Live data from Hacker News

PRISM fears give private search engine DuckDuckGo its best week ever

venturebeat.com

111–120 of 213 posts

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#111
post #45

I ceased using Google search except as a last resort when this story broke, and I had no idea what I had been missing out on with DDG: Excellent keyboard navigation . Also, DDG's results compared to a year ago are night-and-day. It seems to listen to my keywords better than Google did too, a growing annoyance I had. If you haven't, you really should try out DDG for a week.

I've done the same. Also switched to Firefox with full Adblock and tracking bugs blocking. It's not much, but at least I'm no longer leaving a huge slimy trail behind me online.

[deleted]

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#112

I ceased using Google search except as a last resort when this story broke, and I had no idea what I had been missing out on with DDG: Excellent keyboard navigation . Also, DDG's results compared to a year ago are night-and-day. It seems to listen to my keywords better than Google did too, a growing annoyance I had. If you haven't, you really should try out DDG for a week.

I'm all for using DDG on principle, but google search results are still far superior.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#113
post #63

Earlier quoted context omitted.

If you're using HTTPS, they can't even see your URLs or headers. That's sort of the point.

Email is unencrypted in transit.

That's not universally true - there's a remarkable amount of TLS/SSL encrypted email-in-transit, either via STARTTLS ESMTP commands or SSL over port 465 (and 993/995 for IPAM and POP3).

I don't think there's a way to guarantee your mail always travels over TLS/SSL secured connections, but I suspect more of it does than you think.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#114

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

There's no question that they're monitoring upstream traffic. In fact they may still be doing the old ECHELON trick in which the US eavesdrops on non-Americans, the rest of the world spies on Americans (among others) - and then everyone swaps the data received.

But in the light of the PRISM documents it's even more likely than it was before that the NSA doesn't have the ability to decrypt HTTPS, or at the minimum that the US considers it too important to risk giving it away by using it on routine Top Secret signals intelligence. (And/or maybe too resource-intensive to use for that.) The strongest evidence for this is that we haven't heard anything about such a capacity yet from Snowden, Greenwald et al., who all have the full PRISM deck (along with other documents) in their possession and would surely tell us about it if they knew of it. So either 1) the PRISM slides do mention the ability to decrypt SSL or SSH streams but Snowden and the journalists haven't picked up on it (not impossible given the apparent incompetence they displayed over "direct access"), 2) it's too sensitive to mention in a self-aggrandising Top Secret overview of upstream and "direct collection" Internet signals intelligence, which probably means it's not in use (or at least not in regular use) for upstream collection or 3) they really don't have it.

A supporting reason to think that they don't have it, or hardly ever use it, is the apparent emphasis on "direct collection" in the PowerPoint. Why go to the hassle of dancing the frenemy minuet with Google and other fairly-anti-surveillance Silicon Valley firms when you can just get what you want from upstream collection at the apparently more-accommodating telcos? This isn't conclusive because even if you could understand all the traffic into and out of someone's Facebook account you'd still like to be able to see the internal state of the account, in particular so that you'd know what they'd been doing before the upstream surveillance began. But I think it's at least as likely that the whole new focus on direct collection is a workaround for the fact that, thanks to SSL and SSH, upstream collection just isn't what it used to be back in the days of ECHELON.

As the slide said, You Should Use Both: direct collection to give you access to US-company servers, probably bypassing the HTTPS problem, and upstream access to give you data, probably only unencrypted data (email!), that passes through the US without going to a US-company server.

(If you want an exotic alternative theory, you could speculate that the PRISM document is a fake, a limited hangout http://en.wikipedia.org/wiki/Limited_hangout by the US spooks, maybe precisely to direct attention away from their ability to decrypt HTTPS streams. But this now seems unlikely, for example because DNI Clapper would surely have to have approved a managed release of a set of documents that both gave away the Verizon metadata surveillance and so also implicated him in perjury.)

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#115
post #32

Not that this is going to help. The NSA is probably tapping the fiber at the ISP's backbone in front of Google. Why do you think it is called PRISM? It's probably named for the way they are splitting the fiber and recording everything.

In the case of DDG, that would be difficult. DDG uses SSL. If you make a mistake and type "duckduckgo.com" instead of " https://duckduckgo.com" , it will automatically redirect you to the secure page. Unfortunately, that redirect gives a man-in-the-middle and opportunity to hijack your connection, even with SSL; however, that's tricky enough that its hard to imagine anyone pulling it off without ever being noticed.

HSTS allows a site to indicate that in the future it should always be loaded over a secure connection, so you only have an interceptable connection the very first time you visit that site. Both Firefox and Chrome allow sites to add themselves to a list to "preload" HSTS enforcement, so even that initial connection which is man-in-the-middle-able doesn't happen.

I don't see them in the current lists, so DDG should contact Mozilla and Google to get added to their preloaded HSTS lists[1][2] so all connections will automatically happen only over HTTPS.

[1] http://dev.chromium.org/sts

[2] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#116

Earlier quoted context omitted.

Why would anyone believe his own computer isn't already penetrated?

Because I am running GNU/Linux.

Why do you trust any binaries you've got? Where did your first-use/bootstrapping compiler come from?

And even if you wrote your own OS and compiler from the ground up - who wrote your BIOS? Your network card firmware? Your disk controller software? Your CPU microcode?

We _all_ abdicate our trust-chain _somewhere_

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#117

I ceased using Google search except as a last resort when this story broke, and I had no idea what I had been missing out on with DDG: Excellent keyboard navigation . Also, DDG's results compared to a year ago are night-and-day. It seems to listen to my keywords better than Google did too, a growing annoyance I had. If you haven't, you really should try out DDG for a week.

> Also, DDG's results compared to a year ago are night-and-day. Still looks 2nd rate. I replicated one of my last searches (learning rails): rails find if element is in array First hit on google is the stackexchange answer with .include? (which I was spacing-out on) DDG yields the Array docs, which is correct but is a helluva lot of info when I'm looking for a concise answer.

Don't forget about DDG's great bang shortcuts.

If you ever find yourself wanting to fall back on Google's results, just throw !sp at the front of a DDG search for StartPage's proxied Google service (or !g if you absolutely must go to Google). DDG has many, many shortcuts for directly searching StackOverflow, GitHub, Amazon, Wikipedia, etc.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#118
post #79

I ceased using Google search except as a last resort when this story broke, and I had no idea what I had been missing out on with DDG: Excellent keyboard navigation . Also, DDG's results compared to a year ago are night-and-day. It seems to listen to my keywords better than Google did too, a growing annoyance I had. If you haven't, you really should try out DDG for a week.

And they are always there in your im client http://ddg.gg

Plaintext, though. I wish DDG over XMPP would do OTR.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#119

Not that this is going to help. The NSA is probably tapping the fiber at the ISP's backbone in front of Google. Why do you think it is called PRISM? It's probably named for the way they are splitting the fiber and recording everything.

It could also be named PRISM as a form of misdirection, to make people think that the codename referred to upstream-collection operations. (It's beyond doubt that upstream collection is still ongoing too, though.) Or it could be that spy organisations just like optical metaphors. FWIW the You Should Use Both slide seems to use PRISM to refer specifically to the "direct collection" and not the upstream collection capability.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#120
post #76
post #8

Why would anyone believe that DuckDuckGo isn't already penetrated?

Exactly, I think what we might be needing is a non-US (perhaps Iceland or NZ) based alternative. The moment, duckduckgo becomes relevant enough (i.e significant traffic) then is game over IMO.

Ask Kim Dotcom about how well NZ's liberal laws worked out in practice when the US copyright police showed up asking the local cops to wildly overstep their legal authority…

I mean _seriously?_ Helicopters, silenced assault rifles, security dogs, and 72 cops - sent in against someone accused of _copyright infringement?_ And then a Hollywood showreel of the raid gets produced and publicised?

I _like_ New Zealand, they talk the talk, but when it comes to walking the walk - they're lead around by the nose to do whatever the US wants.

Post reply on HN