Referral code substitution detected in Brave browser when opening some sites

In the Brave web browser identified substitution of referral links when trying to open some sites by typing their domain in the address bar (links do not change on open pages). For example, when you type "binance.com" in the address bar, the autocomplete system automatically adds the referral link "binance.com/en?ref=35089877" to the domain. Similar behavior was observed for coinbase.com, binance.us, ledger.com, and trezor.io domains. Similar actions were accepted by many as incorrect manipulation that undermines the trust of users, or as an attempt to covertly earn money from dishonest project participants.

Project Manager He explained that emergence similar functionality in the input completion mechanism is caused by a bug. Brave does have an affiliate program with Binance and some other crypto exchanges, but the referral code is used in a widget shown in a disable ad unit on the new tab page. The input autocompletion was not supposed to add a referral code to the input address and this problem will be fixed.

The problem is caused by a flaw in the partner ID transfer code when broadcasting queries from the address bar to search engines. Entering keywords in the address bar results in sending a request to the search engine with the transfer of an identifier - such identifiers are transmitted by all browsers participating in programs for paying fees to search engines for traffic. Due to an error, direct domain entry recommended affiliate service also resulted in the affiliate ID being attached to the address bar.

Recall that the web browser Brave developed under the leadership of Brendan Eich, the creator of the JavaScript language and former head of Mozilla. The browser is based on the Chromium engine, focuses on protecting user privacy, includes an integrated engine for cutting ads, can work through Tor, provides built-in support for HTTPS Everywhere, IPFS and WebTorrent, offers Subscription-based funding mechanism for publishers alternative to banners. Project code spreads under the free MPLv2 license.

Addition: Correction came down to disable by default the setting that controls the substitution of Brave recommendations when auto-completing in the address bar (previously the setting was enabled by default). The list of replacements itself, in which referral links are indicated, abandoned in the same way.

Referral code substitution detected in Brave browser when opening some sites

Source: opennet.ru

Add a comment