Brave's Email Aliases Plug a Privacy Gap
Brave 1.94 lets users generate disposable email addresses to evade tracking and reduce spam.
Brave's latest browser release takes aim at one of the few remaining links between a user's online identity and their real-world inbox. With version 1.94, the company has introduced a feature called Email Aliases, which lets people generate disposable email addresses when they sign up for a new service. The goal is straightforward: keep the real email address hidden from the website while still allowing messages from that service to reach the user.
Why Email Addresses Are a Privacy Problem
Brave has long used data isolation techniques to prevent websites from correlating user identities through cookies or cache. But email addresses have remained a weak point. They sit on website servers, creating what Brave sees as a privacy gap that cookies and caches don't cover.
The new feature attacks this problem on several fronts. It blocks cross-site identity matching, cuts down on spam, and offers protection against phishing campaigns that often follow data breaches. When a user signs up for a service with a unique alias, the service never sees the primary address, so a breach at that service doesn't expose the user's real inbox to spammers or scammers.
Brave's announcement frames the risk in blunt terms:
“If a website you signed up for is hacked, your information can be leaked and end up with data brokers or worse. Your email address then circulates far beyond the company you originally trusted with it, and can show up in phishing campaigns for years afterward.”
— Brave, in the announcement
How the Alias System Works
To use Email Aliases, users first need a free Brave Account, which is separate from a premium subscription. They register their primary email address with that account, and then the browser can generate aliases on demand. When a user signs up for a new service, the alias forwards messages to the primary inbox.
Brave says the system is free for up to five aliases, but the company plans to introduce a paid Premium version later that would lift that limit. That means the basic tier is enough for a handful of sign-ups, while heavier users might eventually need to pay.
The forwarding process is designed with privacy in mind. Brave stores the primary address and generated aliases in an encrypted state, and forwarded messages are not inspected beyond automated spam and malware filtering. Messages are deleted from Brave's servers within seconds after delivery, so there's no long-term archive sitting on Brave's infrastructure.
Notes Stay Local, Sync Stays Encrypted
Users can attach notes to their aliases, and those notes either remain on the local device or, if synced through Brave Sync, are end-to-end encrypted. That means the notes themselves are not readable by Brave or anyone else intercepting the sync traffic.
This design keeps the alias system from becoming a new data honeypot. The primary address is encrypted at rest, and the forwarded content is ephemeral. Brave is positioning the feature as a way to get the convenience of email forwarding without handing a third party the keys to a user's correspondence.
Authentication Without Transmitting Passwords
In a separate announcement, Brave detailed how Brave Accounts authenticate users. The system uses OPAQUE, a password-authenticated key exchange standardized as RFC 9807, which lets users prove they know a password without transmitting the password or its hash to Brave's servers.
According to Brave, this approach reduces exposure to password logging, memory-scraping attacks, and bulk cracking of leaked password databases. However, Brave notes that it doesn't protect users from phishing or weak passwords. The protocol makes it harder for an attacker to steal credentials from Brave's servers, but it doesn't stop a user from handing over their password to a fake login page.
A Caveat for Early Adopters
Brave cautioned that forwarded messages may initially land in spam folders. As a new email provider, the company has to build up its sending reputation, so users who try the feature early on should keep an eye on their spam filters. That's a practical hurdle for anyone planning to rely on aliases for important sign-ups.
The feature is rolling out with version 1.94, and it's available to anyone willing to create a free Brave Account. The five-alias limit means users can test the system without committing to a paid plan, and the encryption details suggest the company is trying to avoid introducing new privacy risks while solving an old one.
Why It Matters
The email alias feature is a reminder that privacy tools often have to chase the weakest link. Brave has spent effort on cookie isolation and cache partitioning, but the email address is a persistent identifier that doesn't go away when a user clears their browsing data. This move gives users a way to break that chain, at least for new sign-ups.
The implementation has real limits — five free aliases, potential spam-folder delays, and no protection against weak passwords or phishing. But for users who want to limit the blast radius of a data breach, the ability to hand out a throwaway address is a meaningful step. If the paid tier launches as planned, it could push the feature from a nice extra to a core part of how Brave users manage their online identities.
Sources
- BleepingComputer Original source
Continue Reading
Razer Naga V3 Pro: Versatile but Heavy
Razer's Naga V3 Pro offers swappable button plates for MMO, MOBA, and FPS, but its weight and price may limit appeal.
Lambda's Debt-Fueled Chip Expansion
AI cloud firm Lambda raises $1B in private debt to buy Nvidia chips for Microsoft lease.
A Belgian bet on two-wheeler cargo
Belgian startup Any pitches modular electric motorcycle LUV1 with 120 liters of cargo space.