Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

321–330 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#321

Speaking of leaks, I never understood why people use DDG's bangs. By using bangs you're sending your search history to DDG even when using search engines that aren't DDG.

> you're sending your search history to DDG

I was astonished by this at first, but I think you must mean "you're sending all searches performed with bangs to DDG". I worried that you meant somehow the browser search history was being sent to DDG, but that seems impossible.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#322

Earlier quoted context omitted.

> you may be well outside your paygrade on this. Not as worse as publicly denouncing an honest engineer while referencing his paygrade. I hope there is no affiliation you have with DDG to be honest, because this is much, much worse.

What do you mean? This response is fine. It’s honest feedback, and it isn’t a personal swipe to say it’s above someone’s pay grade to be responding to a PR crisis as an honest engineer. I was once an honest engineer too, publicly. Being honest in private is enough for me now. It’s a lesson worth learning. That said, it’s not like a single HN comment will make or break a company, so if they’re really just a rank-and-f…

Yes, but chastising an employee is not in the interest of good PR, even if we sadly see that quite often in the days of social media. That is especially true if the employee just honestly laid out the facts, I wouldn't even call that a mistake.

I use DDG and the possibility of getting a statement directly from an engineer conveys much more trust than a carefully crafted PR statement ever could. I would think again about using it if the company does indeed come down on employees that live the values the company writes on its flags to have honest and transparent business practices.

That said, I am careful too when I state things about my company, even if I believe there is nothing to hide. Still, people that think it isn't the place for others with knowledge to comment are often not too impressive and would have difficulties in convincing me that privacy and transparency are real goals instead of just looking decent enough.

Furthermore the naming of management of DDG creates a stark contrast to the suggestion for more professional distance. I don't like PR very much as you might have guessed, but like a good design it needs some congruence.

If people find out that you just shut up for your company, it might give people the wrong impression about their business.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#323
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

I don't know how you can misunderstand your core demographic this badly mate.

If you think the next time I hit the shitter I'm not going to be looking for a new browser, you're dead wrong.

Just do the basic checks and then fall back to a DDG logo, no one cares that much about the favicon.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#324

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

> ignoring the genuinely huger issue of the amount of info and mining that google

By using DuckDuckGo you're doing the opposite of ignoring privacy issues in Google products.

And hence the reaction. Why use DDG at all, if they're not safely protecting your private data 100%?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#325
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

> the purpose of the request...

... is completely irrelevant. Even if they were trying to save babies from a fire (which they really aren't) it wouldn't excuse the fact that they're doing something orthogonal to their stated policy and sole reason for existing.

Everyone makes mistakes, that's not the point. The point is to correct them when they're found, instead of digging one's heels in the ground and pretending it's nothing.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#326

Speaking of leaks, I never understood why people use DDG's bangs. By using bangs you're sending your search history to DDG even when using search engines that aren't DDG.

I only use bangs when regular DDG search has failed me, and I'm quite happy to tell DDG of that failure.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#327
post #109
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

Take the code from Firefox iOS or Android-components. We spent a lot of time on these and it is all on device. https://github.com/mozilla-mobile/android-components https://github.com/mozilla-mobile/Firefox-iOS

Yes, apart from Chrome's implementation there is probably no better tested and more mature implementation. Still it seems to be a non-trivial problem because Firefox sometimes shows me a favicon from another site I used.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#328
post #2

Very weak argument for why they do it. Using a service to retrieve a favicon? Surely there's a way to implement the same logic locally.

BitWarden does this, too.

BW already has all the URLs of services you use: you saved them yourself for them to keep safe. It's obvious you already trust them enough to know that sort of data.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#329
post #52

DuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases an…

so, essentially you blew privacy because of favicons? favicons??

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#330

Earlier quoted context omitted.

What do you mean? This response is fine. It’s honest feedback, and it isn’t a personal swipe to say it’s above someone’s pay grade to be responding to a PR crisis as an honest engineer. I was once an honest engineer too, publicly. Being honest in private is enough for me now. It’s a lesson worth learning. That said, it’s not like a single HN comment will make or break a company, so if they’re really just a rank-and-f…

Yes, but chastising an employee is not in the interest of good PR, even if we sadly see that quite often in the days of social media. That is especially true if the employee just honestly laid out the facts, I wouldn't even call that a mistake. I use DDG and the possibility of getting a statement directly from an engineer conveys much more trust than a carefully crafted PR statement ever could. I would think again ab…

It’s your duty as an employee to shut up for your company. I didn’t learn this until later in my career. Fortunately it didn’t have lasting impact.

By commenting on an ongoing PR crisis without consulting management, you are both undermining their ability to respond in an effective way — imagine how strange it would look to see a “Hey, X from here” after an existing one was already posted — and you’re acting on your own rather than in a team. You’re a part of a team; how could you think it’s a good idea to act alone?

Of course, I am talking to my former self with this comment, since that’s exactly what I did at S2 when working on HoN. It was a mistake, and I gave the community the wrong impression about the company’s priorities.

You have to understand, when you’re given money to do a job, you’re not given authority to become that job. Just because your job is getting beat up on social media doesn’t mean you should just jump in and go “Hey, that’s not true!” It doesn’t matter whether it’s true. Here, let me pretend to be DDG:

“Hi, Shawn from DDG here. You’re right; this was an oversight on our part. Obviously we dropped the ball on this. To clarify, we were unintentionally gathering the data as a side effect of our favicon service. . We’ll be acting immediately to reverse this, and we’ll be enacting policy changes to ensure that user privacy — our core mission — is maintained going forward.”

But that’s not what they said. And if you’re gonna tell the community the opposite of what they want to hear, you’d better be in charge of the company’s Telling The Community Things division.

Post reply on HN