Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

1–10 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#3
The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.)

What's left for the people who aren't criminals but don't like being spied on? PGP and keys that are exchanged physically, by hand?

If somebody can physically spy on the infrastructure cables that your traffic goes through, will SSL protect you? As written in the article -- no it will not, because the certificate can be obtained, even if it takes some time and strong-arm effort to do so. But when a country can order you to give up private keys and keep quiet about it, really, what can you do?

At this point, full decentralization, mesh networking and something times better than Tor encoded in 100% of the network code seems to be the only way out. Maybe a combination of IPFS and FreeNet, full packet-level encryption and keys that expire in 1 minute and are auto-generated for every transaction?

Re: Duck Duck Go: Illusion of Privacy (2013)

#5
Most of the points is arguing that NSA could compel the company Duck Duck Go, Inc to install equipment and then forbidding the company from disclosing that fact.

Doing so does carry quite a bit of political risk. There have been quite a few lawsuits from EFF and ACLU in regard to do so, and as the comment from CEO of Duck Duck Go says in the comment thread, all existing cases has been about turning over records. Going the extra step of compelling people to install hardware and keeping the operation going would be a further step.

I doubt ddg is currently worth the political risk. There is likely much easier targets to attack first in order to get 100% of the worlds search data.

*down votes? Explanation?

Re: Duck Duck Go: Illusion of Privacy (2013)

#6
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capable of using that solution because they do not have the resources, education or capability.

Re: Duck Duck Go: Illusion of Privacy (2013)

#7
Recently I have been using the free and open source Searx more and more (admittedly mostly using the !searx shortcut from DDG). Results seem better than DDG sometimes. Would be interesting to try and host my own instance or write something that picks a random public instance.

https://asciimoo.github.io/searx/

Re: Duck Duck Go: Illusion of Privacy (2013)

#8
I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can.

If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement about our times, not about any particular company.

The solution ought to be browbeating the US Government for unethical practices, not browbeating a company that does privacy better than most, and not as well as would be necessary to stand toe-to-toe with some of the most powerful and far reaching organizations in the world.

Re: Duck Duck Go: Illusion of Privacy (2013)

#9
post #5

Most of the points is arguing that NSA could compel the company Duck Duck Go, Inc to install equipment and then forbidding the company from disclosing that fact. Doing so does carry quite a bit of political risk. There have been quite a few lawsuits from EFF and ACLU in regard to do so, and as the comment from CEO of Duck Duck Go says in the comment thread, all existing cases has been about turning over records. Goin…

With DDG's focus on privacy, I wonder why they never had any warrant canaries setup?

Re: Duck Duck Go: Illusion of Privacy (2013)

#10
post #7

Recently I have been using the free and open source Searx more and more (admittedly mostly using the !searx shortcut from DDG). Results seem better than DDG sometimes. Would be interesting to try and host my own instance or write something that picks a random public instance. https://asciimoo.github.io/searx/

Wow, very cool project! Thanks for sharing.
Post reply on HN