TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Duck Duck Go: Illusion of Privacy (2013)

248 pointsby awaisraadover 7 years ago

19 comments

sfRattanover 7 years ago
I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can&#x27;t protect you from the NSA. Extremely few actors can.<p>If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That&#x27;s a statement about our times, not about any particular company.<p>The solution ought to be browbeating the US Government for unethical practices, not browbeating a company that does privacy better than most, and not as well as would be necessary to stand toe-to-toe with some of the most powerful and far reaching organizations in the world.
评论 #15321593 未加载
评论 #15322171 未加载
评论 #15322858 未加载
评论 #15321629 未加载
评论 #15327355 未加载
评论 #15322678 未加载
apattersover 7 years ago
My beef with this article is that it&#x27;s unreasonably reductionist to conclude that DDG provides an &quot;illusion&quot; of privacy based on the fact that they&#x27;re as vulnerable to being targeted by the NSA as anyone else. The issue of privacy is so much bigger than that.<p>If you use Google Search and someone obtains access to the data they have on you, legally or illegally, they could end up obtaining many years of your browsing history. If you use DDG they have nothing, and the most they can do (as the article states) is start collecting your search habits from that point onward.<p>I don&#x27;t want huge companies to amass giant archives of data about me. There are so many ways it can be abused by a multitude of actors. It&#x27;s a selling point to me when a service retains little or no information, and if it needs to retain something, it requests limited permission in clear and simple terms.
pdimitarover 7 years ago
The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company&#x27;s servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn&#x27;t a honey pot propaganda operation to lure people to host stuff in Iceland, of course.)<p>What&#x27;s left for the people who aren&#x27;t criminals but don&#x27;t like being spied on? PGP and keys that are exchanged physically, by hand?<p>If somebody can physically spy on the infrastructure cables that your traffic goes through, will SSL protect you? As written in the article -- no it will not, because the certificate can be obtained, even if it takes some time and strong-arm effort to do so. But when a country can order you to give up private keys and keep quiet about it, really, what can you do?<p>At this point, full decentralization, mesh networking and something times better than Tor encoded in 100% of the network code seems to be the only way out. Maybe a combination of IPFS and FreeNet, full packet-level encryption and keys that expire in 1 minute and are auto-generated for every transaction?
评论 #15321372 未加载
评论 #15321536 未加载
评论 #15321597 未加载
评论 #15324407 未加载
评论 #15321872 未加载
评论 #15322152 未加载
kasbahover 7 years ago
Recently I have been using the free and open source Searx more and more (admittedly mostly using the !searx shortcut from DDG). Results seem better than DDG sometimes. Would be interesting to try and host my own instance or write something that picks a random public instance.<p><a href="https:&#x2F;&#x2F;asciimoo.github.io&#x2F;searx&#x2F;" rel="nofollow">https:&#x2F;&#x2F;asciimoo.github.io&#x2F;searx&#x2F;</a>
评论 #15322201 未加载
评论 #15321512 未加载
评论 #15321667 未加载
alsadiover 7 years ago
To be fair here is ceo response quote<p>Hi, this is Gabriel Weinberg, CEO and founder of DuckDuckGo. I do not believe we can be compelled to store or siphon off user data to the NSA or anyone else. All the existing US laws are about turning over existing business records and not about compelling you change your business practices. In our case such an order would further force us to lie to consumers, which would put us in trouble with the FTC and irreparably hurt our business.<p>We have not received any request like this, and do not expect to. We have spoken with many lawyers particularly skilled and experienced in this part of US and international law. If we were to receive such a request we believe as do these others it would be highly unconstitutional on many independent grounds, and there is plenty of legal precedent there. With CALEA in particular, search engines are exempt.<p>There are many additional legal and technical inaccuracies in this article and I will not address all of them in this comment. All our front-end servers are hosted on Amazon not Verizon, for example.
评论 #15325625 未加载
feelin_googleyover 7 years ago
Like Google, by default DDG tracks what results the user clicks on. URLs are prefixed with a DDG URL. Users HTTP requests are forwarded through DDG servers.<p>By default, DDG &quot;lite&quot; does not set cookies or use Javascript. However, if the user wants to change the default &quot;settings&quot; (HTTP has no state so this is a fiction), then AFAICT she has to enable Javascript and accept cookies. Privacy conscious users do not want Javascript or cookies.<p>DDG could achieve the same result by simply providing an alternate URL, something like &#x2F;lite2 in addition to &#x2F;lite.<p>Whether DDG saves this data I have no idea. But one has to wonder why, if privacy is a goal, DDG is collecting it to begin with.<p>If DDG believes it is doing this for the benefit of users, it is not convincing because there are alternative ways to achieve the same benefit that do not require prefixing URLs, Javascript or use of cookies.<p>For example, browser settings already allow the user to control HTTP Referer headers, assuming queries were submitted using GET. The user can change the settings in the browser so that no referer is sent, or to send a custom referer of her choosing.<p>Another example is if DDG accepted queries via POST method in addition to GET. No search terms would be leaked in the URL or in any HTTP referer.
评论 #15323600 未加载
评论 #15323477 未加载
belornover 7 years ago
Most of the points is arguing that NSA could compel the company Duck Duck Go, Inc to install equipment and then forbidding the company from disclosing that fact.<p>Doing so does carry quite a bit of political risk. There have been quite a few lawsuits from EFF and ACLU in regard to do so, and as the comment from CEO of Duck Duck Go says in the comment thread, all existing cases has been about turning over records. Going the extra step of compelling people to install hardware and keeping the operation going would be a further step.<p>I doubt ddg is currently worth the political risk. There is likely much easier targets to attack first in order to get 100% of the worlds search data.<p>*down votes? Explanation?
评论 #15321538 未加载
评论 #15321478 未加载
评论 #15322263 未加载
mighty_banderover 7 years ago
Recently I had a series of unfortunate plumbing mishaps at my home that set me back a bunch of money. I did very minimal google searching (just confirming the spelling of the plumber&#x27;s name), but ads offering emergency home loans have started popping up in my browser.<p>If I can go to a search engine that doesn&#x27;t sell the fact of possible financial problems to whatever loan shark is willing to pay the most to get to me, I see that as a win.
runningmikeover 7 years ago
Privacy requires full transparency. We&#x27;re is documented with what foss software ddg works and where can I find trusted audit reports?
评论 #15321591 未加载
评论 #15321356 未加载
bad_userover 7 years ago
Duck Duck Go is a company that I want to succeed, as they are clearly making a stand on user privacy.<p>However it never made sense to me why people would use those DDG bangs.<p>I mean privacy is the main selling point, so why in the world would you send the searches you make on other websites to DDG, when the browser is perfectly capable of being configured for &quot;<i>search keywords</i>&quot;.<p>In Firefox, go to amazon.com (or any website you want), right click on their search bar and select &quot;<i>Add a Keyword for this search...</i>&quot;. Add &quot;<i>!a</i>&quot; or whatever you want. There, you&#x27;ve got your own bangs.
评论 #15324681 未加载
jerheinzeover 7 years ago
If you&#x27;re worried that DDG may log your IP you can simply use it with the Tor Browser (it&#x27;s the default search engine) or use their onion service (<a href="https:&#x2F;&#x2F;3g2upl4pq6kufc4m.onion&#x2F;" rel="nofollow">https:&#x2F;&#x2F;3g2upl4pq6kufc4m.onion&#x2F;</a>) for increased security and anonymity.
评论 #15322167 未加载
评论 #15322667 未加载
indefenseofddg1over 7 years ago
The issues brought up in this post apply to every single service operating online, and it only applies to DuckDuckGo in any special way because of their increasing size. This includes &quot;client&quot; encrypted webmail and similar applications: they can be forced to deliver malicious JS that gives up your keys, or the JS client delivery can be MitM&#x27;ed.<p>Many people seeking enhanced privacy from DuckDuckGo are seeking privacy <i>from Google</i>, not from state actors. For that, you&#x27;d need additional measures like Tor, for which DuckDuckGo provides a convenient .onion service. Even if DDG is secretly tracking all our searches, they have less data to correlate it with.<p>My current privacy complaint on DuckDuckGo, combined with browser search UI issues (looking at you, Chrome) is over the !bangs. If you&#x27;re doing &quot;!w [sensitive topic]&quot; instead of tabbing to Wikipedia search in your browser and searching that way, you&#x27;re risking DDG or anyone who&#x27;s compromised DDG seeing your Wikipedia searches, when the search should go straight to Wikipedia, Twitter, Stack Overflow, and so on.
评论 #15323336 未加载
patkaiover 7 years ago
I use Duckduckgo because I don&#x27;t like monocultures.
评论 #15324062 未加载
fghtrover 7 years ago
I am participating in a peer-to-peer search engine based on free software, <a href="http:&#x2F;&#x2F;yacy.net" rel="nofollow">http:&#x2F;&#x2F;yacy.net</a>. But I am not sure it can save us from NSA... We have to take political steps against them anyway.
cyphunkover 7 years ago
comparison of using DDG vs Google over tor is enlightening (GIF):<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;cyphunk&#x2F;status&#x2F;849615910545620992" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;cyphunk&#x2F;status&#x2F;849615910545620992</a>
评论 #15324705 未加载
Sidiousover 7 years ago
Collecting meta-data is not benign at all, it&#x27;s trivial for the usual suspects to de-anonymise, and profile based on browsing habits.<p>Fat protocols should marshal the true web 2.0 along with DAOs.
bitmapbrotherover 7 years ago
So does DDG produce a transparency report and if not then why not?
_qbxpover 7 years ago
This is something that&#x27;s always been fascinating to me. In any thread about privacy, there&#x27;s always a comment along the lines of &quot;if your threat model is a nation-state, then you&#x27;re screwed.&quot; You hear it about DDG, Tor, client-side but web-delivered encrypted email, etc.<p>What if your threat model is a nation state? What&#x27;s the proper way to ensure your privacy <i>that does not require abstaining from the internet</i>? Is a high degree of privacy even possible?
评论 #15324364 未加载
knownover 7 years ago
I wrote my own search engine and using it. Not very difficult.
评论 #15324098 未加载