[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


[Advertise on 4chan]


File: 1783149559542605.jpg (55 KB, 1131x636)
55 KB JPG
Brave just introduced Brave Accounts”and they’re doing password auth differently from basically every normal website.

The interesting bit: your password is never sent to Brave’s servers. Not plaintext, not encrypted, not hashed. It never leaves your device.

They’re using OPAQUE, a relatively new password-authenticated key exchange (published as RFC 9807 in 2025). During signup/login, the client and server perform an OPRF-based cryptographic exchange that lets the client prove it knows the password without revealing it.

The server stores cryptographic material derived from the password + a server secret, rather than an encrypted copy/hash of the password itself. Argon2id is also used to make password guessing expensive.

Why this matters:

No plaintext password ever reaches Brave’s auth infrastructure less risk from logs, memory scraping, compromised auth components, rogue insiders, etc.
A stolen password database isn't immediately useful for mass offline cracking.
The server-side secret prevents attackers from doing huge precomputed password dictionaries in advance.
Offline guessing after a full compromise is still possible, but it becomes a per-user, expensive grind.
OPAQUE also produces an export key, which can potentially be used for E2E-encrypted data without Brave ever possessing the encryption key.

They’re planning to use this as the foundation for things like Email Aliases and potentially Brave Sync, including password-based bootstrapping of E2E-encrypted sync on new devices.

Obviously it isn't magic: phishing can still steal your password before OPAQUE runs, weak passwords are still weak, and a fully compromised server can still allow offline guessing.

But conceptually this is pretty fucking cool: instead of asking users to trust the server with their password and hoping the password database/auth stack never leaks it, the protocol is designed so the server never gets the password in the first place.
>>
>>109663985
it really is quite amazing how brave managed to make a browser seem so disreputable and scummy
but sure I'm going to trust them with my actual data
>>
buy an ad
>>
>>109664158
You lost tranny
>>
>>109663985
Not bad but they have 0% integrity
They will just sell your data like Google
If you want account system use Apple, they won't sell your data to companies just feds, if they have to.
>>
>>109663985
Advantages over just using passkeys (preferably hardware-backed)?
>>
>>109664387
Passkeys are better for authentication.
OPAQUE's advantage is if you want to use normal passwords without server side password leaks and enables secure cloud data recovery.
>>
>>109664158
fpbp
why are these retards posting press releases to 4chan anyway?
>>
>>109664989
Because fuck you, troon, that's why.

>>109663985
>weak passwords are still weak

I'm always concerned about "muh new security," without requiring simpler things before hand. This may be more marketing than anything else, because anything "complicated" can have an implementation vulnerability.
>>
>>109663985
Wow, just what this malware needed, more fucking bloat. Lol.
>>
>>109664158
Why does this browser cause so much irrational asspain everywhere?
>>
>>109665399
Idk I don't really care, hide the gay crypto icon, never sign up for their sbemail, I just want a browser that blocks ads on an ipad.
>>
>>109665399
I think it's fine but the incessant shilling is quite obnoxious
>>
File: 1755091928704720.png (107 KB, 300x254)
107 KB PNG
>>109665259
Le shill lion is now leseethe lion? How sad.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.