PRIVACY REPORT:

Why DFA Uses Brave Talk

DFA hosts Digital Freedom Awareness Talks using the Brave Talk video conferencing platform. It works directly in any modern web browser, allowing you to join instantly via a link without downloading an application or creating an account.

This article explain what Brave Talk is and what that means for your privacy.

What Brave Talk is (in plain terms)

Brave Talk is a Brave-branded service that is effectively powered by 8×8 infrastructure (Brave is acting as a reseller/front-end).

That has two consequences:

  • Any privacy and risk assessment must focus primarily on 8×8’s platform, infrastructure, and legal jurisdiction, because that’s where the “heavy lifting” of real-time communications happens (voice/video routing, meeting operations, etc.).
  • Brave may add a small privacy buffer at the account/billing/identity layer (for example, you are engaging with Brave’s product surface rather than directly signing up with 8×8), but it does not create a hard privacy firewall.

PRIVACY CONCERNS:

We do not consider Brave Talk a “high privacy” platform.

Our position on Brave Talk

We use it because it fits our practical needs for open community calls, while being a little better than other available alternatives on friction and identity pressure.

Our main concerns

Our threat model treats the following as meaningful risks:

  • Big Tech infrastructure dependence (cloud and network layers are rarely “privacy clean” in a paranoid model).
  • Public-company incentives and institutional ownership (8×8 is a public company, meaning shareholder incentives apply; large institutional holders—e.g., BlackRock/Vanguard-style funds—are common across public equities).
  • Provider visibility into metadata and media: unless a service is explicitly architected as true end-to-end encrypted with client-side keys, assume the provider can technically access high-value metadata and may have the technical capability to access media under certain conditions.

Bottom line concern: Brave Talk does little to mitigate the core platform risk, because the core platform here is 8×8.

Why DFA uses Brave Talk anyway

We use Brave Talk primarily because it supports how community participation works in practice:

1) Easy to join (low friction)

Participants can typically join with a link without needing to create a new account. That matters because reducing account creation reduces:

  • identity pressure,
  • platform lock-in,
  • and barriers for first-time participants.

2) A pragmatic improvement vs many mainstream options

We’re not claiming Brave Talk is “private.” But for low-identity participation, it can be a better fit than platforms that strongly push persistent accounts and ecosystem IDs.

3) Transcriptions

We use Brave Talk because it supports transcriptions, which improves accessibility and follow-up utility for the community.

4) Recordings

We use Brave Talk because it supports recordings (and related workflows such as review and recap).
Note: Recording and transcription inherently increase the sensitivity and retention footprint of any meeting—so we treat these features as a tradeoff, not a pure win.

Our High Privacy Video Conferencing Server

DFA also operates a privately hosted Jitsi server for internal and sensitive video conferencing. This gives us more control over the stack.

However, in our current setup it has practical limitations for public talks:

  • It requires accounts (higher friction, higher identity pressure).
  • It currently does not provide transcription and recording capabilities we need for these events.

So we currently split the difference:

  • Self-hosted Jitsi for scenarios where control matters most and the workflow fits.
  • Brave Talk (8×8-powered) for open, accessible talks where link-based joining + transcription/recording are important.

WHAT IT MEANS FOR YOU:

What this means for you as a participant

For most people (the “99%” case), joining a DFA call on Brave Talk is likely more private than much of what you already do online day-to-day, simply because it can reduce identity friction and avoids some of the worst consumer-surveillance patterns.

If your threat model is high paranoia / high stakes, then treat Brave Talk like any centralised commercial comms service:

  • assume provider-layer metadata visibility,
  • assume jurisdictional exposure,
  • assume that voice/video content is not cryptographically sovereign.

Participant Choice: Privacy Mitigation Strategies

You can actively manage your level of exposure on the platform. We suggest the following technical and behavioural layers to minimise your data footprint:

  • Utilise Your Own Privacy Stack: Do not connect to the call via a “naked” connection. Use your own established privacy stack—such as a VPN or a hardened browser profile—to obfuscate your real IP address and device fingerprints from 8×8’s infrastructure.
  • Voice Masking & Modification: If you need to speak but want to avoid biometric voice-printing, use voice modulation software to alter your pitch and tone before the audio reaches the browser. This adds a layer of protection against automated voice recognition and transcription profiling.
  • Video Obfuscation & Virtual Cams: If you must be on camera, use a virtual camera (like OBS) to apply filters, heavy blurring, or even an avatar. This allows you to participate visually without handing over a high-resolution biometric map of your face or your private surroundings.
  • Selective Sharing: You can share information or present data via Screen Sharing without ever enabling your camera. This allows you to contribute to the talk while keeping your physical identity and environment completely off the platform’s media servers.
  • Minimise Media Streams: If you are joining primarily to listen, keep your camera and microphone disabled. Voice and video data are the most sensitive assets processed by 8×8; keeping them off removes those data streams from their servers entirely.
  • Ephemeral Identity: Use a minimal, meeting-specific display name. Avoid handles or names linked to your other social identities. Since Brave Talk allows guest access, you can remain “low-identity” throughout the session.
  • Assume “Hot” Infrastructure: Operate under the assumption that the platform is not cryptographically sovereign. Do not share sensitive documents, passwords, or highly confidential information via the in-meeting chat or screen-share functions.

We will continue to refine our tooling and will remain transparent about the trade-offs involved when we utilise convenience features like transcription and recording.