

I gave you the real reason it should be controversial. Brave’s fuck ups have not been significantly worse than other companies’.
re: open source In theory: yes. In practice: maybe. It’ll probably eventually be caught by some researcher but unlike popular belief all open source code bases are not constantly being audited by the community. A random person can’t just read Brave source code for all platforms and accurately gauge if they’re doing something nefarious. It is very easy to hide stuff in code or misuse a protocol for evil purposes, etc.
You can modify the source code but as evident by the fact that there’s no Brave fork with crypto removed (there was one but their branding was too similar to Brave’s so they got sued), it’s not an easy feat to maintain that.
Browsers (except for Tor) doing this in the name of privacy is so dumb. Our timezones are already apparent due to our IP addresses. Not only does this not hide the timezone but also makes the user more fingerprintable. Now I’m the dumbass from Ohio who’s browser reports UTC timezone for some reason.