Brave Origin

and then ? Do you really know Rust ?

I didn't say that he doesn't know about Linux as he wrote it. He made a comment on stage that he did not have any problems with Microsoft or Google, hence my naive agnostic comment.

No, I am no coder. But usually shortcuts can lead to a cul-de-sac with no access to a reverse gear. I think Felipe does know what he is talking about.

Rust is a great coding language, and for sure some who don't know how to use it or don't understand it will say it's not so good... If we had listen this kind of people, we were stay at the stone age

Like Wayland? I beg to differ. At least in the stone age we didn't have the atomic bomb or nuclear missiles.

Wayland is typically the philosophy of "we know what is good for you" from ubuntu, and your first article talk about ubuntu and rust, you see the problem? Rust language or Canonical devs?

1 Like

That is a weird Comparison.

Nope, the main protagonist, just like systemd and PulseAudio is RedHat:

" Wayland is a free and open-source project developed by a community of volunteers, originally initiated in 2008 by Kristian HĆøgsberg , a Linux graphics developer at Red Hat .

The project's development and code contributions are heavily supported by major technology companies, with Red Hat being the primary corporate contributor, followed by Intel , Samsung , and Collabora . Key figures in the ecosystem also include Drew DeVault , who created the influential sway compositor and wlroots library, and early developers such as Daniel Stone , Peter Hutterer , and Pekka Paalanen ."

Brave A.I. on security issues with Rust:

" While Rust’s ownership model significantly reduces memory safety vulnerabilities, security issues persist primarily in unsafe code blocks , logic errors , and supply chain risks .

Memory and Unsafe Code Risks

Memory safety issues are the most common vulnerability type, accounting for approximately 40% of disclosed vulnerabilities, largely stemming from the use of unsafe Rust which bypasses compiler checks. These include buffer overflows, use-after-free errors, and invalid pointer dereferences. Even in safe code, developers may encounter integer overflows (unchecked in release builds) or deadlocks in concurrent applications.

Logic and Application-Level Vulnerabilities

Rust prevents memory corruption but does not enforce correct security logic . Common issues include:

  • Logic bugs : Incorrect state handling, flawed assumptions, or mismanaged external resources.
  • Input Validation : Vulnerabilities related to tainted input (12.78% of issues) and path resolution (3.89%).
  • Cryptographic Misuse : Improper implementation or usage of cryptographic primitives.
  • Denial of Service (DoS) : Resource exhaustion via memory leaks or hash-based collision attacks.

Tooling and Supply Chain

  • Tooling Risks : The Rust compiler (rustc ), documentation generator (rustdoc ), and formatter (rustfmt ) have known issues such as arbitrary file access , stored XSS , and code execution via macros. The Rust threat model assumes all source code and dependencies are trusted.
  • Supply Chain : Like other ecosystems, Rust is susceptible to malicious crates on crates.io . Developers may inadvertently accept risks from third-party dependencies that exploit compile-time features to exfiltrate data (e.g., SSH keys) or execute arbitrary code."

No, it is not. It stands in Your own AI Output.

Stable release is out: Installing Brave Origin on Linux | Brave

1 Like

I beg to differ as it clearly states that it was started by a RedHat employee.

In respect of Ladybird browser, I decided to unsubscribe from its newsletter - but 'Computer says no' - how bad is that!

I believe a typo - it was well over 20,000 lines of code.

I want to be clear here. I have valid concerns about A.I. usage. Primarily energy usage related.
I must point out that Ladybird's developers usage of this was not to write the program for the browser using A.I.
Rather, this was a conversion operation which they describe looking like "C++ wearing a Rust suit."
That description is apt.

This was heavily managed, reviewed and in concert with human engineers, using two separate process to hasten their writing, not to replace human engineers. This distinction is important.
A.I. has a great deal of potential for misuse. You can imagine a worker being replaced by A.I. then A.I. making the very mistakes and hallucinations it is notorious for.
A.I. can be used properly, however. And Ladybird's application here is an example of Proper Use.
You see... we automate things all the time. The car you drive automates process you used to control yourself.
For tedious replication, automation can be proper and beneficial.

And this brings us to Rust.
Rust is indeed, the Shiny New Language. Does that mean it is better than C?
No.
No, it is not. Does that mean it should replace C? No. Not unless you want to trade one problem for a different problem.
Where Ladybird flies into the fray here is that though they initially rejected Rust and opted for C++, they have changed their tune. What happened?
I really won't get into the technical details on a forum post. That's... TLDR or a brain ache, take your pick.
Instead, I will put it this way:
Rust is rigid.
C++ is dynamic.

This fundamental difference really is the crux of the Opinions and Fighting issue.
Rusts rigidity introduces a software stacking nightmare for developers. It is not dynamic like C++, so for a specific action, you need to keep stacking other specific actions on top of it to handle the One and Only single bit of code that C++ can dynamically handle. It can get complex, quickly.

So, can you use a shoe as a hammer?
Well, I guess in an emergency... and you have no other options; But in the real world, best practice is to Know the Applicability Of Your Tools. And to use the right tool for the job, knowing that no one tool is suited to every job.

Rust is new. And Shiny. But knowing the applicability means: Use it where appropriate properly. It cannot replace C++ in many applications but... that does not mean that it can never replace C++ in certain applications where it is the best fit.
Does it Fit Ladybird?
Basically, the Ladybird developers have decided to prioritize Memory Safety and security over ease.
In short, Rusts rigid build allows that a problem in C++: Memory mismanagement and stack overflow can be bypassed entirely by Rusts borrow checker. In short, that rigid model suits a safer and more secure browser.
There is a cost.
For the developers - that rigidity means a Lot of Extra Work for them. From building the stacks to the grueling process of maintaining it.
They lose the dynamic flow of C++, but gain a rigid security that eases memory management. For a Web Browser: This makes sense.
It means that there is no Perfect Programming Language. But applicability led to a decision. And looking at that applicability, it is justifiable.

Further (and I could be wrong), but from what I have read, the majority of Ladybird will still be in C++. The rust portions being written are drop in replacements for key sections that over a long period of time would replace critical portions of the C++ base, not replace it entirely.

And Rust cannot and should not replace C++ on everything. But it can have its place.

To wrap up my tirade: I have never been a fan of Ladybird. There is not one post where I expressed enthusiasm for it. Or much of anything other than apathy.
Eh... yet another browser. Big whoop.
So, there is no motive from me to Defend My Favorite Browser here. I do not care one bit about Ladybird.

2 Likes

Thor thank you for that link .... I just finished downloading and installing it .... as I am already a Brave user it was a snap to install the new version .... just copied over my passwords and favorites .....

Put my old BB and the new BO side by side with dual windows and copied over all the settings .... went pretty quick only took me about 45 min .... gonna keep the old one loaded for a bit to make sure the new BB works as it should ....

Now to see if Mint will update the Brave Origin ..... I installed it using the terminal ....

1 Like

You are most welcome :+1:

Yikes lol 45mins is nearly an hour. You must have a ton of custom settings. It took me less than 10mins, including porting over the tab page websites which I mouse dragged the addresses, which made it much easier.

I have great news, Brave is working on Sync v3 which is account-based. I imagine that would mean all settings and preferences will be ported over in mere seconds. No more 45mins lol

That did crossed my mind but I eventually removed it after a few hours with Origin. I'll probably miss "Speed Reader", though I hardly used it. Comes in handy. It's the only feature I slightly cared for.

Pretty cool how both versions are nearly identical in terms of being snappy. Amazing how bloated Brave Browser is yet both are identical in speed and responsiveness. I just prefer the much cleaner aesthetic of Origin, even though they are 99% identical when features are removed.

That is how I installed it on Zorin. :smiling_face_with_sunglasses:

sudo apt install brave-origin

1 Like

Took me a bit also. Decided to install it on my Dell 2330 (running Aeryn/ Gnome) using Distrobox. Hadn't done that before, and was curious as to the performance. So far very good!

1 Like

Well... I am gonna be that guy.

Long have I pointed out that when something for the End user is free, we become the product. Examples include Facebook, Google... Need customer service for your Facebook account? Your Youtube account? You won't find one, because you are not the customer.

For a company to charge for the product makes the end user the customer, turning this modern internet paradigm of free cost on its head. Sounds great.

But that is not what Brave Origin is doing.

Paying a premium to undo a company's own monetization choices only makes sense if that company is pivoting its entire philosophy. If Brave Origin was the only browser offered.

When it's just a secondary tier running alongside a massive, multi-million-dollar crypto, AI, and ad-tech operation, it doesn't represent a shift in the paradigm. It is not a return to a healthy "customer-vendor" relationship.
It is a corporate optimization strategy: monetizing the people who hate monetization.

This from the browser that champions the end user? In 2020, it broke that the browser automatically inserted its own affiliate referral codes whenever people typed cryptocurrency URLs directly into the address bar.

They opted Twitter, YouTube, and Reddit creators into their "Brave Rewards" ecosystem without those creators' knowledge or consent, collecting BAT tokens from users on behalf of publishers who hadn't signed up and had no idea the money was sitting in a Brave controlled and accessed account.

It is free on GnuLinux - they are like, "Heh... you guys are already onto us. We'll throw you a bone."
Which is true. No one on GnuLinux needs to feed and pander to this marketing gimmick.

1 Like

I imagine many GNULinux enthusiasts would prefer that the Zorin Bros hadn't got into bed with Brave at all. Why did they? Was it really because of Firefox's change of the legal language re: privacy? They talk about the better web compatibility of Chromium, and native ad-blocking out of the box.

One consequence of this whole free-Brave-Origin-for-GNULinux-users policy may be an increase in GNULinux users on the desktop... and that's good(?) Or is it just increasing the influx of former Windows/Mac users who don't care about GNULinux so much as they hate Microsoft?

Philistines...

There have been... comments.

That said, given the choices, this was a very tight list from the start. Having witnessed that decision process first hand, we saw that the ZorinGroup was more resigned to the fate, not happily jumping to Brave Browser.
They had the mental image of holding a mop, trying to clean up a mess someone else made.

The Firefox fiasco was serious and at the time, big news. From their perspective, taking action was preferable to holding their horses and hoping it would all blow over.
I respect it.
We know how I feel about Brave... But I respect the ZorinGroups decision on this. There was not much else they could do.

Because any of us can install the browser we want. We are not locked in. In Any Way. It's just a browser that Zorin OS offers because it has to come with one.
Many users wipe it out and install Firefox.
Many users opt for other browsers entirely.
To me, it is like the ZorinGroup cooked up a nice dinner, I gobbled up what was on my plate - but did not eat the peas.

And yes, I realize I threw a bucket of cold water on the thread.
Anybody got a towel?

4 Likes

By a RedHat Employee. So, we have to check if this is really Red Hat or only a Guy who works for Red Hat - that isn't the same.

Well, they wrote a Statement for the Reasons. It would be possible to argue that this would be only what they wrote but not their Intentions - what would mean they have lied. I would take the Statement as it is: They didn't liked what Mozilla did and went to another Browser. Also: There were Suggestions for Alternatives what we could name. And they decide for Brave.

I would doubt that. Only because fo the Browser, I can't imagine that People switch a whole OS for. It might be one Reason, but not the Main Reason.

2 Likes