Brave just introduced Brave Accounts”and they’re doing password auth differently from basically every normal website.The interesting bit: your password is never sent to Brave’s servers. Not plaintext, not encrypted, not hashed. It never leaves your device.They’re using OPAQUE, a relatively new password-authenticated key exchange (published as RFC 9807 in 2025). During signup/login, the client and server perform an OPRF-based cryptographic exchange that lets the client prove it knows the password without revealing it.The server stores cryptographic material derived from the password + a server secret, rather than an encrypted copy/hash of the password itself. Argon2id is also used to make password guessing expensive.Why this matters:No plaintext password ever reaches Brave’s auth infrastructure less risk from logs, memory scraping, compromised auth components, rogue insiders, etc.A stolen password database isn't immediately useful for mass offline cracking.The server-side secret prevents attackers from doing huge precomputed password dictionaries in advance.Offline guessing after a full compromise is still possible, but it becomes a per-user, expensive grind.OPAQUE also produces an export key, which can potentially be used for E2E-encrypted data without Brave ever possessing the encryption key.They’re planning to use this as the foundation for things like Email Aliases and potentially Brave Sync, including password-based bootstrapping of E2E-encrypted sync on new devices.Obviously it isn't magic: phishing can still steal your password before OPAQUE runs, weak passwords are still weak, and a fully compromised server can still allow offline guessing.But conceptually this is pretty fucking cool: instead of asking users to trust the server with their password and hoping the password database/auth stack never leaks it, the protocol is designed so the server never gets the password in the first place.
>>109663985it really is quite amazing how brave managed to make a browser seem so disreputable and scummybut sure I'm going to trust them with my actual data
buy an ad
>>109664158You lost tranny
>>109663985Not bad but they have 0% integrity They will just sell your data like GoogleIf you want account system use Apple, they won't sell your data to companies just feds, if they have to.
>>109663985Advantages over just using passkeys (preferably hardware-backed)?
>>109664387Passkeys are better for authentication.OPAQUE's advantage is if you want to use normal passwords without server side password leaks and enables secure cloud data recovery.
>>109664158fpbpwhy are these retards posting press releases to 4chan anyway?
>>109664989Because fuck you, troon, that's why.>>109663985>weak passwords are still weakI'm always concerned about "muh new security," without requiring simpler things before hand. This may be more marketing than anything else, because anything "complicated" can have an implementation vulnerability.
>>109663985Wow, just what this malware needed, more fucking bloat. Lol.
>>109664158Why does this browser cause so much irrational asspain everywhere?
>>109665399Idk I don't really care, hide the gay crypto icon, never sign up for their sbemail, I just want a browser that blocks ads on an ipad.
>>109665399I think it's fine but the incessant shilling is quite obnoxious
>>109665259Le shill lion is now leseethe lion? How sad.