Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

481–490 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#481

Earlier quoted context omitted.

I think what angered people was actually that a company saying to hold privacy high was simply refusing to change something after a mistake was pointed out and instead kept on defending it with a technical argument, which makes no sense at all. The reaction would have been actually a lot different if someone from the company admitted the mistake and promised it will be changed. Update: Gabriel Weinberg has promised t…

>defending it with a technical argument, which makes no sense at all. Well hold on now. If there's a valid technical argument, and it's not a violation of privacy, why doesn't that make sense? If people are so distrustful of DDG that they don't believe that argument, why use their browser under any circumstance?

A performance optimization around a trivial thing like a favicon is no reason to destroy everyone's security.

Let's assume DDG is a great and honest company and will collect all the info, but never use it for anything bad. Guess what, they can get still hacked and all the info leaks out.

This is a horrendous breach of trust that they WERE collecting it however, and I'm glad they got caught. It will not be tolerated. They'll have to change this or face a revolt.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#482

Earlier quoted context omitted.

Thank you, this is the response people here want to hear. And if this gets fixed in a reasonable timeframe, this is just one of those "everyone makes a mistake one in a while"-things, no big deal.

If anything, it's much better than 'no big deal'. It's "We made this design decision, thought you would like it -- we've learnt, changed, and will avoid it later". Can you imagine Google doing something similar? Heck, they're just about to throw the Android rooting community under a hardware-attestation DRM-filled bus.

There's no way that this feature would've made it into Chromium.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#483

Earlier quoted context omitted.

Really, just a response, saying everything is ok, validates your trust? Bought some wirecard stocks latly?

Creating a throwaway account to disparage a particular point of view is also questionable, no? At what point did we stop taking people's word and commitment as valid? Sure, I too want to see proof that they are doing the right thing here (because I don't understand the design decisions that led to the creation of that service in the first place), but because these changes are not immediate, this statement does at lea…

Well for me it was back in the 90’s

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#484

Earlier quoted context omitted.

Thank you, this is the response people here want to hear. And if this gets fixed in a reasonable timeframe, this is just one of those "everyone makes a mistake one in a while"-things, no big deal.

If anything, it's much better than 'no big deal'. It's "We made this design decision, thought you would like it -- we've learnt, changed, and will avoid it later". Can you imagine Google doing something similar? Heck, they're just about to throw the Android rooting community under a hardware-attestation DRM-filled bus.

They started a fire through mild negligence, denied the fire existed, and only put out the fire when the entire neighborhood started yelling.

It was a forgivable-but-negligent decision to write/approve that code in the first place. It was a sign of a bad process that a reported security vulnerability was not escalated to people security-conscious enough to immediately identify this as a major problem.

I don't agree with the outrage. Anyone who has followed DDG knows they're legit. They just need to do a bit better. They probably will.

Their main feature is privacy. They should be at least as sensitive to privacy vulnerabilities as their most aware users.

DDG should announce that they now pay out privacy-related vulnerabilities like this and send the reporter $5k. It would be good honest PR and well worth the expense.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#485

Earlier quoted context omitted.

Read your comment again. You are faulting someone for defending thier own argument. You suggest that people who do not cow and apologize to the mob deserve the anger and retribution the mob has to offer. People have a right to think differently and express themselves without threats, bullying, or shaming. The mob does not deserve apologies. The comment above is spot on - we've lost all sense of proportionality. It is…

i cant fully agree. you obviously should be allowed to make a mistake and be forgiven for it. that does not mean that i personally would ever forgive any `company` that markets itself as pro-privacy after its been caught gathering data on its users. i could forgive the people working at the company and would definitely expect future employers not to hold that against them, however. but if a `company` does something w…

You seem to put great value on forgiveness. What is your forgiveness worth? What emotional chasm do you struggle with that you demand others to beg for your forgiveness?

Why on Earth should anyone care if you forgive them. This is your emotional hangup - not a problem with DuckDuckGo.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#486
post #451

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

If you claim to fight for privacy and rise to popularity by shaming your competitors' evil anti-privacy (or shady) practices and do something exactly what the rest do, you deserve every bit of criticism. Why should you receive a free pass and the competitors shouldn't? Simply because of your marketing stance?? And for the record, collecting your browser history just to display a stupid favicon is the most ridiculous…

"collecting your browser history just to display a stupid favicon is the most ridiculous excuse I've heard in a long while"

Though I agree the the implementation could be better, they should just check the head and the root for the icon and if not found that's that. But the possibility of something be used for malicious ends does not entail confirmation of it being used that way. Just because we have knifes in our kitchen does not make us automatically guilty of stabbing people. I find it easier to believe that this was actually, if misguided, an attempt to solve a problem rather than a nefarious plots to track users across the web.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#487

Earlier quoted context omitted.

>defending it with a technical argument, which makes no sense at all. Well hold on now. If there's a valid technical argument, and it's not a violation of privacy, why doesn't that make sense? If people are so distrustful of DDG that they don't believe that argument, why use their browser under any circumstance?

A performance optimization around a trivial thing like a favicon is no reason to destroy everyone's security. Let's assume DDG is a great and honest company and will collect all the info, but never use it for anything bad. Guess what, they can get still hacked and all the info leaks out. This is a horrendous breach of trust that they WERE collecting it however, and I'm glad they got caught. It will not be tolerated.…

[deleted]

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#488
I didn't know they had a browser. I'll have to give it a try. Can't be any worse than Google's browser. Or their OS. Or their video monopoly. Or their search monopoly. Or their secret partnerships with governments. Or their ad monopoly. Or their email monopoly.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#489

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

[deleted]

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#490
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

Thank you, this is the response people here want to hear. And if this gets fixed in a reasonable timeframe, this is just one of those "everyone makes a mistake one in a while"-things, no big deal.

It's fixed: https://github.com/duckduckgo/Android/pull/878/files
Post reply on HN