Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

381–390 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#381

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

> But... the reaction here is "they made a mistake, let's pile on like kids in a playground"

It's not one mistake, but several. Other then the initial mistake there is also the sloopy reaction and the fact they just closed the issue without bothering to fix it. And this was 1 year(!) ago. Nothing changed in the meanwhile. Now someone pushed it to public and after just some hours they reopen the issue and promise to fix it.

This is the reason why people react loud, because it works. And often it's even the only way that works.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#382

Earlier quoted context omitted.

I think it would be more clear if you come up with a statement like: ‘we never used this data, other than showing favicons’

We never used this data, other than showing favicons. In fact, we didn't (and don't in general) collect any user-level data in the first place, per our strict privacy policy: https://duckduckgo.com/privacy In this case, the way it works is you hit our favicon service and it returns the favicon, not using any PII in the process, and our web servers are configured not to log any PII. In other words, our system is techn…

Thank you very much for confirmation.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#383
post #369
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

I've already posted this somewhere else, but I'll copy it here again as well: It's not immediately obvious whether it is more privacy preserving if the client automatically makes a request to each site in the search results while scrolling through the results, especially since you're already trusting DDG when performing the search. Maybe this should be an opt-in rather than an opt-out feature? All in all its really n…

> not as big of an issue as people here make it out to be.

Please refrain from speaking for others without being asked to.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#384

Earlier quoted context omitted.

In germany we have the words "Datensparsamkeit" (data parsimony) and "Datenvermeidung" (data prevention) [1]. Which wikipedia merely translates as "Privacy by design" [2]. DDG is unneccessaryly producing (aggregating), transmitting (and collecting?) very sensitive user data here, which is just the opposite of data protection. I can't even understand why they try to justify their actions. It's like omitting the seat-b…

In fact I think what they do here is illegal by GDPR. It does not matter that they say they do not collect the information, it is enough it is unnecessarily sent to their servers to make the whole function illegal. The transmission of ip address alone, which is necessary for the TCP request to happen, deanonymizes the request enough to not be considered anonymous within the GDPR framework. GDPR Article 5 (1) c: "Pers…

I think you are being downvoted because your interpretation of GDPR is extremely broad and people disagree with that. I also don't think it's in line with the way it is being applied in practice. Nothing to do with DDG.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#385

Haha, amazing to witness. This is the problem with catering to this crowd: your audience is suddenly full of people who just want to see you fail. Good luck, DDG.

I don't agree.

I really like DDG - it works good, it is fast and it does not use my personal search for giving me "better ads" or "better search results" that put me in a filter bubble.

But there is a different issue here at play; because of errors like this the whole DDG brand gets a bad rap - and thats not only bad because of the risk of people losing a google alternative but because it is real easy to exploit situations like this for google-like companies to give an impression that "all this privacy thing is bs, all companies work in a same way". There are a lot of people that are not really sure is this "privacy thing" is worth the inconvinience of swiching to some other search engine/browser/app and situations like this one are not helpful in that regard.

Lot of folks are aware of this and are displeased for risking brand confidence of such a visible privacy-concerned company for miniscule gains like performance gains for fetching a favicon for the first time - just fetch the favicon after you display the rest of the page and cache it, maybe dont even try to fech it if the connection is poor - who cares really

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#386
post #332

Earlier quoted context omitted.

Complicated code can run just fine on device. I’ve been an avid DDG user for years and it worries me that DDG staff don’t see why this is an issue. We shouldn’t have to trust your privacy policy if you minimize exposure.

This. No matter how tricky the logic is, there's literally no reason to run that code on DDG server's and throw in a remote connection. What the hell?

That's not fair. There is a very clear reason: it simplifies development for them and avoids duplicating functionality in two different codebases. You can argue about whether or not that's a good trade-off given the privacy implications (and I would agree that it's not) but you can't claim that there is "literally no reason".

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#387

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

> But... the reaction here is "they made a mistake, let's pile on like kids in a playground" It's not one mistake, but several. Other then the initial mistake there is also the sloopy reaction and the fact they just closed the issue without bothering to fix it. And this was 1 year(!) ago. Nothing changed in the meanwhile. Now someone pushed it to public and after just some hours they reopen the issue and promise to f…

Part of the point is that likely this has zero privacy implications (except potentially disclosing to someone monitoring your traffic that you are using their browser).

The mistake is rather an area of improvement where they can change something that respect privacy by policy to something that respect privacy by design.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#388
post #335
post #109

Earlier quoted context omitted.

Take the code from Firefox iOS or Android-components. We spent a lot of time on these and it is all on device. https://github.com/mozilla-mobile/android-components https://github.com/mozilla-mobile/Firefox-iOS

Why don't they just take the code from their "internal favicon service"? The whole thing smells.

If you don't visit the site explicitly, just have the site somewhere in a list/bookmark/whatever, that site now has your IP address and basic header info when it needs to go retrieve it. By going through DDG, the site has a bot hit.

To me it looks to be trying to uphold your anonimity until you commit (click) through to the site/link. But certainly other ways they can approach this if it really bothers people.. I'd prefer DDG doing the lookup.. or having no fav icons.. over my computer going and downloading all my bookmark or other source icons

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#389

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

I disagree, or maybe we read different responses, but the ones I read where more critical of how (a) ddg (employee) handled this. Didn't see anyone claim that this was on a google-level of bad, more like pointing out that google started out as a small company wanting to "do no evil", but slowly turned into what it is today. Is it really that weird that people are worried that this might be the first of many small ste…

> Didn't see anyone claim that this was on a google-level of bad

The point is that people are reacting as if it was.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#390

Earlier quoted context omitted.

> ignoring the genuinely huger issue of the amount of info and mining that google By using DuckDuckGo you're doing the opposite of ignoring privacy issues in Google products. And hence the reaction. Why use DDG at all, if they're not safely protecting your private data 100%?

Google: stripmines everything. Would collect your soul if it could[0]. DDG: favicon fuckup. And you can't see the difference? > Why use DDG at all, if they're not safely protecting your private data 100%? Says the man who's willingly chosen to spunk his real name, the company he works for, his position within said company, his photograph and I'm sure I could find much else besides, over the web. Then asks for 100% pr…

This isn't just a mistake. They're saying it's not a problem. Do you agree with that? If not, you're arguing with the wrong person.
Post reply on HN