Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

31–40 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#31
post #11
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

If one's threat model includes state actors that target that person then all regular methods are useless. The best we can do is to protect against passive attacks and that's where PGP, double ratchet schemes, Tor etc come in handy.

True enough, sadly. Still doesn't mean we shouldn't push back with the means we have in our hands. Open-source firmwares might be a VERY good first step in that direction (one of the reasons I am replacing my ASUS router with Mikrotik; another being that ASUS routers are laggy pieces of crap, even those that cost north of $200).

Also, we all know about Intel ME, right? It's baffling how most people using PCs have hardware-level backdoor and the world hasn't lost its shit. It's a very sad epoch we live in. :(

A solution right now is to simply not get on the state adversaries' bad side, maybe. And utilize the blockchain for anonymity, I guess.

Re: Duck Duck Go: Illusion of Privacy (2013)

#33
post #16

Earlier quoted context omitted.

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capabl…

Solving the problem with technology is 1000000 times easier than solving it from the "social" side.

Sure, if you're a fairly affluent and educated hacker news reader. But there are far more people who I routinely work with who struggle with the concept of a password but need to use the internet to apply for work, register for disability, social security, communicate with family, etc. Do those people deserve less privacy?

Re: Duck Duck Go: Illusion of Privacy (2013)

#34
post #5

Most of the points is arguing that NSA could compel the company Duck Duck Go, Inc to install equipment and then forbidding the company from disclosing that fact. Doing so does carry quite a bit of political risk. There have been quite a few lawsuits from EFF and ACLU in regard to do so, and as the comment from CEO of Duck Duck Go says in the comment thread, all existing cases has been about turning over records. Goin…

I'm not sure if they really need to compel DDG in the first place. I know if I was a three letter agency, I'd start a "secure" service like DDG myself as kind of a honeypot. Not that I'm saying that such an agency is actually behind DDG -- I have no way of knowing. But I would be very surprised if a large number of services promising "security" and "privacy" weren't run by such agencies or their agents. That's why I…

While that is always possible, I think its more plausible that they then simply buy out key companies rather than found a bunch of new companies in hope that one will succeed. The question then is, what is the likelihood that NSA is the secret owner and operator of Microsoft, Apple or Yahoo, which each would likely be the cost effective choice if one wanted access to all search queries done on the Internet.

Independent third-party auditing is useful. There is the occasional fund raising for auditing of software (Truecrypt comes in mind), but I don't recall hearing one about search engines.

Re: Duck Duck Go: Illusion of Privacy (2013)

#35

Earlier quoted context omitted.

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capabl…

I agree. The biggest problem in this age is having a strong encryption that is user-friendly. The common wisdom says it's impossible to combine the two. I disagree with it but I don't have the time to try and work in the area, nor am I an expert. IMO it's a good cause to work on anyhow. Furthermore, spies aren't stopped by social stigma. Even if the whole planet agrees in one voice wiretapping shouldn't be done (neve…

> strong encryption that is user-friendly

Not enough, in my opinion. Where most people will fail is on the opsec side. They just don't understand security best practices. I realize that not all problems can be solved, but technology is not just encryption, it's understanding how the technology works so you can avoid leaking information in the hundreds of other ways that are possible on the Internet.

Re: Duck Duck Go: Illusion of Privacy (2013)

#36
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

There are two levels at play here: who is saying what and who is talking to who. The second one is extremely hard to protect against and already plenty useful on its own.

Re: Duck Duck Go: Illusion of Privacy (2013)

#37
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

From previous discussions I've learned that USA companies are the only ones that actually are protected from the USA government. So feel free to build a company in Sweden, but the US is actually legally permitted to wiretap the crap out of it.

Except that's not how it works. They will take everything including those USA companies' data and then they will go to a judge to ask for a warrant to make interception after the fact legal. It's US citizens that are exempt and their data is only looked at in exceptional cases but on the whole you should not assume the data is not recorded. The legal fiction used to protect this abuse of your rights is that they claim that as long as nobody looks at it your data wasn't really collected.

Re: Duck Duck Go: Illusion of Privacy (2013)

#38

If you're worried that DDG may log your IP you can simply use it with the Tor Browser (it's the default search engine) or use their onion service ( https://3g2upl4pq6kufc4m.onion/ ) for increased security and anonymity.

Tor is far from perfect and there are several ways in which one could connect traffic at some endpoint with a user at a specific IP. Do not rely on Tor if you really want anonymity.

Re: Duck Duck Go: Illusion of Privacy (2013)

#39
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

If I were a conspiracy theorist, I'd think there was something nefarious going on when I see articles like this. What if the intended result is not actually browbeating DDG but, rather, making people think that DDG is no better than Google in the privacy arena so why invest the energy in switching?

If DDG isn't any better than maybe nobody is, so we might as well get used to the lack of privacy. Why switch if you're just going to get worse results, expend more energy, and not actually get increased privacy? You might just as well give up the struggle...

Fortunately, I'm not a conspiracy theorist,

Re: Duck Duck Go: Illusion of Privacy (2013)

#40
post #16

Earlier quoted context omitted.

Solving the problem with technology is 1000000 times easier than solving it from the "social" side.

Is it? For who? Do you think people's data would be more secure at the border if - You kernal-hacked iOS so that it booted into a vanilla account upon entry of a certain passcode, and encouraged people to install your hack from GitHub, potentially borking their phones - People couldn't be compelled (or face being denied entry) to allow search of their electronic devices ? What about trying to do everything via a VPN…

Is it? For who?

For HN readers. And probably in general.

As for your questions, I would definitely like to first use software which doesn't compromise my privacy and security and only as a very distant second have some bureaucrat who would maybe in the best case scenario fine a company which leaks my data.

The vote I cast by running a Tor relay is much more meaningful and valuable defence of privacy than a vote in the general elections. By orders of magnitude.

Post reply on HN