Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

261–270 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#261
post #238

Earlier quoted context omitted.

I think you're being downvoted because you chose to piggyback your comment on a seemingly unrelated one at the top, are being vitriolic, and didn't back up your claims with respect to their intent and refusal to change this.

Well it's related because Mozilla actually cares about your privacy vs DuckDuckGo which obviously could care less from their reaction to this issue. Their refusal to change this is all the proof you need to know. I dont even use DDG I use Google I just think its funny they have a "Privacy browser" that sends all the sites you visit back to their servers

It is not relevant to this sub-thread, and should have been a new top-level comment.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#262

Earlier quoted context omitted.

Are you saying DDG is forcing you to send a User-Agent header? DDG's privacy policy also goes on about the privacy implications of User-Agent headers combined with IP addresses. So let's say I take what they have put in their privacy policy to heart and I stop sending a User-Agent header. In response DDG sends prefixed result URLs? WTF? Using haproxy, for example, I can use a "modern browser" and send no User-Agent h…

You can disable this on the settings page. Frankly I'd infinitely rather send my request through a redirect served by DDG than send my referer to every site I visit. I think this is a perfectly sensible default for the average user, who both doesn't block / obscure their user agent and doesn't have referer masking software in place. You're free to disagree, but in that case you can make use of the option to change th…

The settings page requires that the user enable Javascript.

I would not call haproxy "referer masking software". In any event, a proxy is not even needed.

Modern browsers are open source, right? Users can edit the source and remove the code that sends Referer header.

Even easier, I wrote my own http client. I can send any header I want, or none at all. According to DDG's privacy policy this is a good thing.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#263
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

In germany we have the words "Datensparsamkeit" (data parsimony) and "Datenvermeidung" (data prevention) [1]. Which wikipedia merely translates as "Privacy by design" [2].

DDG is unneccessaryly producing (aggregating), transmitting (and collecting?) very sensitive user data here, which is just the opposite of data protection. I can't even understand why they try to justify their actions. It's like omitting the seat-belt in a car, then telling customers that this was required to make the in-car entertainment system more usable.

[1] https://de.wikipedia.org/wiki/Datenvermeidung_und_Datenspars...

[2] https://en.wikipedia.org/wiki/Privacy_by_design

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#264

Speaking of leaks, I never understood why people use DDG's bangs. By using bangs you're sending your search history to DDG even when using search engines that aren't DDG.

Because it's the easiest (and sometimes only) way to get this functionality on major browsers and browser developers have no plans to implement this functionality natively.

Both Firefox and Chrome have custom search keywords:

https://support.mozilla.org/en-US/kb/how-search-from-address...

I maintain a set of such keywords in my Firefox, that I use on iOS and Android too.

The easiest would be to just use Google btw, as it does a reasonable job to give you the website you're thinking of just by mentioning it in the search query, e.g "Frozen imdb" (though it does a perfect job in this case with just "Frozen").

If you use DDG, because I'm assuming you value your privacy, sending your search history to DDG when you could avoid it doesn't make much sense.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#265

Earlier quoted context omitted.

How can users turn this off?

Route icons.duckduckgo.com to null. Sidenote: The more I use pi-hole the more I realise how essential it is!

Is there a difference between using pi-hole and edinting etc host on Windows? I've heard about pi-hole but I'm not sure what it does exactly.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#266

Earlier quoted context omitted.

I appreciate you answering, probably knowing you'd face some negative feedback. Saying "we should trust you, it's for a good reason" is what google and everyone else says. You'll be better off if you just end this. The loss of the fav icon is less important than keeping your credibility.

This is the correct answer. We all remember "Do No Evil" and have been around long enough to see that sentiment die. Don't go down this path.

They've already started down that path, judging by all the DDG billboards I see driving my 18 wheeler around the country, and all the DDG ads I hear on NPR-related podcasts.

Not that I'm against making money. But there's a tipping point associated with some height value in a pile of cash, and once you cross that point then the pile controls you. DDG probably hasn't crossed that point yet, but self-justification is one of the steps on that path.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#267

Earlier quoted context omitted.

> Argument from fallacy is the formal fallacy of analyzing an argument and inferring that, since it contains a fallacy, its conclusion must be false. It is also called argument to logic (argumentum ad logicam), the fallacy fallacy, the fallacist's fallacy, and the bad reasons fallacy. https://en.wikipedia.org/wiki/Argument_from_fallacy

I'm talking about situations where no fallacy has actually occurred, not situations where a fallacy has occurred but a correct conclusion has been arrived at anyway.

That’d be a form of equivocation: the accuser is using an incorrect definition of the fallacy, instead of the true one.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#268
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

Does Gabriel know about this? If not could you please clue him in and get some guidance because you are absolutely getting roasted here and are wrecking DDG's carefully built up reputation. I can easily see how this might seem to be a good idea to you and other DDG engineers but it goes 180 degrees against DDG's stated mission. In other words: you may be well outside your paygrade on this.

This is an asshole response.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#269
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

In germany we have the words "Datensparsamkeit" (data parsimony) and "Datenvermeidung" (data prevention) [1]. Which wikipedia merely translates as "Privacy by design" [2]. DDG is unneccessaryly producing (aggregating), transmitting (and collecting?) very sensitive user data here, which is just the opposite of data protection. I can't even understand why they try to justify their actions. It's like omitting the seat-b…

In fact I think what they do here is illegal by GDPR. It does not matter that they say they do not collect the information, it is enough it is unnecessarily sent to their servers to make the whole function illegal.

The transmission of ip address alone, which is necessary for the TCP request to happen, deanonymizes the request enough to not be considered anonymous within the GDPR framework.

GDPR Article 5 (1) c: "Personal data shall be ... adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);" - this is the "Datensparsamkeit" you mentioned.

Exceptions from Article 7 do not apply: The user has to give wilfully give informed consent, which he cannot do as the privacy policy of the browser omits the information that all visited domains are transmitted to DDG servers.

GDPR Recital 30 "Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags."

Oh, and the fact I'm downvoted for a purely informational comment additionally does not shine a good light on DDG.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#270

Earlier quoted context omitted.

Does Gabriel know about this? If not could you please clue him in and get some guidance because you are absolutely getting roasted here and are wrecking DDG's carefully built up reputation. I can easily see how this might seem to be a good idea to you and other DDG engineers but it goes 180 degrees against DDG's stated mission. In other words: you may be well outside your paygrade on this.

> you may be well outside your paygrade on this. Not as worse as publicly denouncing an honest engineer while referencing his paygrade. I hope there is no affiliation you have with DDG to be honest, because this is much, much worse.

While that last bit was slightly crass, the rest of the comment was dispensing some very sage advice, I thought.
Post reply on HN