Photo Depicting Brave Brand
© rafapress/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

The Brave browser is set to introduce “localhost” resource permissions to allow users to control which sites have access to local network resources, the company announced on Tuesday.

The new feature, which will only become available with Brave version 1.54, is expected to boost user privacy and security, Brave said in its announcement.

Local network resources, or “localhost resources,” refer to various resources like images or pages hosted on a user’s device. Many browsers, including Google Chrome and Mozilla Firefox, allow websites to access local network resources without restrictions.

“Unfortunately, a wide range of malicious, user-harming software on the Web uses access to localhost resources for malicious reasons. For example, fingerprinting scripts try to detect unique patterns in the other software you have running on your device to re-identify you, and other scripts try to identity insecure and vulnerable software on the machine and try to exploit it,” the Brave team said.

Unrestricted access to these resources has long been a security concern, and Brave is seeking to address it by putting control back into the hands of the users.

The Localhost Permission: A Game Changer

While most websites request access to localhost resources for “benign” reasons, it opens up potential security vulnerabilities.

“Brave’s control over sites accessing localhost resources vastly improves user privacy. Popular sites like eBay and Ameriprise port scan (a common use for accessing localhost resources) their users, allowing users to be re-identified in harmful ways,” Peter Snyder, Brave’s vice present of privacy engineering, told VPNOverview in an email. “Worse, accessing localhost resources can also be used by malicious scripts (in rare but important) cases to exploit vulnerabilities on other software running on your machine.”

Brave has adopted a unique approach to managing requests for localhost resources. Currently, Brave blocks scripts that maliciously scan localhost resources and requests from public sites to access localhost resources.

Brave’s localhost permission ensures only sites that have been granted permission can make sub-resource requests to localhost resources. By default, no sites possess this permission, and most sites cannot prompt users for it.

Brave will also maintain a list of trusted sites that access localhost resources for beneficial reasons. When a site from Brave’s allow list initiates a request to a localhost resource for the first time, users will receive a prompt for the localhost permission. If users grant permission, the site will be able to request localhost resources for the duration the user has approved.

If the site is not on Brave’s allow list, it can’t prompt users for permission to localhost resources. However, users can manually grant this permission to specific sites through the site settings interface.

Snyder explained that the allow lihst is “manually curated by Brave, and is built from the results of automated crawls and manually filed bug reports.”

“In building the list, we try to assess whether a user would understand why the site is trying to access localhost resources and if it’s being done for a user-serving purpose (instead of a privacy or security violating purpose,” he said.

This addition of localhost resources permission makes Brave the only browser that blocks requests to localhost resources from both secure and insecure public sites while maintaining a compatibility path for sites that users trust.

While Safari and other WebKit browsers block requests to access localhost resources, the Brave team said this appears to be a side-effect of security restrictions.

Browsing the Web Privately

Brave said it is looking into how to “better explain” localhost resources and the new permissions to users.

“Once we’re confident we’ve found a way of explaining what the permission controls that non-advanced users can understand, we plan on making the permission available to all sites, and not only those on our list,” the Brave team said.

Brave is also working to extend these protections deeper into the network stack to guard against less common methods of localhost requests.

The Brave browser has received key updates to its privacy features this year. In January, Brave added the Snowflake Tor feature to fight censorship, and in May, the browser received an anti-tracking feature called “Forgetful Browsing” to prevent websites from tracking users.

Brave is one of our top-rated private browsers. Read our article on the best browsers for privacy to learn about the benefits of using a private browser and discover alternatives to Brave.

Leave a comment