Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

11–20 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#11
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

If one's threat model includes state actors that target that person then all regular methods are useless. The best we can do is to protect against passive attacks and that's where PGP, double ratchet schemes, Tor etc come in handy.

Re: Duck Duck Go: Illusion of Privacy (2013)

#12
post #5

Most of the points is arguing that NSA could compel the company Duck Duck Go, Inc to install equipment and then forbidding the company from disclosing that fact. Doing so does carry quite a bit of political risk. There have been quite a few lawsuits from EFF and ACLU in regard to do so, and as the comment from CEO of Duck Duck Go says in the comment thread, all existing cases has been about turning over records. Goin…

I'm not sure if they really need to compel DDG in the first place.

I know if I was a three letter agency, I'd start a "secure" service like DDG myself as kind of a honeypot.

Not that I'm saying that such an agency is actually behind DDG -- I have no way of knowing. But I would be very surprised if a large number of services promising "security" and "privacy" weren't run by such agencies or their agents.

That's why I believe that frequent, independent third-party auditing (by multiple trusted groups like the EFF) would be necessary to gain any kind of confidence in such services. Even then, it'll be no guarantee that they're not compromised, but it would just make such compromise significantly more difficult and less likely to be effective.

Re: Duck Duck Go: Illusion of Privacy (2013)

#13

Privacy requires full transparency. We're is documented with what foss software ddg works and where can I find trusted audit reports?

Even if they were completely open source how would you verify that they are using the same software on their servers? That the hardware is not compromised?

Audit reports? How trustworthy are they if Symantec was able to provide good reports for such a long time for their certificate issuance when things were clearly not ok.

Re: Duck Duck Go: Illusion of Privacy (2013)

#14
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

The article was a response to a guardian article that ultimately cited https://siliconangle.com/blog/2013/06/14/duckduckgo-the-pris...

> “By not storing any useful information, DuckDuckGo simply isn’t useful to these surveillance programs,” says Weinberg. “We literally do not store personally identifiable user data, so if the NSA were to get a hold of all our data, it would not be useful to them since it is all truly anonymous.”

DDG is "unfairly singled out" for good reason, namely that company representatives made an incorrect assertion. DDG is still useful for ongoing surveillance, as the article pondered:

> But what if DuckDuckGo provided a splitter-feed to the NSA? DuckDuckGo can claim without lying that they store no personal information, but that speaks nothing of a collaborating partner storing it.

Re: Duck Duck Go: Illusion of Privacy (2013)

#15
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

Here's another solution, from the late Pieter Hintjens: https://www.indiegogo.com/projects/edgenet#/

Re: Duck Duck Go: Illusion of Privacy (2013)

#16
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capabl…

Solving the problem with technology is 1000000 times easier than solving it from the "social" side.

Re: Duck Duck Go: Illusion of Privacy (2013)

#17
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

Protection from the Nation State Actors cannot come from companies. One must implement protections on one's own client-side. Proper encryption always. Tor when needed. Software and, where possible, hardware only from trusted sources.

Re: Duck Duck Go: Illusion of Privacy (2013)

#18
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

The article was a response to a guardian article that ultimately cited https://siliconangle.com/blog/2013/06/14/duckduckgo-the-pris... > “By not storing any useful information, DuckDuckGo simply isn’t useful to these surveillance programs,” says Weinberg. “We literally do not store personally identifiable user data, so if the NSA were to get a hold of all our data, it would not be useful to them since it is all truly…

Not to get off topic but there's a part of me that suspect the Equifax hack has the NSA (or will ultimately filter back to them). When I read Dragnet Nation a couple years ago one of the things that left an impression on me was the fact that the gov can buy "private" personal data on the open market just like anyone else can. That is, it's not spying (and a violate of right / laws) if the data is on the free market.

Obviously, DDG isn't perfect. I'm not naive. But for me there's some value in trying not to succumb to Google's desire to have us all assimilate.

Re: Duck Duck Go: Illusion of Privacy (2013)

#19
post #7

Recently I have been using the free and open source Searx more and more (admittedly mostly using the !searx shortcut from DDG). Results seem better than DDG sometimes. Would be interesting to try and host my own instance or write something that picks a random public instance. https://asciimoo.github.io/searx/

i saw there's an Installation page but do you know of an easy step by step tutorial for setting this up? Perhaps with a low cost recommended host, etc.?

Re: Duck Duck Go: Illusion of Privacy (2013)

#20
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

Protection from the Nation State Actors cannot come from companies. One must implement protections on one's own client-side. Proper encryption always. Tor when needed. Software and, where possible, hardware only from trusted sources.

Even then the concept of "trusted sources" is a dubious one. A source only needs to be trusted until it sells you down the river.
Post reply on HN