Live data from Hacker News

DuckDuckGo XSS vulnerability

twitter.com

21–25 of 25 posts

Re: DuckDuckGo XSS vulnerability

#21

Wow. "Reported in March 2017, emailed them 9 times about the issue since then. Still unfixed as of now."

We have corresponded many times about this issue, and have made many changes over that period.

It's not as simple as just shutting down the open proxy because we need an open proxy to adequately protect users' privacy on our site, e.g. for image search. It just needs to be more locked down and more obvious it is a proxy, which we are doing right now (half done already -- CSP rolled out fully, new domains in process).

Re: DuckDuckGo XSS vulnerability

#22
post #20

Can someone explain what I'm seeing? As far as I can tell, both those links really do leave me on DDG webpages. The only requests according to firebug are to duckduckgo.com. What am I missing (or has this since been fixed)?

It has since been fixed.

Re: DuckDuckGo XSS vulnerability

#23

Thank you, just the push I've been needing. As of this moment, I'm off to ixquick/startpage, which for one thing doesn't require me to go all laid-back and inclusive on the JavaScript, and which for another has those nifty proxy-links.

If you just want a search engine without Javascript try https://duckduckgo.com/html Adding to Firefox is easy via https://addons.mozilla.org/en-US/firefox/addon/duckduckgo-ht...

That's one trick I had somehow missed. Mind you, that's extremely barebones, not as much as a link to any image-search or options.

Re: DuckDuckGo XSS vulnerability

#25
post #21

Wow. "Reported in March 2017, emailed them 9 times about the issue since then. Still unfixed as of now."

We have corresponded many times about this issue, and have made many changes over that period. It's not as simple as just shutting down the open proxy because we need an open proxy to adequately protect users' privacy on our site, e.g. for image search. It just needs to be more locked down and more obvious it is a proxy, which we are doing right now (half done already -- CSP rolled out fully, new domains in process).

+ 1
Post reply on HN