The images in this article were generated with artificial intelligence. How we publish
Brave has officially launched Brave Origin, a payment version of your browser that promises a "minimalist" experience by eliminating monetizing-oriented functions: rewards for seeing ads, cryptomoneda portfolio, VPN promotions, Leo AI integration, news, Brave Talk calls, sponsored images and other promotional components that are default-activated in the standard edition. The company details the product in its own release, where it positions it as an option for those looking for a cleaner browser without giving up the privacy protections that Brave offers, as Brave Shields(tracker and ad blocking).
The chosen commercial model is striking: a unique payment license of USD 59.99 that can be activated on up to 10 devices, while the Linux version is offered free of charge. This scheme raises two opposite readings: on the one hand, for users who value simplicity and prefer to pay to get it without touching configurations, Origin can be attractive; on the other hand, many users have criticized the decision because they perceive that Brave is collecting to remove characteristics that could previously be considered unnecessary, making the application itself a new layer of monetization.

From the point of view of security and privacy, reduce integrated functions can reduce the attack surface. Components such as cryptomoneda coins or integrated AI modules expand the complexity of the code and therefore potential vulnerability vectors. However, the relationship between "less functions" and "more security" is not automatic: it matters how the withdrawals are implemented, how the product is updated and if the shared units remain present. Brave maintains Shields, which retains the defense against trackers and many forms of follow-up, but it is appropriate to regularly verify that security updates are transparent and effective.
One practical question is that much of what Origin disables can already be deactivated in the free version through adjustments or business policies. Brave documents administrative and group policy options for organizations that want to disable default functions; for administrators this means that it is not strictly necessary to buy Origin to obtain a "clean" profile in corporate deployments. For individual users with technical knowledge, there is also the option to manually disable many functions, although that requires time to be invested and to understand the implications of each adjustment.
The public debate that has emerged around the launch reflects a broader conflict in free software and browsers: should the experience "by default" prioritize monetization or privacy? Some project advocates argue that the existence of a payment version makes it easier for non-technical users to obtain a private and non-extras experience, in addition to financially supporting the computer behind the browser. Others argue that this normalizes the collection by removing the unwanted and that companies should offer a cleaner configuration by default.
If you are considering whether to pay for Brave Origin or stay in the free version, you should follow a risk-based and practical approach: first, define your threat model- what assets you must protect and what types of monitoring or attacks concern you -; second, check if you can achieve that level of privacy by deactivating functions in the free version (and consult the official documentation for advanced policies); third, if you value simplicity and want to avoid manual configuration, compare the cost with other private alternatives and the possibility of directly supporting the development of the project.
For those who manage devices in business environments or want a centralized configuration, Brave offers group policies that allow you to automate the deactivation of many of the business functions, which can eliminate the need to buy a license just to get a controlled corporate configuration. Brave's policy documentation is publicly available and is a good starting point for IT teams that need to deploy multi-team configurations.

In practical terms of safety, if you choose Brave Origin or the free version with settings, do not forget to check the source of the facilities and updates. Confirm the signature of the binaries when possible, use official download channels and preferably manage updates through your system's package manager if you are in Linux. Remember also to audit extensions and supplements: many privacy leaks come from poorly configured or malicious extensions, so less extensions and only from reliable sources It's a simple and effective rule.
The Origin launch also invites a wider reflection on sustainability and business models in privacy software. Paying for software that eliminates ads and promotions can be valid as a form of direct funding, but projects must clearly communicate what the licenses benefit, how data are managed and how product and technical independence is guaranteed against commercial incentives. Those who want to deepen Brave's official proposal can read the ad on their blog, and those who manage deployments will find useful in the group policy guide.
Useful links: Official announcement of Brave Origin: https: / / brave.com / blog / brave-origin /, and Brave's business policy documentation: https: / / support.brave.app / hc / en-us / articles / 360039248271-Group-Policy. To download the standard version or check official channels: https: / / brave.com / download /.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...