Hot Take Brave Accounts: your password never leaves your device, ever.

lokamoka820

Level 53
Thread author
Verified
Top Poster
Well-known
Mar 1, 2024
4,210
3
15,041
5,169
Banana Republic
Today we’re introducing Brave Accounts, a brand new way to sign up for our Brave services, such as Email Aliases. However, contrary to what other services do, the way it handles your password is different from other login forms you have ever filled in.

Here’s the short version: when you sign in to a service built on Brave Accounts, your password itself is never sent to our servers: not encrypted, not hashed, nor “briefly held in memory and then discarded”. The password is never transmitted, so you don’t have to “trust” that we are keeping it safe for you. We don’t know it at sign-up, we don’t know it at login, and if someone were to steal our entire password database tomorrow, with high probability they still wouldn’t know it.

How do we do this? We are using cryptography, and specifically using a cryptographic protocol called OPAQUE (recently specified by the IRTF). We are in fact one of the first to use this new cryptography.
 

You may also like...