Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

121–128 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#121

Earlier quoted context omitted.

> Snowden Snowden, a man who worked from home in Hawaii as an NSA contractor making over $200k a year with his smoking hot girlfriend, who suddenly decided he had a moral compass, was able to download tons of classified files over VPN to his laptops and run off to meet Greenwald et. al. to divulge all this information, then flee to Russia where he sends out anti-Russian tweets. Meanwhile, nothing has happened. The NS…

What does Snowden's girlfriend have anything to do with... well, anything?

I'm not sure what the poster was getting at - are security contractors with smoking hot girlfriends making 200k a year less credible such that we should explore conspiracy theories?

If so, poor security contractors (and their apparently less appealing girlfriends) with our cynical assumptions.

Re: Duck Duck Go: Illusion of Privacy (2013)

#122

Earlier quoted context omitted.

> The only conclusion I can make from this article is to avoid services hosted in the USA The thing is, there are absolutely no guarantees it's any better in other countries : the fact that NSA activities were revealed doesn't mean other countries don't do as bad. It's probably still a good idea to segments services across countries, though, so that it's not a single country who have access to all data. I was thinkin…

I have asked myself the same. I see two-fold answer: (1) Business who are familiar with web tech and for them it's simply good business to not invest in entirely new (for the dev teams in there) stacks and data formats. (2) Political pressure -- we know that NSA successfully pushed a broken crypto once in the past, so it's not a stretch to theorize that influential people were whispering in the right ears at the righ…

Indeed, especially #1. There's a thing with the web : it's easy. If we start making more native apps, especially desktop apps, we then have to consider users' environment (we do not control the execution environment, like with a server), we have to implement error reporting, manage the propagation of updates, etc. Centralizing data is easier too : no need to manage data synchronization, it's just about putting everything in the same database.

It seems like we'll have to wait for users to complain more about privacy issues before the effort is worth it, from a business point of view.

The alternative, of course, being to find a way to make native apps as easy. Nothing prevent us to make updates automatically apply (many apps do that, actually). Applications can run in some sort of VM/container so environment is controlled. And regarding distributed databases, we already have a good idea of what it could look like with blockchains, even if it would obviously be way better to build something with databases in mind from the start. For example, servers could be used for people to register to a service and be added to groups. Then, clients contact servers to get a list of peers, and then they sync their group database by executing transactions (somehow like migrations).

Re: Duck Duck Go: Illusion of Privacy (2013)

#123
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are…

As others have kinda pointed out: it's the amount of data they store.

I think it is less about who you should trust to do the right thing and more of how much you trust an individual group to be able and willing to maintain the security of the data they have.

That is to say: it is more about the ratio of / rather than either of those values.

Google stores more data than I personally trust anybody to be able to store. Largely because they make themselves a huge target.

Equifax is a great example of storing WAY too much data. Sure, their practices are to blame, but I'd argue that them storing half the information they do is better than doubling their security (whatever that means). This is due to the compounding effect of being a smaller target.

DDG at least claims to not store as much of that information.

> When was the last time Google leaked your data.

If Google has one major leak, does the historical quantity of leaks matter?

EDIT: more thoughts.

Re: Duck Duck Go: Illusion of Privacy (2013)

#124

Earlier quoted context omitted.

That's a good question. My reply would be I'm not sure the intelligence community / legal profession can collect and hoard such things without legal approval. Certainly Equifax has other data. Maybe they didn't get what they wanted? Maybe Equifax isn't being transparent? Maybe they don't know?

That's a lot of maybes to support an already unlikely scenario.

Unlikely? Because in the history of the NSA or CIA there has never been an "No way??!! They did what???"

What do you think the NSA is doing with all that computing (and storage) power? Processing cat photos? :)

Re: Duck Duck Go: Illusion of Privacy (2013)

#125

Earlier quoted context omitted.

You're missing the point. That is it's possible, if not probable (per books like Dragnet Nation, Snowden, etc.) that data is being collected and you have no idea why, who, etc. I'm not saying i think that's what happened. I'm saying there's a part of me that has good reason it it's possible it could be that. Crazy? Not more than some of things we know the intelligence community has done or tried to do.

I'm not missing the point. I'm not saying it isn't happening because it's some crazy Tom Clancy plot. I'm saying the intelligence agencies have better ways of getting that data without also giving it to a ton of other bad actors

You should read Dragnet Nation. I'm not talking about bad actors. I'm talking about legit data collection and resale outfits.

We're being tracked. One click/visit at a time.

Re: Duck Duck Go: Illusion of Privacy (2013)

#126
post #71

I wrote my own search engine and using it. Not very difficult.

Is it a proxy to other search engines or do you search your own database of websites?

Sorry for the delay in my reply.

I search from my own 1GB database; It covers 80% of my needs;

Re: Duck Duck Go: Illusion of Privacy (2013)

#127
post #126

Earlier quoted context omitted.

Is it a proxy to other search engines or do you search your own database of websites?

Sorry for the delay in my reply. I search from my own 1GB database; It covers 80% of my needs;

Interesting. Thanks for your reply.

Re: Duck Duck Go: Illusion of Privacy (2013)

#128

Earlier quoted context omitted.

> Snowden Snowden, a man who worked from home in Hawaii as an NSA contractor making over $200k a year with his smoking hot girlfriend, who suddenly decided he had a moral compass, was able to download tons of classified files over VPN to his laptops and run off to meet Greenwald et. al. to divulge all this information, then flee to Russia where he sends out anti-Russian tweets. Meanwhile, nothing has happened. The NS…

What does Snowden's girlfriend have anything to do with... well, anything?

Probably just salty that Snowden gets to have a hot girlfriend and also be a hero.
Post reply on HN