Live data from Hacker News

PRISM fears give private search engine DuckDuckGo its best week ever

venturebeat.com

141–150 of 213 posts

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#141

Earlier quoted context omitted.

That's not universally true - there's a remarkable amount of TLS/SSL encrypted email-in-transit, either via STARTTLS ESMTP commands or SSL over port 465 (and 993/995 for IPAM and POP3). I don't think there's a way to guarantee your mail always travels over TLS/SSL secured connections, but I suspect more of it does than you think.

There's a straightforward way to make sure your email is always encrypted in transit: encrypt it before you send. No promises about making sure your email can always be read by the recipient, though...

And here's the problem. Email needs to be able to be read by the recipient, so until a significant portion of email recipients can handle encrypted mail - the NSA doesn't need to attack my encrypted email storage, because enough of my correspondence ends up in cleartext in gmail/hotmail/yahoo et al.

This is a hard one to solve. GPGmail seems to get broken with every Mac Mail.app release. Vast numbers of people rely on webmail - which'd need server-side or in-browser GPG decryption. My Mom's not going to use command like gpg tools. How the hell do we bootstrap our way up to ubiquitous encrypted email?

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#142

Earlier quoted context omitted.

Why would anyone believe his own computer isn't already penetrated?

Because I am running GNU/Linux.

How do go about determining whether or not you're pwned?

Asking for a friend.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#143

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

I know this is paranoid, but I keep coming back to this post that hit HN a few days ago: http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html

When you combine that with the beam splitter logo, things get a bit scary.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#144

I like DDG, but has it ever mentioned how this TRACKING data is used? http://duckduckgo.com/l/?kh=-1&uddg=http%3A%2F%2Fwww.dmv.org... (every time you click on a search result you actually click on a link like this,which redirects you to the actual page) Is it just for pagerank?

It might be used internally for additional ranking signals. But the privacy policy states it can never be tied back to you as an individual so nothing to worry about.

From memory the main reason they do this is to allow downstream websites to determine if a user was referred to them by DuckDuckGo without the actual search term. IE you know they came from DDG but with no leakage.

I run searchcode.com (which provides a lot of the code doco and sample results) and since this was done I can now determine how much referral traffic actually comes from DDG but have no idea what you were searching for when you click through.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#145
post #94

Earlier quoted context omitted.

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

OTOH, if they can get a CA - any CA - to cooperate, they can MITM anyone without having to break SSL.

Not without someone noticing. Some sites have pinned certs in Chrome, which would stop this, and even without that you would expect some knowledgeable techie at Facebook or Github or something to be using their home laptop and say, "Wait a sec, this isn't my company's public cert!"

Not having seen any blog posts screaming, "OMG, my site is being hijacked wholesale," I can only assume that the NSA isn't doing this (or has managed to squelch by legal order every single person privy to the real cert at MITM'ed sites, which is absurd and would beg the question, why not obtain the private key from these people in a similar way?).

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#146
post #94

It's not safe to assume the NSA doesn't log DDG searches. Look at the PRISM logo - it's a beam splitter. Read the slide, look at the "Upstream" portion. http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the... They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the s…

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

Thanks for pointing this out. I'm looking into updating our ciphers very soon.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#147
post #14
post #7

Here is a non-US-based alternative: https://startpage.com

Just because they say they don't collect your info, it doesn't mean that google doesn't get it. Look at the source of a search page and you'll notice that they include scripts directly from google.com...

Google assuredly gets info, just not from the user. There aren't any google requests from Firebug's net tab, either, so perhaps you are mistaken.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#148
post #132

Earlier quoted context omitted.

Plaintext, though. I wish DDG over XMPP would do OTR.

Isn't OTR usually don client-side?

I guess he was referring to the ddg bot answering your questions over XMPP.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#149
post #146
post #94

Earlier quoted context omitted.

"How much are you willing to bet they can't decrypt https?" I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack. However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that t…

Thanks for pointing this out. I'm looking into updating our ciphers very soon.

Heh, I was wondering if that might get noticed. :)

On the one hand, don't take my word for it; I also have not found anyone I trust who has verified my explanation directly. On the other hand, I did do my best to read the primary sources very carefully, both for what they say and what they don't say, and I was confident enough to implement more conventionally strong ciphers on the services I'm responsible for, so my money is where my metaphorical mouth is.

Re: PRISM fears give private search engine DuckDuckGo its best week ever

#150

I like DDG, but has it ever mentioned how this TRACKING data is used? http://duckduckgo.com/l/?kh=-1&uddg=http%3A%2F%2Fwww.dmv.org... (every time you click on a search result you actually click on a link like this,which redirects you to the actual page) Is it just for pagerank?

You can turn that on/off in the settings dialog, essentially it is meant to hide the search queries from the target website.
Post reply on HN