Privacy Pass Authentication for Kagi Search
251–260 of 359 posts
Re: Privacy Pass Authentication for Kagi Search
#252Seeing as I'm not getting any traction in the fediverse ( https://tenforward.social/@aspensmonster/113999217587309328 ), maybe I can ask here instead. ================================= From their blog: >As standardized in [2 - 4], the Privacy Pass protocol is able to accommodate many “architectures.” Our deployment model follows the original architecture presented by Davidson et al. [1], called “Shared Origin, Attest…
This would definitely seem like a big concern if you were just looking at the RFC, but the key here is that Kagi's system has a different set of security/privacy/functional requirements and therefore the issues mentioned in the RFC do not necessarily apply. In the RFC's architecture, the request flow is like so: 1. CLIENT sends anonymous request to ORIGIN 2. ORIGIN sends token challenge to CLIENT 3. CLIENT uses its i…
The ISSUER and ATTESTER are different roles. As previously quoted, "Clients explicitly trust Attesters to perform attestation correctly and in a way that does not violate their privacy." The RFC is explicit that, when all of the roles are held by the same entity, the attestation should not rely on unique identifiers. But that's exactly what a session cookie is.
>You can see how the ISSUER/ATTESTER can identify the client as the source of the "anonymous request" to the ORIGIN because the ISSUER, ATTESTER and ORIGIN are the same entity, and therefore it can use a timing attack to correlate the request to the ORIGIN (1.) with the request to the ISSUER/ATTESTER (3.).
No timing or spacing attack is needed here. If I have to provide Kagi with a valid session cookie in order to get the tokens, then they already have a unique identifier for me. There is no guarantee that Kagi is not keeping a 1-to-1 mapping of session cookies to ISSUER keypairs, or that Kagi could not, if compelled, establish distinct ISSUER keypairs for specific session cookies.
Re: Privacy Pass Authentication for Kagi Search
#253I want to pay for Kagi, but it's priced way too high (for me). Would love it if they implemented Purchasing Power Parity (PPP).
problem is that they have small margins because they have to pay a lot for their upstream providers (and those don't care about what region kagi users are from so charge the same)
Re: Privacy Pass Authentication for Kagi Search
#254It's madness - how is it market fairness when iOS literally forces you to use Google? I know Google is paying Apple to do exactly that, but it's so beyond anti-consumer I can't believe it.
Re: Privacy Pass Authentication for Kagi Search
#255Earlier quoted context omitted.
With kagi you'll get used to them making the correct choice. It's been stunning how they haven't really had any missteps I wish my kagi t-shit could say the same. Bottom hem unraveled on the second wash, and so it's been consigned to the sleep and yard work shirts. They issued me a coupon for a free shirt as replacement, but it's yet to ship
I think I can finally buy into the Kagi hype now that I've found a sincere negative opinion.
Re: Privacy Pass Authentication for Kagi Search
#256I still cannot get iOS to reliably use Kagi as my default search engine. I've tried the extension, etc. but nothing works reliably. It's madness - how is it market fairness when iOS literally forces you to use Google? I know Google is paying Apple to do exactly that, but it's so beyond anti-consumer I can't believe it.
Re: Privacy Pass Authentication for Kagi Search
#257Earlier quoted context omitted.
If you can get Kagi to agree to it, definitely write a blog post on their behalf, please.
FWIW, the person you're replying to did write most of the blog post. We work together at Kagi on Privacy Pass.
Anywho, the person I replied to seemed to be willing and able to go a technical level deeper than the article, and that's something I'm also interested in reading. It sounds like they'd be allowed :)
Re: Privacy Pass Authentication for Kagi Search
#258The post hints at this, but having a shop where one can buy a privacy pass without an account makes sense. Should support some crypto currency (probably monero), and something like GNU Taler if that technology ever becomes usable.
Kagi accepts bitcoins but Vlad (the founder) mentioned on their forum that so few people use this option that it does not make sense to work on accepting Monero.
Re: Privacy Pass Authentication for Kagi Search
#259Neat! It's rare to see that a service you use actually does something that benefits the user rather that itself. An unexpected, but a really pleasant surprise. I wish this extension would integrate better with the browser by automatically understanding the context. That is, if I'm in a "regular" mode it'll use my session, but if I'm in a "private browsing" mode (`browser.extension.inIncognitoContext`) it'll use Priva…
> (I don't use Orion, as there's no GNU/Linux version.) We commenced work on Orion for Linux yesterday.
Re: Privacy Pass Authentication for Kagi Search
#260Earlier quoted context omitted.
I know I’m just one guy, but lack of Monero support kept me away. This feature looks like it narrows the gap a bit though. Nice work
Don't know a bunch about cryptocurrencies, but couldn't you get the benefits of monero by just converting monero to btc before paying? Are the conversion fees too high?