Live data from Hacker News

DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

searchenginewatch.com

21–30 of 128 posts

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#21

At the end of the article the author insinuates that the Bing ad partnership might lend itself to tracking users or otherwise making the service less secure and anonymous. Is that possible?

IIRC it depends how the ads are routed. The ads could be piped through duckduckgo so Bing only receives searches to return contextual ads for but has no knowledge of the IPs for each search. Duckduckgo then embeds the ads in the search page and returns it to the searcher, then forgets their IP.

On the other hand if there's just a bit of javascript on the search page that says "Tell bing to put ads on this page using the search bar text" then bing would be able to link the search to an IP and you lose your privacy.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#22
post #20
post #19

I am one of those that have changed to DDG after the scandals. So far it feels like I find my results as quickly as I used to do with Google. One nice feature that I just found: under the Privacy tab at https://duckduckgo.com/settings you can change so that the query is sent as a HTTP POST parameter instead of a GET parameter. That way your ISP can't find out what you are searching for (assuming you have https enable…

It shouldn't matter if you are using GET or POST - how would your ISP find out anything about your request if you are using HTTPS?

You are correct, I was drawing the wrong conclusions from how the HTTP headers are sent. It doesn't affect how much info the ISP gets. However, POST parameters are somewhat more secure, since less info about your query is cached by your browser: http://stackoverflow.com/questions/198462/is-either-get-or-p...

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#23
post #18

Google's strategy is to profit from advertising. It fundamentally benefits from knowing as much about its users as possible. Every tactic it has will always support that strategy or it will risk failure. You can tell its strategy motivates it toward evil (its term, not mine), because its slogan is "Don't be evil." It chose that slogan because it risks being evil, in its own terms. It doesn't need a slogan like "Don't…

Whatever you feel about Google's actions, there's no need to concoct elaborate stories around and speculative theories about the origin of Google's 'don't be evil' slogan. You can look it up.

According to http://blogoscoped.com/archive/2007-07-16-n55.html, the 'don't be evil' slogan came from Paul Buchheit, who was brand-new to the company when he proposed it at a corporate-values brainstorming meeting. This meeting was before Google became an advertising company, and Paul intended the slogan to be funny, and a jab at other companies.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#24
post #18

Google's strategy is to profit from advertising. It fundamentally benefits from knowing as much about its users as possible. Every tactic it has will always support that strategy or it will risk failure. You can tell its strategy motivates it toward evil (its term, not mine), because its slogan is "Don't be evil." It chose that slogan because it risks being evil, in its own terms. It doesn't need a slogan like "Don't…

Okay, but what's the end point? What's the "evil" destination for Google? When do we know Google has arrived there, if you say reaching that point is inevitable?

I think that even if Google themselves never do anything "evil", by any definition, there still remains this problem of "having very important user data" that you don't want to fall "in the wrong hands". The more data it has about the users, the more other, external, "wrong hands", will want it for reasons other than just to sell you advertising.

Unfortunately, those "wrong hands" will most likely be the government, and not just some hackers or other companies, and Google is relatively powerless against them, if they really want all the users' data.

This is why I think that if Google really cared about us, they'd do their best to at least give the users the option to have their data protected even if it falls into those "wrong hands". We need Google to implement some real encryption and decentralization in its services.

If Google really is powerless against the government, then they should leave it up to us to deal with the government, when that moment arrives, but help make it easy for everyone to protect that data.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#26
post #22
post #20

Earlier quoted context omitted.

It shouldn't matter if you are using GET or POST - how would your ISP find out anything about your request if you are using HTTPS?

You are correct, I was drawing the wrong conclusions from how the HTTP headers are sent. It doesn't affect how much info the ISP gets. However, POST parameters are somewhat more secure, since less info about your query is cached by your browser: http://stackoverflow.com/questions/198462/is-either-get-or-p...

POST parameters also usually won't show up in logs, unlike GET parameters.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#28
post #16
post #5

Earlier quoted context omitted.

DDG logs very litte information...so while NSA can subpoena DDG, there's no data to get. Developers should read "Playing chicken with cat.jpg" [1] which was a response from cperciva [2] to the 37 Signals privacy blunder. It was discussed quite a bit on HN [3] and for me it was a perspective-changing read on privacy. [1] http://www.daemonology.net/blog/2012-01-19-playing-chicken-w... [2] https://news.ycombinator.com/u…

Why bother asking DDG itself when traffic can be intercepted and logged at their ISP?

IIRC HTTPS would encrypt your data from your ISP.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#29
post #4
post #3

If NSA could subpoena Google, they can (and probably do) do the same with DDG. Not that I don't wish them success, but PRISM is not the right reason to switch search engine to them.

If I recall correctly, DDG claims not to keep a record of your searches, so a subpoena would not provide anyone with much information.

Isn't DDG just a search engine aggregator? If they weren't relying on 3rd party search engines, which do record log searches, they'd then probably have to implement a diminished search themselves. A search implementation which I imagine would be severely hampered by a lack of logs.

I don't really see how their model is sustainable at scale.

Re: DuckDuckGo Sees Record Traffic After NSA PRISM Scandal

#30
post #19

I am one of those that have changed to DDG after the scandals. So far it feels like I find my results as quickly as I used to do with Google. One nice feature that I just found: under the Privacy tab at https://duckduckgo.com/settings you can change so that the query is sent as a HTTP POST parameter instead of a GET parameter. That way your ISP can't find out what you are searching for (assuming you have https enable…

I badly want numbers for search results on ddg.

Load 100 results at a time.

Post reply on HN