Today we’re introducing Brave Accounts, a brand new way to sign up for our Brave services, such as Email Aliases. However, contrary to what other services do, the way it handles your password is different from other login forms you have ever filled in.
Here’s the short version: when you sign in to a service built on Brave Accounts, your password itself is never sent to our servers: not encrypted, not hashed, nor “briefly held in memory and then discarded”. The password is never transmitted, so you don’t have to “trust” that we are keeping it safe for you. We don’t know it at sign-up, we don’t know it at login, and if someone were to steal our entire password database tomorrow, with high probability they still wouldn’t know it.
How do we do this? We are using cryptography, and specifically using a cryptographic protocol called OPAQUE (recently specified by the IRTF). We are in fact one of the first to use this new cryptography.
Brave Accounts: your password never leaves your device, ever. | Brave
Brave Accounts is a brand-new way to sign into Brave services like Email Aliases. Built on the OPAQUE cryptographic protocol, your password is never sent to our servers—not encrypted, not hashed—so it never leaves your device.

