Brave update slams the door on devious 'bounce tracking' technique

Brave browser
(Image credit: Brave)

Brave Software has rolled out an update for its privacy-centric web browser to combat an invasive tracking technique capable of bypassing existing protections.

As explained in the company’s latest blog post, bounce tracking is a method of circumventing protections by pulling users through intermediate domains as they navigate between web pages, without their knowledge. Over time, this practice could supposedly allow a third-party to build up a detailed profile of someone’s interests.

Although Brave already features a number of mechanisms designed to repel bounce tracking attempts, the company is now bolstering its arsenal with a new feature: Unlinkable Bouncing. Under this system, bounce tracking sites are still able to collect information about the user’s interests, but cannot connect that information with data collected on previous occasions.

The new Unlinkable Bouncing feature is currently available in early-access, but will roll out to all users with Brave version 1.37.

The fight against trackers

Although the objective of services like Brave is to shield against all predatory tracking techniques, doing so is effectively impossible as a result of the ever-changing nature of the landscape.

The relationship between Brave and stakeholders in the web tracking market can be compared to that between threat actors and cybersecurity specialists; advances on one side necessitate innovation on the other.

In a recent conversation with TechRadar Pro, CEO Brendan Eich explained that his team is monitoring constantly for chinks in the armor created by “sneaky” new tracking techniques.

“We’ve got an aggressive ongoing agenda, because privacy has an adversary: the trackers, data brokers and ad tech vendors. And they keep evolving; they are always trying new and sneaky ways to get around what Brave does,” he told us.

The latest Brave update is an example of this process playing out; the company has identified a method of tracking capable of weaselling through its existing protection and deployed an additional mitigation.

Specifically, Unlinkable Bouncing utilizes a capability called “first-party ephemeral storage”, which prevents websites from re-identifying users that visit on multiple occasions. The feature is said to be comparable to clearing browser storage each time someone exits a site, but more effective.

“Unlikable Bouncing is just the first application of our first-party ephemeral storage plans, and we’re excited to share more features with Brave users soon,” the company explained.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Firefox icon
Firefox is ending Do Not Track, but there are better ways to protect your privacy – here's what I recommend
Fingerprint
Profit over privacy? Google gives advertisers more personal info in major ‘fingerprinting’ U-turn
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Browser
The future of mobile browsers: time for a new model?
Abstract illustration of a young woman looking at a smartphone, as large eyes peek through from her hair
Want to hit restart on your online presence? Here's 5 tools you need to stay truly private online
female graphic designer pointing with finger on laptop computer during collaboration with male colleague on common project in coffee shop
How sites are falsely blaming ad blockers for site breakdowns
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day