Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

181–190 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#181
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

What a wussy excuse. This should have been a no-brainer decision: do we quietly compromise privacy so that our users can have little icons on their browser tabs? How absurd. Duckduckgo chose compliance with the inconsequential minutae of bigtech over its primary pain point. This is indicative of misalignment between stated values and the values demonstrated through actions. If you guys made this call, sacrificing pri…

[deleted]

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#182

Earlier quoted context omitted.

Seems a bit off-topic for the concrete issue. Advertising your Twitter for the advice of "switch to somewhat well-known browser X, install these very common extensions and use a VPN" is also a bit ... odd.

Privacy-focused web browsers; alternative to DDG browser due to this issue among others.

I think it’s significant that a former DDG employee is advocating switching away from the DDG browser.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#183
post #132

Earlier quoted context omitted.

Could you please elaborate as to why you suggest ilGur1132's Smart-HTTPS instead of EFF's HTTPS-Everywhere?

https://reddit.com/r/privacytoolsIO/comments/5qnq6j/time_to_...

That's outdated information. Nowadays you can enable Encrypt All Sites Eligible and the extension will force HTTPS everywhere skipping the whitelist. It'll also prompt you to continue to the HTTP version if HTTPS fails to load.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#184

Earlier quoted context omitted.

What a wussy excuse. This should have been a no-brainer decision: do we quietly compromise privacy so that our users can have little icons on their browser tabs? How absurd. Duckduckgo chose compliance with the inconsequential minutae of bigtech over its primary pain point. This is indicative of misalignment between stated values and the values demonstrated through actions. If you guys made this call, sacrificing pri…

They need to run international ad campaigns, what's that tell you?

What is this possibly meant to imply? Nonprofits run international ad campaigns, governments run international ad campaigns, the military runs international ad campaigns, most organizations could probably find a reason if they have international domain. What is your insinuation specifically?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#185
post #154
post #89

Earlier quoted context omitted.

You really can't use "we promise we won't misuse the information" as an argument, that's what everyone says whether it's true or not, and the whole point of using a privacy-centric browser is that as a user you can't trust those kinds of promises.

They’re primarily a search engine, so yes, you definitely have to trust that they won’t misuse information about what search terms you are querying for.

That’s pretty shaky ground. Trusting a site for X has nothing to do with being comfortable to trusting them with X + Y when Y is unnecessary.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#186

Earlier quoted context omitted.

I appreciate you answering, probably knowing you'd face some negative feedback. Saying "we should trust you, it's for a good reason" is what google and everyone else says. You'll be better off if you just end this. The loss of the fav icon is less important than keeping your credibility.

Seconded. Day in and day out we're given empty promises we can never audit -- now it's being done DuckDuckGo staff too?

thirded. an inconsequential token is not a suitable reason to engage in this kind of data collection, especially for a search tool that prides itself on 'not tracking' users..

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#187
post #81

Earlier quoted context omitted.

This doesn’t make sense for a browser: just embed the service’s logic in the browser, the browser has all the same information the service could get.

We had already had created this anonymous favicon service for our private search engine. In addition, doing it this way avoids another request (and potentially multiple) to the end site. The service is private as we do not collect any personal information (e.g. IP addresses) on any requests for this or any service and the requests are all end-to-end encrypted.

Please ask your higher-ups to educate you about essentials of privacy in the modern age. It's not about what you may be doing wrong, it's about what you technically could do wrong.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#189
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

Technical aspects aside, don't you agree it's a legitimate privacy concern from the user's point of view?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#190
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

Does Gabriel know about this? If not could you please clue him in and get some guidance because you are absolutely getting roasted here and are wrecking DDG's carefully built up reputation. I can easily see how this might seem to be a good idea to you and other DDG engineers but it goes 180 degrees against DDG's stated mission. In other words: you may be well outside your paygrade on this.
Post reply on HN