frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Enabling Media Router by default undermines Brave's privacy claims

2•noguff•1h ago
So, Brave now enables Casting by default on desktop — and does so silently, without explicit notification or consent after an update? What fresh hell is this?

A browser that markets itself as privacy‑first should not be turning on a network discovery feature by default as if it were a trivial setting. If the Brave team’s operational goal is to expand the browser’s attack surface (more than they already have) they’ve made a strong start. Forcing users to manually opt out of Media Router to protect their systems and data directly contradicts the principle of “privacy by default.” This is exactly the kind of behavior many users left Chrome to avoid.

Media Router is not a harmless convenience toggle. Under the hood, it relies on automatic device discovery protocols such as SSDP and UPnP on the local network. That means the browser is actively participating in multicast discovery traffic and probing for devices that advertise casting endpoints. Enabling this behavior by default alters the browser’s network footprint and introduces additional code paths and interactions that would otherwise not exist.

Any feature that performs automated device discovery should be treated as a security‑sensitive capability. SSDP has a long history of being abused in poorly configured environments, and expanding the browser’s participation in that ecosystem increases the potential attack surface. At a minimum, it amplifies observable network activity and exposes extra logic that can be triggered by devices on the local network.

Quietly turning this on without user knowledge or explanation is the opposite of responsible security design. Users were not warned, not asked, and not given any transparency about what the feature does or which protocols it uses. That is not what “privacy by default” looks like.

If Brave wants its privacy claims to remain credible, this needs to change. Apparently Brave’s privacy branding is negotiable when convenience features are involved. Quietly enabling network discovery features in the background is exactly the sort of practice Brave claims to stand against.

Show HN: Adversarial Code Review

https://github.com/gaurav-yadav/adversarial-ai-review
1•rainmod•1m ago•0 comments

How we hire AI-native engineers now: our criteria

https://www.augmentcode.com/blog/how-we-hire-ai-native-engineers-now
1•samuel246•6m ago•0 comments

Stop spending money on Claude Code. Chipotle's support bot is free

https://twitter.com/om_patel5/status/2032248004443287962
1•rmason•7m ago•0 comments

Agent Engine Optimization (AEO): Selling to AI Agents

https://github.com/subconscious-systems/AEO
1•hyluo•9m ago•0 comments

Chaos of Agent

https://agentsofchaos.baulab.info/
1•xdotli•9m ago•1 comments

Why Technology Makes Us More Productive but Not Richer

https://www.fullstackpm.tech/blog/productivity-paradox-capital-lockup
1•harshakcheruku•10m ago•1 comments

Show HN: 3DIMLI – Sell Any Digital Product, Zero Commission

1•arpit077•10m ago•0 comments

AI Software Tells Cops to Arrest the Wrong Guy [video]

https://www.youtube.com/watch?v=lPUBXN2Fd_E
1•stefap2•11m ago•0 comments

Saudi Arabia, Qatar, and the UAE are financing new data corridors

https://restofworld.org/2026/gulf-overland-data-cables-europe-war/
1•colinprince•11m ago•0 comments

I built an offline Text-to-Speech app for iPhone using Kokoro-82M

https://apps.apple.com/us/app/ghost-reader-ai/id6759826819
1•jantheman•17m ago•1 comments

Ask HN: Do you use your smartphones for local LLMs?

1•lavren1974•17m ago•0 comments

China's Road from Revolution to Reform

https://branko2f7.substack.com/p/there-is-a-great-disorder-under-the
2•rmdmphilosopher•22m ago•0 comments

Show HN: Stuffer, browser based QR/NFC inventory management with peer.js sync

https://github.com/EternityForest/Stuffer
1•eternityforest•23m ago•0 comments

Tuish – TUI toolkit in pure portable shell script (bash/zsh/busybox/ksh/mksh)

https://github.com/alganet/tuish
2•gaigalas•23m ago•1 comments

Ironies of Automation

https://en.wikipedia.org/wiki/Ironies_of_Automation
2•py4•26m ago•0 comments

MCPs, CLIs, and skills: when to use what?

https://jngiam.bearblog.dev/mcps-clis-and-skills-when-to-use-what/
1•ankit84•26m ago•0 comments

Ukraine's $1k interceptor drones The Pentagon wants to buy

https://www.militarytimes.com/news/pentagon-congress/2026/03/11/these-are-ukraines-1000-intercept...
1•mizzao•32m ago•0 comments

Show HN: Global Maritime Chokepoints

https://ryanshook.org/chokepoints/
3•RyanShook•34m ago•0 comments

VeryAI raises $10M to build palm-scan identity system on Solana

https://cointelegraph.com/news/polychain-backs-veryai-s-10m-raise-to-build-palm-scan-identity-sys...
1•adrianwaj•37m ago•0 comments

Vite 8.0 Is Out

https://vite.dev/blog/announcing-vite8
18•kothariji•40m ago•1 comments

Some Simple Economics of AGI

https://arxiv.org/abs/2602.20946
1•aray07•43m ago•0 comments

ScraperNode – Scraping API for LinkedIn, Instagram, TikTok, and More

https://scrapernode.com
1•emery_p•43m ago•0 comments

Hugging Face Storage Buckets Storage Bucket

https://huggingface.co/storage
1•tamnd•44m ago•0 comments

2011-2026 time lapse: rebuilding after Tōhoku earthquake and tsunami [video]

https://www.youtube.com/watch?v=ZE-JgL_UUkI
1•kazinator•45m ago•1 comments

Ask HN: Does anyone here use Discord as their work chat tool?

2•Poomba•52m ago•4 comments

AI-generated passwords aren't random, it just looks that way

https://www.theregister.com/2026/02/18/generating_passwords_with_llms/
1•pabs3•53m ago•1 comments

Show HN: ClawRemove – Inspect and clean AI agent environments

https://github.com/tianrking/ClawRemove
1•tianrking•53m ago•1 comments

A Multilingual, IRGC-affiliated Influence Operation on X, Instagram, and Bluesky

https://open.clemson.edu/cgi/viewcontent.cgi?article=1009&context=mfh_reports
1•longislandguido•55m ago•0 comments

Who Will Remember Us When the Servers Go Dark?

https://newdesigncongress.org/en/pub/who-will-remember-us-when-the-servers-go-dark/
2•pabs3•59m ago•0 comments

Native CLI scaffolds consistently outper-form OpenCode when using the same model

https://arxiv.org/abs/2603.08640
1•xdotli•59m ago•1 comments