Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

61–70 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#61
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are probably one of the most targeted, especially by state actors such as china and russia.

Re: Duck Duck Go: Illusion of Privacy (2013)

#62
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are…

>When was the last time Google leaked your data[?]

According to the State of California Department of Justice [0], the last publicly acknowledged data breach from Google was March 9th, 2017. Before that it was August 10th, 2016, and before that March 29th, 2016.

[0] https://www.oag.ca.gov/privacy/databreach/list

Re: Duck Duck Go: Illusion of Privacy (2013)

#63
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are…

All signs point to their active cooperation, and indeed their overlap with, the intelligence sector.

Re: Duck Duck Go: Illusion of Privacy (2013)

#64
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are…

I'd say every single company sitting on billions of assets are on the target list. Facebook, Apple, Microsoft, Google, Amazon, Uber, everyone (although Microsoft is the least attacked here). But the illusion here is we only see the big guys, we rarely question the smaller guys, unless someone publishes a CVE or publish a disclosure.

Many users are paranoid about ToS and how companies (esp the big guys) make money either by learning your behaviors (search preference, sites you visited) or selling your data to a partner (Foursquare, although they claim to only sell location data which are anonymous). We have a blind-trust with service providers. We let service providers to collect everything about ourselves, but internally they can decide whether to discard "sensitive data" early on or not during data processing (but web logs would have the trace).

Has anyone every inspect the traffic, or reverse the API in (e.g. Fitbit?) What about file sharing companies? Are they storing your data in a secure way and without reading what's in your file? What about sites that let you compare prices across multiple stores? What about medtech startups? What about when the company is acquired?

Because the giants are more eye-catching, we don't see the smaller guys; but we are willing to give away sensitive and private data to the smaller guys because? If the argument is "well the big guys should have known better and have more resources to do the right thing", then I argue that by 2017 the new startups are doing the right things (not making the same well-known security flaws for example). I have doubt; I doubt many achieve 50% of what is on the imaginary checklist. The claim "we build MVP" is the equivalent of the big guys saying "we know what we are doing, don't worry."

No, we don't know better. No, your MVP should be secure enough so users can trust you. I almost never try a newly launched service because I really don't want to be a lab rat. I am sorry if that sounds cynical, but I don't trust myself doing everything right. If you let me choose between a new file sharing startup vs others, I'd go with either Dropbox, Google Drive or OneDrive (FWIW, Google is replacing Drive with a new service). Why? Because if the big guy is compromised, well, shit, thousands or millions will be affected. The least cynical version is, well, they are too big to do stupid things (of course not true in reality).

Our biases create illusions.

Re: Duck Duck Go: Illusion of Privacy (2013)

#65

Earlier quoted context omitted.

I don't get why Google is always singled out either. When was the last time Google leaked your data. As you said, very few actors can protect your data from the NSA, so the next best thing is to have it protected from hackers and leaks. Every other company out there keeps on getting hit left and right, but for their size, Google is only of the only company who has never messed up with user data, and you know they are…

>When was the last time Google leaked your data[?] According to the State of California Department of Justice [0], the last publicly acknowledged data breach from Google was March 9th, 2017. Before that it was August 10th, 2016, and before that March 29th, 2016. [0] https://www.oag.ca.gov/privacy/databreach/list

According to the notification letters on that site, those three incidents all involve Google employees' information being leaked by third parties, not Google leaking users' data.

Here's a quote from one of them:

"We recently learned that certain hotel reservations made for Google business travel were among the many reservations affected by a security incident impacting a third-party provider’s electronic reservation system that serves thousands of travel agencies and hotels. This did not affect Google’s systems. However, this incident impacted one of the travel providers used by Googlers, Carlson Wagonlit Travel (CWT)."

Re: Duck Duck Go: Illusion of Privacy (2013)

#66
post #39
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

If I were a conspiracy theorist, I'd think there was something nefarious going on when I see articles like this. What if the intended result is not actually browbeating DDG but, rather, making people think that DDG is no better than Google in the privacy arena so why invest the energy in switching? If DDG isn't any better than maybe nobody is, so we might as well get used to the lack of privacy. Why switch if you're…

Conspiracy just means multiple people working together in secret toward some common goal. People do that all the time. Why just last week we had a closed door meeting at my company about how we might conspire to create more interest in the user community for our product. That's a conspiracy.

Of course there are nutty conspiracy theories but there are nutty math and physics papers too. I feel like the blanket ridicule of any notion of conspiratorial action is meant to discourage any form of investigative journalism or deeper probing below the surface of the narrative.

Your hypothesis is reasonable and plausible.

Re: Duck Duck Go: Illusion of Privacy (2013)

#67
Like Google, by default DDG tracks what results the user clicks on. URLs are prefixed with a DDG URL. Users HTTP requests are forwarded through DDG servers.

By default, DDG "lite" does not set cookies or use Javascript. However, if the user wants to change the default "settings" (HTTP has no state so this is a fiction), then AFAICT she has to enable Javascript and accept cookies. Privacy conscious users do not want Javascript or cookies.

DDG could achieve the same result by simply providing an alternate URL, something like /lite2 in addition to /lite.

Whether DDG saves this data I have no idea. But one has to wonder why, if privacy is a goal, DDG is collecting it to begin with.

If DDG believes it is doing this for the benefit of users, it is not convincing because there are alternative ways to achieve the same benefit that do not require prefixing URLs, Javascript or use of cookies.

For example, browser settings already allow the user to control HTTP Referer headers, assuming queries were submitted using GET. The user can change the settings in the browser so that no referer is sent, or to send a custom referer of her choosing.

Another example is if DDG accepted queries via POST method in addition to GET. No search terms would be leaked in the URL or in any HTTP referer.

Re: Duck Duck Go: Illusion of Privacy (2013)

#68

The issues brought up in this post apply to every single service operating online, and it only applies to DuckDuckGo in any special way because of their increasing size. This includes "client" encrypted webmail and similar applications: they can be forced to deliver malicious JS that gives up your keys, or the JS client delivery can be MitM'ed. Many people seeking enhanced privacy from DuckDuckGo are seeking privacy…

DDG has https://DuckDuckGo.com/lite

For non js. There are of course other vectors and many not even search engine dependent.

Re: Duck Duck Go: Illusion of Privacy (2013)

#69

Earlier quoted context omitted.

The article was a response to a guardian article that ultimately cited https://siliconangle.com/blog/2013/06/14/duckduckgo-the-pris... > “By not storing any useful information, DuckDuckGo simply isn’t useful to these surveillance programs,” says Weinberg. “We literally do not store personally identifiable user data, so if the NSA were to get a hold of all our data, it would not be useful to them since it is all truly…

Not to get off topic but there's a part of me that suspect the Equifax hack has the NSA (or will ultimately filter back to them). When I read Dragnet Nation a couple years ago one of the things that left an impression on me was the fact that the gov can buy "private" personal data on the open market just like anyone else can. That is, it's not spying (and a violate of right / laws) if the data is on the free market.…

This vaguely reminds me of the time a paranoid coworker told me not to store tax documents on the cloud because the government could get at it.

Re: Duck Duck Go: Illusion of Privacy (2013)

#70

Like Google, by default DDG tracks what results the user clicks on. URLs are prefixed with a DDG URL. Users HTTP requests are forwarded through DDG servers. By default, DDG "lite" does not set cookies or use Javascript. However, if the user wants to change the default "settings" (HTTP has no state so this is a fiction), then AFAICT she has to enable Javascript and accept cookies. Privacy conscious users do not want J…

According to DDG, they prefix the links to prevent the destination websites from obtaining the search terms used via the HTTP Referer header.

Source: https://duckduckgo.com/privacy

Post reply on HN