Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

21–30 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#21
post #7

Recently I have been using the free and open source Searx more and more (admittedly mostly using the !searx shortcut from DDG). Results seem better than DDG sometimes. Would be interesting to try and host my own instance or write something that picks a random public instance. https://asciimoo.github.io/searx/

i saw there's an Installation page but do you know of an easy step by step tutorial for setting this up? Perhaps with a low cost recommended host, etc.?

There's a Dockerfile, just spin that up. (Or, if needed, find a brief step-by-step on running a docker container, because that's all there is to getting searx running.)

Re: Duck Duck Go: Illusion of Privacy (2013)

#22
post #16

Earlier quoted context omitted.

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capabl…

Solving the problem with technology is 1000000 times easier than solving it from the "social" side.

Is it? For who?

Do you think people's data would be more secure at the border if

- You kernal-hacked iOS so that it booted into a vanilla account upon entry of a certain passcode, and encouraged people to install your hack from GitHub, potentially borking their phones

- People couldn't be compelled (or face being denied entry) to allow search of their electronic devices

?

What about trying to do everything via a VPN and spoofed UA strings vs. PII being banned from sale, heavily taxed, or a meaningful opt-out existing? Or even just DNT having a legal basis?

Re: Duck Duck Go: Illusion of Privacy (2013)

#24
post #13

Privacy requires full transparency. We're is documented with what foss software ddg works and where can I find trusted audit reports?

Even if they were completely open source how would you verify that they are using the same software on their servers? That the hardware is not compromised? Audit reports? How trustworthy are they if Symantec was able to provide good reports for such a long time for their certificate issuance when things were clearly not ok.

For example if they used AGPL software, it would be much harder for them to cheat. But you can never get 100% confidence.

Re: Duck Duck Go: Illusion of Privacy (2013)

#26
post #20

Earlier quoted context omitted.

Protection from the Nation State Actors cannot come from companies. One must implement protections on one's own client-side. Proper encryption always. Tor when needed. Software and, where possible, hardware only from trusted sources.

Even then the concept of "trusted sources" is a dubious one. A source only needs to be trusted until it sells you down the river.

So Equifax were good guys until they ditched all out data?

Re: Duck Duck Go: Illusion of Privacy (2013)

#27
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

From previous discussions I've learned that USA companies are the only ones that actually are protected from the USA government.

So feel free to build a company in Sweden, but the US is actually legally permitted to wiretap the crap out of it.

Re: Duck Duck Go: Illusion of Privacy (2013)

#28
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

I've argued here at HN before that I don't think this is a technological problem, but a social one. There is nothing that stops a powerful enough actor from breaking encryption with a rubber hose, except for a strong stigma against that kind of behavior. We need to give digital privacy the same social protection. The other problem with making a purely technical solution is that you leave out people who are not capabl…

I agree. The biggest problem in this age is having a strong encryption that is user-friendly. The common wisdom says it's impossible to combine the two. I disagree with it but I don't have the time to try and work in the area, nor am I an expert. IMO it's a good cause to work on anyhow.

Furthermore, spies aren't stopped by social stigma. Even if the whole planet agrees in one voice wiretapping shouldn't be done (never gonna happen) the spies can always deny that they're spying. It's not like any of us can actually prove that any agency is indeed wiretapping.

Morality is, in the technical sense, optional. It cannot be enforced. Thus it's unreliable.

Re: Duck Duck Go: Illusion of Privacy (2013)

#29
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

From previous discussions I've learned that USA companies are the only ones that actually are protected from the USA government. So feel free to build a company in Sweden, but the US is actually legally permitted to wiretap the crap out of it.

From all the leaks we've seen in the last 4 years, the three lett3r agenc1es weren't deterred by the laws at all, wouldn't you agree?

Re: Duck Duck Go: Illusion of Privacy (2013)

#30
post #20

Earlier quoted context omitted.

Protection from the Nation State Actors cannot come from companies. One must implement protections on one's own client-side. Proper encryption always. Tor when needed. Software and, where possible, hardware only from trusted sources.

Even then the concept of "trusted sources" is a dubious one. A source only needs to be trusted until it sells you down the river.

We need more than "trust". We need open software and open hardware.
Post reply on HN