Breaking
Tech NewsDeveloping Story

Brave's Email Aliases Plug a Privacy Gap

Brave 1.94 lets users generate disposable email addresses to evade tracking and reduce spam.

··3 hours ago·4 min read
windows 7 logo on black background
Photo by Solen Feyissa on Unsplash

Brave's latest browser release takes aim at one of the few remaining links between a user's online identity and their real-world inbox. With version 1.94, the company has introduced a feature called Email Aliases, which lets people generate disposable email addresses when they sign up for a new service. The goal is straightforward: keep the real email address hidden from the website while still allowing messages from that service to reach the user.

Why Email Addresses Are a Privacy Problem

Brave has long used data isolation techniques to prevent websites from correlating user identities through cookies or cache. But email addresses have remained a weak point. They sit on website servers, creating what Brave sees as a privacy gap that cookies and caches don't cover.

The new feature attacks this problem on several fronts. It blocks cross-site identity matching, cuts down on spam, and offers protection against phishing campaigns that often follow data breaches. When a user signs up for a service with a unique alias, the service never sees the primary address, so a breach at that service doesn't expose the user's real inbox to spammers or scammers.

Brave's announcement frames the risk in blunt terms:

“If a website you signed up for is hacked, your information can be leaked and end up with data brokers or worse. Your email address then circulates far beyond the company you originally trusted with it, and can show up in phishing campaigns for years afterward.”

— Brave, in the announcement

How the Alias System Works

To use Email Aliases, users first need a free Brave Account, which is separate from a premium subscription. They register their primary email address with that account, and then the browser can generate aliases on demand. When a user signs up for a new service, the alias forwards messages to the primary inbox.

Brave says the system is free for up to five aliases, but the company plans to introduce a paid Premium version later that would lift that limit. That means the basic tier is enough for a handful of sign-ups, while heavier users might eventually need to pay.

The forwarding process is designed with privacy in mind. Brave stores the primary address and generated aliases in an encrypted state, and forwarded messages are not inspected beyond automated spam and malware filtering. Messages are deleted from Brave's servers within seconds after delivery, so there's no long-term archive sitting on Brave's infrastructure.

Notes Stay Local, Sync Stays Encrypted

Users can attach notes to their aliases, and those notes either remain on the local device or, if synced through Brave Sync, are end-to-end encrypted. That means the notes themselves are not readable by Brave or anyone else intercepting the sync traffic.

This design keeps the alias system from becoming a new data honeypot. The primary address is encrypted at rest, and the forwarded content is ephemeral. Brave is positioning the feature as a way to get the convenience of email forwarding without handing a third party the keys to a user's correspondence.

Authentication Without Transmitting Passwords

In a separate announcement, Brave detailed how Brave Accounts authenticate users. The system uses OPAQUE, a password-authenticated key exchange standardized as RFC 9807, which lets users prove they know a password without transmitting the password or its hash to Brave's servers.

According to Brave, this approach reduces exposure to password logging, memory-scraping attacks, and bulk cracking of leaked password databases. However, Brave notes that it doesn't protect users from phishing or weak passwords. The protocol makes it harder for an attacker to steal credentials from Brave's servers, but it doesn't stop a user from handing over their password to a fake login page.

A Caveat for Early Adopters

Brave cautioned that forwarded messages may initially land in spam folders. As a new email provider, the company has to build up its sending reputation, so users who try the feature early on should keep an eye on their spam filters. That's a practical hurdle for anyone planning to rely on aliases for important sign-ups.

The feature is rolling out with version 1.94, and it's available to anyone willing to create a free Brave Account. The five-alias limit means users can test the system without committing to a paid plan, and the encryption details suggest the company is trying to avoid introducing new privacy risks while solving an old one.

Why It Matters

The email alias feature is a reminder that privacy tools often have to chase the weakest link. Brave has spent effort on cookie isolation and cache partitioning, but the email address is a persistent identifier that doesn't go away when a user clears their browsing data. This move gives users a way to break that chain, at least for new sign-ups.

The implementation has real limits — five free aliases, potential spam-folder delays, and no protection against weak passwords or phishing. But for users who want to limit the blast radius of a data breach, the ability to hand out a throwaway address is a meaningful step. If the paid tier launches as planned, it could push the feature from a nice extra to a core part of how Brave users manage their online identities.

#brave#email aliases#privacy#tracking

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories