Live data from Hacker News

Privacy Pass Authentication for Kagi Search

blog.kagi.com

251–260 of 359 posts

Re: Privacy Pass Authentication for Kagi Search

#252

Seeing as I'm not getting any traction in the fediverse ( https://tenforward.social/@aspensmonster/113999217587309328 ), maybe I can ask here instead. ================================= From their blog: >As standardized in [2 - 4], the Privacy Pass protocol is able to accommodate many “architectures.” Our deployment model follows the original architecture presented by Davidson et al. [1], called “Shared Origin, Attest…

This would definitely seem like a big concern if you were just looking at the RFC, but the key here is that Kagi's system has a different set of security/privacy/functional requirements and therefore the issues mentioned in the RFC do not necessarily apply. In the RFC's architecture, the request flow is like so: 1. CLIENT sends anonymous request to ORIGIN 2. ORIGIN sends token challenge to CLIENT 3. CLIENT uses its i…

>3. CLIENT uses it's identity to request token from ISSUER/ATTESTER

The ISSUER and ATTESTER are different roles. As previously quoted, "Clients explicitly trust Attesters to perform attestation correctly and in a way that does not violate their privacy." The RFC is explicit that, when all of the roles are held by the same entity, the attestation should not rely on unique identifiers. But that's exactly what a session cookie is.

>You can see how the ISSUER/ATTESTER can identify the client as the source of the "anonymous request" to the ORIGIN because the ISSUER, ATTESTER and ORIGIN are the same entity, and therefore it can use a timing attack to correlate the request to the ORIGIN (1.) with the request to the ISSUER/ATTESTER (3.).

No timing or spacing attack is needed here. If I have to provide Kagi with a valid session cookie in order to get the tokens, then they already have a unique identifier for me. There is no guarantee that Kagi is not keeping a 1-to-1 mapping of session cookies to ISSUER keypairs, or that Kagi could not, if compelled, establish distinct ISSUER keypairs for specific session cookies.

Re: Privacy Pass Authentication for Kagi Search

#253

I want to pay for Kagi, but it's priced way too high (for me). Would love it if they implemented Purchasing Power Parity (PPP).

problem is that they have small margins because they have to pay a lot for their upstream providers (and those don't care about what region kagi users are from so charge the same)

and they use all of their margin to build a browser because why not

Re: Privacy Pass Authentication for Kagi Search

#254
I still cannot get iOS to reliably use Kagi as my default search engine. I've tried the extension, etc. but nothing works reliably.

It's madness - how is it market fairness when iOS literally forces you to use Google? I know Google is paying Apple to do exactly that, but it's so beyond anti-consumer I can't believe it.

Re: Privacy Pass Authentication for Kagi Search

#255

Earlier quoted context omitted.

With kagi you'll get used to them making the correct choice. It's been stunning how they haven't really had any missteps I wish my kagi t-shit could say the same. Bottom hem unraveled on the second wash, and so it's been consigned to the sleep and yard work shirts. They issued me a coupon for a free shirt as replacement, but it's yet to ship

I think I can finally buy into the Kagi hype now that I've found a sincere negative opinion.

Kagi has its share of issues. The whole shirt thing was a debacle and I wish they'd just sunk the absurd amount of money back into the product. I just often find the criticism from non-users to be disingenuous.

Re: Privacy Pass Authentication for Kagi Search

#256
post #254

I still cannot get iOS to reliably use Kagi as my default search engine. I've tried the extension, etc. but nothing works reliably. It's madness - how is it market fairness when iOS literally forces you to use Google? I know Google is paying Apple to do exactly that, but it's so beyond anti-consumer I can't believe it.

Meanwhile, Google gets hit with the anti-competitive judgment and Apple gets off by way of being more anti-competitive. Wild, isn't it?

Re: Privacy Pass Authentication for Kagi Search

#257
post #217
post #201

Earlier quoted context omitted.

If you can get Kagi to agree to it, definitely write a blog post on their behalf, please.

FWIW, the person you're replying to did write most of the blog post. We work together at Kagi on Privacy Pass.

Oh, interesting. Maybe it's just on mobile, but no authors are rendering on the article for me.

Anywho, the person I replied to seemed to be willing and able to go a technical level deeper than the article, and that's something I'm also interested in reading. It sounds like they'd be allowed :)

Re: Privacy Pass Authentication for Kagi Search

#258
post #21
post #10

The post hints at this, but having a shop where one can buy a privacy pass without an account makes sense. Should support some crypto currency (probably monero), and something like GNU Taler if that technology ever becomes usable.

Kagi accepts bitcoins but Vlad (the founder) mentioned on their forum that so few people use this option that it does not make sense to work on accepting Monero.

Nobody wants to use BTC because of high fees and at this point its less a usable exchange of value than speculative asset. I personally would only ever use and trust a online service advertised as private/anonymous if it actually supported a private and anonymous currency (like some vpns do).

Re: Privacy Pass Authentication for Kagi Search

#259

Neat! It's rare to see that a service you use actually does something that benefits the user rather that itself. An unexpected, but a really pleasant surprise. I wish this extension would integrate better with the browser by automatically understanding the context. That is, if I'm in a "regular" mode it'll use my session, but if I'm in a "private browsing" mode (`browser.extension.inIncognitoContext`) it'll use Priva…

> (I don't use Orion, as there's no GNU/Linux version.) We commenced work on Orion for Linux yesterday.

Any target date for open-sourcing it? :^)

Re: Privacy Pass Authentication for Kagi Search

#260
post #250

Earlier quoted context omitted.

I know I’m just one guy, but lack of Monero support kept me away. This feature looks like it narrows the gap a bit though. Nice work

Don't know a bunch about cryptocurrencies, but couldn't you get the benefits of monero by just converting monero to btc before paying? Are the conversion fees too high?

You can but its not only more effort and increases the price but also reduces privacy and anonymity because you introduce a possible point of tracking with most likely KYC exchanged BTC and a publicly viewable blockchain.
Post reply on HN