Cyber Security News

Brave Unveils New Email Aliases to Keep Your Personal Email Address Private

Brave has introduced a new Email Aliases feature in desktop browser version 1.94, allowing users to sign up for websites without sharing their real email address.

The privacy-focused feature generates unique forwarding addresses that deliver messages to a user’s primary inbox while keeping that primary address hidden from online services.

The release is the 39th entry in Brave’s ongoing privacy-update series. It was developed by Brave engineers Pavel Beloborodov, Tarik Demirović, Harold Spencer Jr., and DesignOps Lead Agustín Ruiz, with contributions from former Brave privacy engineer Arthur Edelstein.

Email addresses have become valuable identifiers for advertisers, websites, and data brokers. Unlike browser cookies, an email address can follow a person across devices, browsers, and online services.

Companies can use customer email lists to match users with profiles held by advertising platforms, including Google, Meta, and LinkedIn.

Brave Unveils New Email Aliases

For example, a customer may provide an email address while purchasing running shoes from an online store. The store could then upload that address to an advertising platform’s server-side matching system.

create an email alias (Source: Brave )

If the platform already has the same email linked to a social-media account, it can associate the customer’s purchase with their advertising profile.

This type of data sharing can occur outside the browser, meaning traditional tracker blocking may not stop it. Brave said Email Aliases are designed to reduce this exposure by giving each website a separate address rather than the user’s permanent email identity.

Users can create an alias directly inside an email field on a website. The generated address forwards incoming messages to the email linked with the user’s Brave Account.

If an alias begins receiving spam or is connected to a service the user no longer uses, it can be deactivated and replaced with a new address.

Click any email field to create an alias, or right-click and select “New Email Alias” (Source: Brave )

The feature is managed through Settings > Autofill & Passwords > Email Aliases, or through the internal browser page brave://settings/email-aliases.

Users must first create a Brave Account using an email address and password, which is separate from a Brave Premium subscription account.

Brave said its account system uses OPAQUE, a password-authenticated key exchange protocol standardized in RFC 9807. The protocol is intended to ensure that a user’s password is not sent directly to Brave’s servers during authentication.

According to Brave, it stores the primary account address and generated aliases encrypted at rest. The company said it does not read email content, but processes incoming mail for spam and malware filtering before forwarding it. Messages are deleted from Brave’s servers within seconds after delivery.

Alias notes are stored locally on the user’s device. When Brave Sync is enabled, those notes are encrypted end-to-end between devices in the same Sync chain.

Brave is initially offering five free email aliases per user. The company said it plans to expand the capability to mobile devices and introduce a Premium version later. It also warned that some forwarded messages may initially reach spam folders while the service establishes its email-sending reputation.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago