Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

471–480 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#472

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

I think what angered people was actually that a company saying to hold privacy high was simply refusing to change something after a mistake was pointed out and instead kept on defending it with a technical argument, which makes no sense at all. The reaction would have been actually a lot different if someone from the company admitted the mistake and promised it will be changed. Update: Gabriel Weinberg has promised t…

>defending it with a technical argument, which makes no sense at all.

Well hold on now. If there's a valid technical argument, and it's not a violation of privacy, why doesn't that make sense?

If people are so distrustful of DDG that they don't believe that argument, why use their browser under any circumstance?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#473
post #368

Earlier quoted context omitted.

Google don’t sell privacy. Anyways, what’s this got to do with Google? “Privacy browser violates basic privacy to do something useless” is actually ridiculous. And the response is even more ridiculous! How does literally every single other browser do it? I’m disappointed because I put my reputation on the line to recommend DDG to users based on...privacy. But here we see they actually do not hold true to their stated…

> Google don’t sell privacy. Of course they do. They sell users' privacy for advertising dollars. I am not defending DDG here, as they are clearly in the wrong - but let's not pretend that their error is even close to what Google does.

Can you explain how they sell "privacy"? This is thrown around all the time but I don't think it means what people think it means.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#474
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

Thank you for re-opening and prioritizing this. However, this problem demonstrates gross incompotence for a browser team supposedly concerned with privacy. Will you please do a post-mortem on how this code made it through your code review process in the first place, as well as how it managed to stay in place for a full year after it was pointed out that it represented a privacy problem? "Sends every URL you visit to…

You can’t think of anything they could have done that would be worse than sending URLs to their lookup server? It’s the single worst thing?

My browser syncs URL history between my devices, and that’s a feature that I value about it. Your comments on this topic seem to suggest that all users are making the same decisions about what is acceptable usage of their data, and that’s pretty obviously not true.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#475
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

To be more clear, your staff, and you, have said PII ‘like IP addresses’, and have said ‘thrown away’ some places and ‘not collected’ others. Contrary to this framing, it’s not possible to not incidentally become aware of every single browser users’ usage timing and user IP addresses if the browsers are phoning home this way — a colloquial understanding of ‘collect’, not the James Clapper NSA dodge definition of ‘col…

Just to be fair, as a matter of fact, you surfing that site is revealing you, surfing that site to your ISP and state actors, in the first place. A change, where to get the icon from (origin vs ddg), will not change this fact. It is all about ddg not getting to know, which sites you are surfing, when not searching for it on ddg. Which should, indeed, be a no-brainer.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#476

Can someone please explain like I'm five how this line of code sends the domain a user visited to DDG's servers?

Every time you visit a website on the Android version of the browser, instead of requesting the favicon from https://example.com/favicon.ico, the app is calling out to https://icons.duckduckgo.com/ip3/example.com/favicon.ico.

Since DDG owns the icons.duckduckgo.com service and the domain you were interested in is in the request to icons.duckduckgo.com, you've sent the domain to DDG's servers.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#477

Earlier quoted context omitted.

I think what angered people was actually that a company saying to hold privacy high was simply refusing to change something after a mistake was pointed out and instead kept on defending it with a technical argument, which makes no sense at all. The reaction would have been actually a lot different if someone from the company admitted the mistake and promised it will be changed. Update: Gabriel Weinberg has promised t…

Read your comment again. You are faulting someone for defending thier own argument. You suggest that people who do not cow and apologize to the mob deserve the anger and retribution the mob has to offer. People have a right to think differently and express themselves without threats, bullying, or shaming. The mob does not deserve apologies. The comment above is spot on - we've lost all sense of proportionality. It is…

i cant fully agree.

you obviously should be allowed to make a mistake and be forgiven for it. that does not mean that i personally would ever forgive any `company` that markets itself as pro-privacy after its been caught gathering data on its users.

i could forgive the people working at the company and would definitely expect future employers not to hold that against them, however.

but if a `company` does something while claiming to stand morally opposed to exactly that.... proves that it doesn't actually care about the topic. it just wants the publicity for marketability, discrediting them entirely for all future communication.

in this particular case, i wouldn't go that far however. they weren't gathering any data on their users if i understood it correctly. it was just a badly implemented feature, which will get changed

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#478
It is a hilarious excuse for DDG to claim they are doing this for a favicon. Even if DDG is legitimately not using the data they are definitely collecting the data.

The problem with that is that it requires users to "trust" DDG, which is not how the world works today. If you are a company that collects info, and you expect users to trust that the info will remain safe, secure, and never get misuse that is downright foolish for anyone to believe a word of that.

We all know that DDG cannot claim it's impossible for them to get hacked and have all that data leak out. Hacks happen all the time and so the solution for DDG is to simply NOT collect the data, rather than collect and claim it's all secure.

And we all also know DDG has (or will) get a NSL (National Security Letter) from the NSA to secretly turn over the data anyway, and when that does happen the DDG employees are not even allowed to admit it ever happened.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#479
post #474

Earlier quoted context omitted.

Thank you for re-opening and prioritizing this. However, this problem demonstrates gross incompotence for a browser team supposedly concerned with privacy. Will you please do a post-mortem on how this code made it through your code review process in the first place, as well as how it managed to stay in place for a full year after it was pointed out that it represented a privacy problem? "Sends every URL you visit to…

You can’t think of anything they could have done that would be worse than sending URLs to their lookup server? It’s the single worst thing? My browser syncs URL history between my devices, and that’s a feature that I value about it. Your comments on this topic seem to suggest that all users are making the same decisions about what is acceptable usage of their data, and that’s pretty obviously not true.

If your browser is Firefox, then it encrypts your history before sending it to the vendor.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#480

Earlier quoted context omitted.

> Argument from fallacy is the formal fallacy of analyzing an argument and inferring that, since it contains a fallacy, its conclusion must be false. It is also called argument to logic (argumentum ad logicam), the fallacy fallacy, the fallacist's fallacy, and the bad reasons fallacy. https://en.wikipedia.org/wiki/Argument_from_fallacy

I'm talking about situations where no fallacy has actually occurred, not situations where a fallacy has occurred but a correct conclusion has been arrived at anyway.

I see what you mean. Just because you’re saying a person has a bad history doesn’t mean your committing an “ad hominem”. That seems different.
Post reply on HN