NOTE again confusing language)
do not allow any site to use a plugin to access your computer ACTIVE
--- handlers sub sub section ---
(NOTE confusing language)
do not allow any site to handle protocols ACTIVE
--- MIDI devices sub subsection ---
(NOTE confusing language)
do not allow any sites to use system exclusive messages to access MIDI devices ACTIVE
(Heck NO!)
--- USB devices sub subsection ---
(NOTE confusing language)
do not allow any sites to access USB devices ACTIVE
(Heck NO!)
--- serial ports sub subsection ---
(NOTE confusing language)
do not allow any sites to access serial ports ACTIVE
(Heck NO!)
--- file editing sub subsection ---
(NOTE confusing language)
do not allow any sites to edit files or folders ACTIVE
(Heck NO!)
--- pdf documents sub subsection ---
download pdf files instead of automatically opening them in Brave ON
--- protected content subsection ---
allow sites to play protected content ON
allow identifiers for protected content ON
--- clipboard sub subsection ---
(NOTE confusing language)
do not allow sites to see text and images copied to the clipboard ACTIVE
(Heck NO!)
--- payment handlers sub subsection ---
(NOTE confusing language)
do not allow any site to install payment handlers ACTIVE
(Heck NO!)
--- insecure content sub subsection ---
Insecure content is blocked by default on secure sites. Exceptions can be stored here.
(now backing out of the site and shields settings subsection back to the main privacy and security section)
--- back in main privacy and security section ---
google safe browsing ON
send a do not track request with your browsing traffic ON
allow sites to check if you have payment methods saved OFF
preload pages for faster browsing and searching OFF
--- autofill section ---
(NOTE I don't autofill anything. I don't want my browser remembering anything. I use lastpass for passwords.)
--- passwords subsection ---
offer to save passwords OFF
auto sign-in OFF
--- payment methods subsection ---
save and fill payment methods OFF
--- addresses and more subsection ---
save and fill addresses OFF
--- downloads section ---
ask where to save each file before downloading ON
--- help tips section ---
show wayback machine prompt on 404 pages OFF
--- system section ---
continue running background apps when brave is closed OFF
(Heck NO!)
(NOTE I feel this is a critical security item. If I close the browser, I want everything related to it shut down, PERIOD.)
use hardware acceleration when available ON
Those are my settings. Hope this info is useful.