Live data from Hacker News

DuckDuckGo browser seemingly sends domains a user visits to DDG servers

github.com

501–510 of 531 posts

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#501
post #499

Earlier quoted context omitted.

Thank you for re-opening and prioritizing this. However, this problem demonstrates gross incompotence for a browser team supposedly concerned with privacy. Will you please do a post-mortem on how this code made it through your code review process in the first place, as well as how it managed to stay in place for a full year after it was pointed out that it represented a privacy problem? "Sends every URL you visit to…

Maybe you’re taking this a bit too far? They explicitly state they will not store your data anywhere, and the main safeguard you have for that is your trust in them, not this one specific line of code somebody happened to notice which can’t even break that promise on its own.

Privacy is never built on trust. It's built on mathematical and logical facts. The only effective way to keep data private is to never handle it in the first place.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#502

Earlier quoted context omitted.

i cant fully agree. you obviously should be allowed to make a mistake and be forgiven for it. that does not mean that i personally would ever forgive any `company` that markets itself as pro-privacy after its been caught gathering data on its users. i could forgive the people working at the company and would definitely expect future employers not to hold that against them, however. but if a `company` does something w…

You seem to put great value on forgiveness. What is your forgiveness worth? What emotional chasm do you struggle with that you demand others to beg for your forgiveness? Why on Earth should anyone care if you forgive them. This is your emotional hangup - not a problem with DuckDuckGo.

Not particularly.

I was specifically responding about your outrage how internet 'mobs' demand forgiveness from the people they've supposedly wronged. The whole comment was just me talking from the perspective of a possible self identified victim and how that person (me) would respond in such a case.

Forgiveness would've to happen for me to trust that party again, which would be a requirement for me becoming a user/paying for the service again. If that possible other party doesn't care about wherever the people they've supposedly wronged use/pay for their services, then there is obviously no need for any interaction after that point.

And as I said before: none of this applied to ddg, as they didn't spy on their user. They implemented a leaky feature, which they've committed to changing.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#503
post #202

Earlier quoted context omitted.

BitWarden does this, too.

If you host your own Bitwarden server you don't have to worry about that. Also different expectations

I host my own BitWarden server and had to explicitly deny using BitWarden's favicon lookup feature.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#504
post #500

Earlier quoted context omitted.

They started a fire through mild negligence, denied the fire existed, and only put out the fire when the entire neighborhood started yelling. It was a forgivable-but-negligent decision to write/approve that code in the first place. It was a sign of a bad process that a reported security vulnerability was not escalated to people security-conscious enough to immediately identify this as a major problem. I don't agree w…

Correct me if I’m wrong, but by default DDG uses redirects to prevent leaking your search queries through the referrer, so they already can technically see every URL you visit. Except their whole product and system is designed around protecting privacy and not storing that data. If the favicon endpoint respects the same rules (which it obviously does), it is no different.

Except the favicon thing applies not just to searches on DDG, but every page you visit if you use this browser

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#505
post #302
post #202

Earlier quoted context omitted.

If you host your own Bitwarden server you don't have to worry about that. Also different expectations

Yeah, I would just have to worry about losing all my passwords ever.

It's really easy to back up the server and never lose passwords.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#506

Earlier quoted context omitted.

As a DDG user I don't feel like I'm sacrificing anything. Two sets of results are better than one (I can see Google results by adding !g, which I do less than once per day on average) and, ironically, DDG bangs are the easiest way to use even Google services like Translate and Scholar.

Ask.Moe also support bangs (I know !g and !gt works, not sure about scholar). Searx doesn’t but I imagine they’d gladly accept a pull request for it.

I don't know much about those search engines. What's the advantage of Ask.Moe or Searx?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#507
post #433

Earlier quoted context omitted.

Yeah that's my bad. epi0Bauqu is my original account, but since no one knew who I was under that account I, some years later, made the yegg account and I try to post from there. The issue here is I logged in to post the comment, and then switched to my laptop where I was already logged in this other account.

Good to know, I just wanted to be sure that someone wasn't attempting an impersonation.

It was only a minor issue that got resolved quickly thanks to your question, but DDG's response to this whole issue of losing users' trust seems to be accurately characterised by the phrase "a succession of embarrassing own goals". :-/

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#508

Earlier quoted context omitted.

I think it would be more clear if you come up with a statement like: ‘we never used this data, other than showing favicons’

We never used this data, other than showing favicons. In fact, we didn't (and don't in general) collect any user-level data in the first place, per our strict privacy policy: https://duckduckgo.com/privacy In this case, the way it works is you hit our favicon service and it returns the favicon, not using any PII in the process, and our web servers are configured not to log any PII. In other words, our system is techn…

You might want to clarify you never retained any PII, unless you can 100% confirm that that favicon request didn't include any embedded user- or installation-id in cookies, headers or the like?

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#509

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

> But... the reaction here is "they made a mistake, let's pile on like kids in a playground" ignoring the genuinely huger issue of the amount of info and mining that google et al. do.

What about genocide too? Please people, stop with these "but the other bigger unrelated issue should get more visibility".

> Which is why politicians rarely admit mistakes, because it's taken as a sign of weakness, not strength, to admit you were wrong.

Can you point me where DDG admitted they were wrong doing this? They didn't... they just explained why they did it but completely ignore the greater issue because they consider themselves "good". Just like that politician you may talk about, or Google, or whatever.

This is about DDG.

Re: DuckDuckGo browser seemingly sends domains a user visits to DDG servers

#510

There's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But…

> But... the reaction here is "they made a mistake, let's pile on like kids in a playground" ignoring the genuinely huger issue of the amount of info and mining that google et al. do.

What about genocide too? Please people, stop with these "but the other bigger unrelated issue should get more visibility".

> Which is why politicians rarely admit mistakes, because it's taken as a sign of weakness, not strength, to admit you were wrong.

Can you point me where DDG admitted they were wrong doing this in their first response? They didn't... they just explained why they did it but completely ignore the greater issue because they consider themselves "good". Just like that politician you may talk about, or Google, or whatever. They are part of that bigger issue you mentions.

This is about DDG.

Luckily that pile of kids in a playground made them realize that mistake, they would have ignored otherwise (like they did on their first respond).

Post reply on HN