Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

491–500 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#491
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

[deleted]

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#492
post #338

Earlier quoted context omitted.

Yeah people burnt witches in the past ... If they are confident that this feature has no privacy implications they are right to defend the point, despite what people say or think People don't run DDG, the company People can use another search engine if they want I'll keep using DDG anyway

DDG can do what they want and people can as a result publicly state their opinions on it. Freedom goes both ways.

Those witches have a right to be on fire.

Where's my pitchfork?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#493
post #470

Earlier quoted context omitted.

More like we made a design decision, than someone warned us this is bad for privacy, we ignored, after 1 year it blew up on HN, now we are fixing it.

That's exactly right. Don't know why I can't upvote this

In this day and age, bringing problems to the attention of the right people is a challenge.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#494

Earlier quoted context omitted.

I think what angered people was actually that a company saying to hold privacy high was simply refusing to change something after a mistake was pointed out and instead kept on defending it with a technical argument, which makes no sense at all. The reaction would have been actually a lot different if someone from the company admitted the mistake and promised it will be changed. Update: Gabriel Weinberg has promised t…

Read your comment again. You are faulting someone for defending thier own argument. You suggest that people who do not cow and apologize to the mob deserve the anger and retribution the mob has to offer. People have a right to think differently and express themselves without threats, bullying, or shaming. The mob does not deserve apologies. The comment above is spot on - we've lost all sense of proportionality. It is…

This is a really strange take.

Once people have gone down the avenue of earnestly reporting private information leakage, the correct answer is to investigate. DDG decided not to do this and instead dismissed the problem completely out of hand and ignored it for almost a year without taking any action.

No one asked for an apology, they asked DDG to admit fault and then to fix the problem. ie "we shouldn't have done that" not "we're sorry we did that."

You keep saying "mob" but these people didn't collect to harass, if you actually read all of the comments the vast majority are people who are (rightly!) concerned about their data privacy advocate built software leaking every visited URL.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#495
post #154

Earlier quoted context omitted.

They’re primarily a search engine, so yes, you definitely have to trust that they won’t misuse information about what search terms you are querying for.

That’s pretty shaky ground. Trusting a site for X has nothing to do with being comfortable to trusting them with X + Y when Y is unnecessary.

I suppose that's valid. This is the first time I had heard that DDG has a browser too, and I was just assuming that anyone who would use the browser probably also uses the search engine, which they obviously have to trust when they send search queries to it.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#496
post #2

Very weak argument for why they do it. Using a service to retrieve a favicon? Surely there's a way to implement the same logic locally.

So if favicons were gathered locally, then you would prefer that your own browser would reach out and make multiple requests to every (potentially dodgy) site listed on the search result page? Note also that these are favicons for results that DDG has already given you . This isn't tracking your clicks. The list of sites that appear on the search result page is not new information to the search engine that just gave…

Can you explain your edit a little more? I still only understand your original viewpoint. Just because there's an app doesn't mean they don't have to contact DDG servers at all, right?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#497

Earlier quoted context omitted.

Read your comment again. You are faulting someone for defending thier own argument. You suggest that people who do not cow and apologize to the mob deserve the anger and retribution the mob has to offer. People have a right to think differently and express themselves without threats, bullying, or shaming. The mob does not deserve apologies. The comment above is spot on - we've lost all sense of proportionality. It is…

This is a really strange take. Once people have gone down the avenue of earnestly reporting private information leakage, the correct answer is to investigate. DDG decided not to do this and instead dismissed the problem completely out of hand and ignored it for almost a year without taking any action. No one asked for an apology, they asked DDG to admit fault and then to fix the problem. ie "we shouldn't have done th…

You’re absolutely ignoring the possibility of an argument where there is no fault and this is being blown out of proportion. You just assume your opinion is correct and they owe you to fix it. That is in itself the problem OP was exposing.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#498
post #421

Earlier quoted context omitted.

Oh, please. There's a million threads on HN complaining about Google and Facebook. Doesn't even matter if they did something, any post will still have those comments. You can't consider the proportionality of the response by just one thread. It's really quite amazing that when a company that's hitched it's brand entirely to privacy first commits a big privacy faux pas, hides it for a year, and then doubles down on it…

It's because DDG has been shilling on HN for quite a while.

This breaks the HN guidelines against accusations of astroturfing or shilling without evidence. If there's one thing I've learned from looking at the data for countless hours, it's that internet users are far, far too quick to jump to this interpretation of what they perceive on the internet. The overwhelming majority of such accusations are purely bogus, and they poison the community, so we don't allow them here.

Actual evidence is a different story, of course, but then you should be emailing it to hn@ycombinator.com so we can take it seriously and investigate.

Lots more explanation at https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme... going back years now.

https://news.ycombinator.com/newsguidelines.html

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#499
post #340

Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addr…

Thank you for re-opening and prioritizing this. However, this problem demonstrates gross incompotence for a browser team supposedly concerned with privacy. Will you please do a post-mortem on how this code made it through your code review process in the first place, as well as how it managed to stay in place for a full year after it was pointed out that it represented a privacy problem? "Sends every URL you visit to…

Maybe you’re taking this a bit too far? They explicitly state they will not store your data anywhere, and the main safeguard you have for that is your trust in them, not this one specific line of code somebody happened to notice which can’t even break that promise on its own.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#500

Earlier quoted context omitted.

If anything, it's much better than 'no big deal'. It's "We made this design decision, thought you would like it -- we've learnt, changed, and will avoid it later". Can you imagine Google doing something similar? Heck, they're just about to throw the Android rooting community under a hardware-attestation DRM-filled bus.

They started a fire through mild negligence, denied the fire existed, and only put out the fire when the entire neighborhood started yelling. It was a forgivable-but-negligent decision to write/approve that code in the first place. It was a sign of a bad process that a reported security vulnerability was not escalated to people security-conscious enough to immediately identify this as a major problem. I don't agree w…

Correct me if I’m wrong, but by default DDG uses redirects to prevent leaking your search queries through the referrer, so they already can technically see every URL you visit. Except their whole product and system is designed around protecting privacy and not storing that data. If the favicon endpoint respects the same rules (which it obviously does), it is no different.
Post reply on HN