Live data from Hacker News

PRISM fears give private search engine DuckDuckGo its best week ever

venturebeat.com

131–140 of 213 posts

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#131
post #94

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

I might bet my life on HTTPS depending on what my alternate choices are. I'm loathe to bet my life on anything, though.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#133

Earlier quoted context omitted.

Email is unencrypted in transit.

That's not universally true - there's a remarkable amount of TLS/SSL encrypted email-in-transit, either via STARTTLS ESMTP commands or SSL over port 465 (and 993/995 for IPAM and POP3). I don't think there's a way to guarantee your mail always travels over TLS/SSL secured connections, but I suspect more of it does than you think.

There's a straightforward way to make sure your email is always encrypted in transit: encrypt it before you send. No promises about making sure your email can always be read by the recipient, though...

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#134
One thing that I prefer about DDG is that it doesn't try to guess what language I want to search in other than by my input. It is ridiculous that google forces me to go through worse results based solely on my location, it shouldn't matter where you are from.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#135
post #89

Earlier quoted context omitted.

Email is unencrypted in transit.

What does that have to do with using a search engine? I'm pretty sure you aren't emailing them your queries.

Maybe that's all Stallman's queries

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#136

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

While I haven't heard explicitly about Amazon being part of PRISM, the duckduckgo ips all point to amazon's EC2 platform.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#137
post #122

Earlier quoted context omitted.

Why do you trust any binaries you've got? Where did your first-use/bootstrapping compiler come from? And even if you wrote your own OS and compiler from the ground up - who wrote your BIOS? Your network card firmware? Your disk controller software? Your CPU microcode? We _all_ abdicate our trust-chain _somewhere_

This is why it's important to look at PRISM as a political issue and not merely a technical one, like I see a ton of people doing now. The best solution to government spying isn't to tell everyone to use Linux and DuckDuckGo, it's to change the spying itself.

Indeed - but the political changes (if we get them at all) will take time - time probably measured in years or political terms.

The "merely technical" solutions are going to be important in the meantime. Duckduckgo, encfs, Tarsnap, GPG, Tor, ForceSSL - things like that will (probably) help in the meantime (especially if we can help convince "regular users" to use them), as will encouraging places like DDG to implement TLS cyphers that use forward secrecy.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#138

Earlier quoted context omitted.

This is most likely that Google has more user behavior data than DDG. If enough people use DDG and click on the StackExchange link for that query (or similar queries), DDG will be able to get that to the top. On the other hand, did DDG just use Bing API, and only Blekko crawls the web? Or do I get my search engines mixed up?

That's correct, blekko does have our own multi-billion page crawl and index. And we're private, too. Every web search engine depends on one of these indexes: google, bing, blekko, yandex, baidu.

Don't forget Gigablast, Procog, Yioop and Samuru which also have their own crawled index.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#139
post #94

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

OTOH, if they can get a CA - any CA - to cooperate, they can MITM anyone without having to break SSL.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#140
post #94

Earlier quoted context omitted.

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

OTOH, if they can get a CA - any CA - to cooperate, they can MITM anyone without having to break SSL.

Only for targeted traffic though. They can't record, go back, and break it.
Post reply on HN