Brave Browser 1.94 Introduces Disposable Email Aliases for Privacy

Brave browser version 1.94 introduces a new Email Aliases feature that lets users generate disposable email addresses when signing up for online services. The aliases keep a user's real email address hidden from websites while still forwarding messages from those services. Brave already blocks cookie- and cache-based identity tracking, but email addresses stored on website servers have remained a privacy gap, and this feature closes that hole.

Aliases help reduce spam and protect users from phishing attacks that often follow data breaches. When a website is hacked, leaked email addresses can circulate to data brokers and appear in phishing campaigns for years afterward. To use the feature, users need a free Brave Account with their primary email registered for forwarding. Brave secures these accounts using OPAQUE, a password-authenticated key exchange standardized as RFC 9807, which keeps passwords off Brave's servers and reduces exposure to logging, memory-scraping, and password database cracking.

The feature is free for up to five aliases, with a paid Premium version planned later that removes the limit. Brave stores primary addresses and aliases in encrypted form, and forwarded messages are only scanned by automated spam and malware filtering before being deleted from servers within seconds of delivery. Alias notes stay local or sync end-to-end encrypted through Brave Sync. Brave warns that forwarded messages may initially land in spam folders while the service builds its sender reputation.

Read More at the original source →