Live data from Hacker News

Privacy Pass Authentication for Kagi Search

blog.kagi.com

171–180 of 359 posts

Re: Privacy Pass Authentication for Kagi Search

#171

In general I am a very happy Kagi subscriber, but I have noticed in the past month or so that sometimes my searches (via the Safari extension) just hang. Navigating it kagi.com also hangs. When I'm in a rush this forces me to fall back to Google which often doesn't provide good results for my queries, which is unfortunate It generally resolves itself in under a minute, but it is still a mildly irritating availability…

Just as a data point, I haven't seen this in Safari on desktop or mobile, or in Edge (on my Windows work machine).

Re: Privacy Pass Authentication for Kagi Search

#172

Earlier quoted context omitted.

Unlimited is only $10, more than worth it for me.

I will try it for more technical queries, but the results seem to be worse than Google/DDG. The reverse image search sucks and has never returned a single result for me. I suppose the advantage is that it whitelists/blacklists against spam, but it frequently comes up empty handed. So maybe it needs to crawl/scrape the web deeper or it needs a better search algorithm or trust model. I could probably get better results…

Heh, that's one of the more aggressive "how hard can it be?!" that I've seen in a while

I invite you to look at the number of threads of people complaining about Cloudflare locking their perfectly normal browser out of a stupid amount of the Internet and then carefully consider how you would circumvent those anti-bot controls

Re: Privacy Pass Authentication for Kagi Search

#173
post #118

Earlier quoted context omitted.

Government's power over companies does not negate cryptographic privacy protections. For example, one criminal who used ProtonMail got caught because ProtonMail handed over their recovery GMail address to the law enforcement after they were compelled[1]. However, that means end-to-end encryption worked: that was the only thing they could hand over. I think the same principle applies here. [1] https://www.techradar.co…

The government forces companies to backdoor their systems and use compromised implementations of what would otherwise be private and secure systems (see for example https://en.wikipedia.org/wiki/Lavabit ). It's also worth noting that the only thing preventing your searches being linked to your account via IP address and browser fingerprinting is to use Tor which conveniently will also not protect your from the US gov…

The difference is cost. Pervasive and unhindered surveillance is way cheaper than coordinating an individual to be targeted through court orders and all the bureaucracy and potential legal battles that come with it. That’s why EU/UK is trying to coerce Apple to disable end to end encryption[1]. If it hadn’t made any difference, we wouldn’t be seeing any complaints from governments.

[1] https://techinformed.com/uk-government-orders-apple-to-hand-...

Re: Privacy Pass Authentication for Kagi Search

#174

Neat! It's rare to see that a service you use actually does something that benefits the user rather that itself. An unexpected, but a really pleasant surprise. I wish this extension would integrate better with the browser by automatically understanding the context. That is, if I'm in a "regular" mode it'll use my session, but if I'm in a "private browsing" mode (`browser.extension.inIncognitoContext`) it'll use Priva…

> It's rare to see that a service you use actually does something that benefits the user rather that itself The reason it's become so rare is most companies in this space (heck tons of tech companies period) have used a business model of offering a thing to one group of users and then turning around and selling the results of that thing to another group of users, where the latter group is the one actually driving you…

They would be a good steward of pinboard.in if it were for sale / recovery.

Re: Privacy Pass Authentication for Kagi Search

#175

Trying to understand Privacy Pass here. My understanding is, it's analogous to writing a note to your manager. That note is a random number written in ink your manager can't actually read; all they can do with that note is sign it. They ask God (used here to represent math itself) how to sign this note, and God gives them a unique signature that also theoretically cannot be used to calculate the number that's written…

> They ask God (used here to represent math itself)

Thank you so much, I am 100% stealing this

Re: Privacy Pass Authentication for Kagi Search

#176
post #21

Earlier quoted context omitted.

Kagi accepts bitcoins but Vlad (the founder) mentioned on their forum that so few people use this option that it does not make sense to work on accepting Monero.

(vlad here) Rather, we are opportunistic about it and we want to focus on things that make impact (which most of the time is search, not billing). If there is enough demand, we will work on Monero support - and yes I agree, buying privacy pass tokens, without even needing an account, is one of those super-cool use cases.

[deleted]

Re: Privacy Pass Authentication for Kagi Search

#178
post #140

Earlier quoted context omitted.

This is one of the best explanations I've seen for this phenomenon. If you try to build a network of paid users, you lose because you'll be run over by 'free' competitors monetizing indirectly.

Playing devil's advocate... Yeah, the ad supported model has its problems, but it also makes the internet way more accessible. If we think about it, companies and people with more money are basically subsidizing these services for everyone else. They're the ones seeing the ads that keeps the lights on for users who can't afford to pay. If everything was subscription only, a ton of people like students, low income fam…

> Yeah, the ad supported model has its problems, but it also makes the internet way more accessible. If we think about it, companies and people with more money are basically subsidizing these services for everyone else. They're the ones seeing the ads that keeps the lights on for users who can't afford to pay.

The problem (other than the obvious privacy and noise issues) is that it's not a neutral subsidy. It introduces a lot of biases.

Since advertisers are subsidizing the platform, they tilt the content toward things they want and away from messages they don't. Messages that criticize advertisers products (which include things like governments and political ideologies since they are advertisers) are de-emphasized and marginalized.

Since impressions / clicks / eyeballs are the goal, an inherent bias is introduced toward emotionally triggering and/or addictive or hypnotic content. The reason social media for example is so divisive and negative is that this keeps people engaged by triggering simple powerful emotions.

Re: Privacy Pass Authentication for Kagi Search

#179
post #163

Earlier quoted context omitted.

Playing devil's advocate... Yeah, the ad supported model has its problems, but it also makes the internet way more accessible. If we think about it, companies and people with more money are basically subsidizing these services for everyone else. They're the ones seeing the ads that keeps the lights on for users who can't afford to pay. If everything was subscription only, a ton of people like students, low income fam…

Playing the... angel's advocate... There's no reason why a subscription model could not also be used to subsidize people who can not pay, other than that companies are structured to extract as much as possible (by law, if they are public). There are good network effect arguments about why this strategy can be effective, not simply 'altruistic.' Ads simply make the extraction happen across the board, except that the a…

What's the mechanism by which a private company does e.g. income verification to figure out who gets subsidy or not?

Or would the idea be to only subsidize students and not poor adults?

It would be one thing if we had like a national "verify I'm on SNAP or equivalent API"

Re: Privacy Pass Authentication for Kagi Search

#180

I'm not affiliated with the Tor Project organization, but I have some questions. From Tor docs [0]: > Add-ons, extensions, and plugins are components that can be added to web browsers to give them new features. Tor Browser comes with one add-on installed: NoScript. You should not install any additional add-ons on Tor Browser because that can compromise some of its privacy features. How does Kagi square this with Priv…

I sat down on my desktop to take a closer look at how Kagi implemented this. It turns out that the privacy pass extension isn't the one implemented by CloudFlare (and rejected by Tor), but a new extension called Kagi Privacy Pass.

Ok, let's look at the source.

    curl -L https://addons.mozilla.org/firefox/downloads/file/4436183/kagi_privacy_pass-1.0.2.xpi > /tmp/extension.xpi
    unzip /tmp/extension.xpi -d /tmp/extension
    cd /tmp/extension

Alright, here's some nice, clean, easy-to-read Javascript. Nice! Wait, what's that?

    // ./scripts/privacypass.js
    /*
     * Privacy Pass protocol implementation
     */
    
    import init, * as kagippjs from "./kagippjs/kagippjs.js";
    ...
    // load WASM for Privacy Pass core library
    await init();
I opened ./kagippjs/kagippjs.js and was, of course, greeted with a WASM binary.

I personally would not install unknown WASM blobs in Tor browser. Source and reproducible build, please!

Let's continue.

    // get WWW-Authenticate HTTP header value
    let origin_wwwa_value = "";
    const endpoint = onion ? ONION_WWWA_ENDPOINT : WWWA_ENDPOINT;
    try {
      const resp = await fetch(endpoint, { method: "GET", headers: { 'X-Kagi-PrivacyPass-Client': 'true' } });
      origin_wwwa_value = resp.headers.get("WWW-Authenticate");
    } catch (ex) {
      if (onion) {
        // this will signal that WWWA could not fetch via .onion
        // the extension will then try normally.
        // if the failure is due to not being on Tor, this is the right path
        // if the failure is due to being on Tor but offline, then trying to fetch from kagi.com
        //   won't deanonymise anyway, and will result in the "are you online?" error message, also the right path
        return origin_wwwa_value;
      }
      throw FETCH_FAILED_ERROR;
    }

What?? If the Onion isn't reachable, you make a request to the clearnet site? That will, in fact, deanonymize you (although I don't know if Tor browser will Torify `fetch` calls made in extensions). You don't want Tor browser making clearnet requests just because it couldn't reach the .onion! What if the request times out while it's bouncing between the 6 relays in the onion circuit? Happens all the time.
Post reply on HN