Skip to content
This repository has been archived by the owner. It is now read-only.

Brave is detectable #11012

Closed
ghost opened this issue Sep 19, 2017 · 8 comments
Closed

Brave is detectable #11012

ghost opened this issue Sep 19, 2017 · 8 comments
Labels

Comments

@ghost
Copy link

@ghost ghost commented Sep 19, 2017

Brave can be detected. There are 7 possible ways to easily identify brave, without canvas and shields off. Will be disclosed on hacker one, if bounty eligible. Else solution will be released commercially,

@luixxiul
Copy link
Contributor

@luixxiul luixxiul commented Sep 19, 2017

@luixxiul
Copy link
Contributor

@luixxiul luixxiul commented Sep 19, 2017

@diracdeltas will this be closed in favor of #10655?

@ghost
Copy link
Author

@ghost ghost commented Sep 19, 2017

@luixxiul At that time there were 3 ways. Now I've found 7 ways. Even with the latest update there were no fixes.

@diracdeltas
Copy link
Member

@diracdeltas diracdeltas commented Sep 19, 2017

Although our HackerOne bounty program lists detecting Brave as out-of-scope, I would accept this as eligible if you found an attack that sets the User-Agent (or some other commonly-logged browser property) to Brave instead of Chrome OR if the attack worked with scripts disabled.

@ghost
Copy link
Author

@ghost ghost commented Sep 19, 2017

1 method of the attack can detect without JavaScript enabled. Most reliable one uses JS. Easy Fixes are not easily possible for 1 way(JS way). So its eligible? I will submit after clarification here otherwise I can just give it away to Admiral, they'll be happy, and would reward.

@luixxiul
Copy link
Contributor

@luixxiul luixxiul commented Sep 20, 2017

@diracdeltas please close this if this will be also triaged through hackerone.

https://github.com/AhsanE/BraveBrowserDetection

@luixxiul luixxiul added the needs-info label Sep 20, 2017
@ghost
Copy link
Author

@ghost ghost commented Sep 20, 2017

@diracdeltas Will wait for 1 business day for the reply. Otherwise response will be assumed as negative.

@diracdeltas
Copy link
Member

@diracdeltas diracdeltas commented Sep 20, 2017

closing this and waiting on the hackerone report, thanks

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.