Live data from Hacker News

DuckDuckGo XSS vulnerability

twitter.com

11–20 of 25 posts

Re: DuckDuckGo XSS vulnerability

#11
We are working on further fixing this issue. We require an open proxy in some form to protect our users' privacy, though it should be more locked down and more obvious it is a proxy.

Re: DuckDuckGo XSS vulnerability

#12
post #11

We are working on further fixing this issue. We require an open proxy in some form to protect our users' privacy, though it should be more locked down and more obvious it is a proxy.

> We require an open proxy in some form to protect our users' privacy

Which feature relies on this?

Re: DuckDuckGo XSS vulnerability

#13
post #11

We are working on further fixing this issue. We require an open proxy in some form to protect our users' privacy, though it should be more locked down and more obvious it is a proxy.

> We require an open proxy in some form to protect our users' privacy Which feature relies on this?

Currently all the features that showcase third-party content on DuckDuckGo, the biggest being image and audio instant answers.

Re: DuckDuckGo XSS vulnerability

#15
post #13

Earlier quoted context omitted.

> We require an open proxy in some form to protect our users' privacy Which feature relies on this?

Currently all the features that showcase third-party content on DuckDuckGo, the biggest being image and audio instant answers.

Thanks for the update and follow-up answers.

Could you comment on the "Reported in March 2017, emailed them 9 times about the issue since then. Still unfixed as of now." claim, as it seems imperative to the discussion?

Is there something that can be improved here? Perhaps that inbox not as actively monitored as it could be?

Re: DuckDuckGo XSS vulnerability

#16

Thank you, just the push I've been needing. As of this moment, I'm off to ixquick/startpage, which for one thing doesn't require me to go all laid-back and inclusive on the JavaScript, and which for another has those nifty proxy-links.

If you just want a search engine without Javascript try https://duckduckgo.com/html

Adding to Firefox is easy via https://addons.mozilla.org/en-US/firefox/addon/duckduckgo-ht...

Re: DuckDuckGo XSS vulnerability

#17
post #13

Earlier quoted context omitted.

> We require an open proxy in some form to protect our users' privacy Which feature relies on this?

Currently all the features that showcase third-party content on DuckDuckGo, the biggest being image and audio instant answers.

Content-Type whitelist, CSP, and a separate domain for proxying please? I don’t feel safe using DuckDuckGo now.

Re: DuckDuckGo XSS vulnerability

#18
post #13

Earlier quoted context omitted.

Currently all the features that showcase third-party content on DuckDuckGo, the biggest being image and audio instant answers.

Content-Type whitelist, CSP, and a separate domain for proxying please? I don’t feel safe using DuckDuckGo now.

CSP has already been rolled out and we're working on another domain now; we will do a proxy.duckduckgo.com in the interim.

Re: DuckDuckGo XSS vulnerability

#19
post #15
post #13

Earlier quoted context omitted.

Currently all the features that showcase third-party content on DuckDuckGo, the biggest being image and audio instant answers.

Thanks for the update and follow-up answers. Could you comment on the "Reported in March 2017, emailed them 9 times about the issue since then. Still unfixed as of now." claim, as it seems imperative to the discussion? Is there something that can be improved here? Perhaps that inbox not as actively monitored as it could be?

We have real-time monitoring for that inbox and a 24/7 ops team. We have corresponded many times about this issue, and have made many changes over that period.

It's not as simple as just shutting down the open proxy because we need an open proxy to adequately protect users' privacy on our site. It just needs to be more locked down and more obvious it is a proxy, which we are doing right now (half done already).

Re: DuckDuckGo XSS vulnerability

#20
Can someone explain what I'm seeing? As far as I can tell, both those links really do leave me on DDG webpages. The only requests according to firebug are to duckduckgo.com. What am I missing (or has this since been fixed)?
Post reply on HN