Duck Duck Go: Illusion of Privacy (2013)
81–90 of 128 posts
Re: Duck Duck Go: Illusion of Privacy (2013)
#82Like Google, by default DDG tracks what results the user clicks on. URLs are prefixed with a DDG URL. Users HTTP requests are forwarded through DDG servers. By default, DDG "lite" does not set cookies or use Javascript. However, if the user wants to change the default "settings" (HTTP has no state so this is a fiction), then AFAICT she has to enable Javascript and accept cookies. Privacy conscious users do not want J…
DuckDuckGo staff here - just want to clarify a couple of points: * We don't track result clicks. URLs are no longer prefixed with a DDG URL by default except for old browsers (although this is controllable in the settings: https://duckduckgo.com/settings#privacy ), but even if this is in effect we don't store which sites users visit. We started stripping search queries in referrer headers in 2010 and you're right, cu…
Re: Duck Duck Go: Illusion of Privacy (2013)
#83I use Duckduckgo because I don't like monocultures.
Re: Duck Duck Go: Illusion of Privacy (2013)
#84If you're worried that DDG may log your IP you can simply use it with the Tor Browser (it's the default search engine) or use their onion service ( https://3g2upl4pq6kufc4m.onion/ ) for increased security and anonymity.
Tor is far from perfect and there are several ways in which one could connect traffic at some endpoint with a user at a specific IP. Do not rely on Tor if you really want anonymity.
No one made such claim, not even the Tor Project themselves.
> and there are several ways in which one could connect traffic at some endpoint with a user at a specific IP.
DDG traffic is e2e encrypted especially if you use their onion service since it wont use exit nodes, the best they can know is that someone did some unknown search on DDG.
> Do not rely on Tor if you really want anonymity.
Tor is the best solution low-latency anonymity system currently.
Re: Duck Duck Go: Illusion of Privacy (2013)
#85I wrote my own search engine and using it. Not very difficult.
Re: Duck Duck Go: Illusion of Privacy (2013)
#86Earlier quoted context omitted.
Tor offers a layer of protection. It is possible to stay anon on Tor.
> It is possible to stay anon on Tor. That is an extremely dangerous statement to make and one I do not agree with. Keep in mind that: - you will have to trust that a large chunk of the nodes is not in the hands of someone that you count as your enemy - that even if your enemy is not in charge of a substantial part of the network they may still be monitoring entry and egress and that that alone can be enough to figur…
Why not run your own guard node or even an obfuscated brige and then connect to it? That way you can make sure that no one will do traffic correlation (except, of course, a global adversary) since that would require controlling both the guard node and the exit used in the circuit (which changes every 10min, and in the Tor Browser you get a new circuit for each website).
> that even if your enemy is not in charge of a substantial part of the network they may still be monitoring entry and egress and that that alone can be enough to figure out who is talking to who
That's not possible in practice, quoting from the Tor Browser design documentation [1]:
> In the case of this attack, the key factors that increase the classification complexity (and thus hinder a real world adversary who attempts this attack) are large numbers of dynamically generated pages, partially cached content, and also the non-web activity of the entire Tor network. This yields an effective number of "web pages" many orders of magnitude larger than even Panchenko's "Open World" scenario, which suffered continuous near-constant decline in the true positive rate as the "Open World" size grew (see figure 4). This large level of classification complexity is further confounded by a noisy and low resolution featureset - one which is also relatively easy for the defender to manipulate at low cost.
> To make matters worse for a real-world adversary, the ocean of Tor Internet activity (at least, when compared to a lab setting) makes it a certainty that an adversary attempting examine large amounts of Tor traffic will ultimately be overwhelmed by false positives (even after making heavy tradeoffs on the ROC curve to minimize false positives to below 0.01%). This problem is known in the IDS literature as the Base Rate Fallacy, and it is the primary reason that anomaly and activity classification-based IDS and antivirus systems have failed to materialize in the marketplace (despite early success in academic literature).
> Still, we do not believe that these issues are enough to dismiss the attack outright. But we do believe these factors make it both worthwhile and effective to deploy light-weight defenses that reduce the accuracy of this attack by further contributing noise to hinder successful feature extraction.
And just recently netflow padding has been added to Tor 0.3.1.x.[2]
> So no, Tor is not 100% secure and it is very well possible that even if you use Tor your identity will be connected with some activity or even all of your activity while using the network.
That still doesn't disprove the fact that Tor is the best low-latency anonymity system and that not using Tor is much much worse than using it.
[1] : https://www.torproject.org/projects/torbrowser/design/
Re: Duck Duck Go: Illusion of Privacy (2013)
#87Earlier quoted context omitted.
Well, if you want to trust your anonymity to luck or not being monitored then yes, you can be anonymous on Tor. But that's little comfort. It's possible to cross a highway blindfolded too. But it isn't smart to do so and it is even less smart to assume that it will always work just because you can't see the danger with your silly blindfold on.
Thankfully, none of your assumptions are true if you consider TOR one part of anonymity as your parent comment did. Not to mention, you conspicuously avoid comparing degrees of anonymity. Obviously TOR is better than SSL, which doesn't provide any anonymity.
Re: Duck Duck Go: Illusion of Privacy (2013)
#88Earlier quoted context omitted.
The article was a response to a guardian article that ultimately cited https://siliconangle.com/blog/2013/06/14/duckduckgo-the-pris... > “By not storing any useful information, DuckDuckGo simply isn’t useful to these surveillance programs,” says Weinberg. “We literally do not store personally identifiable user data, so if the NSA were to get a hold of all our data, it would not be useful to them since it is all truly…
Not to get off topic but there's a part of me that suspect the Equifax hack has the NSA (or will ultimately filter back to them). When I read Dragnet Nation a couple years ago one of the things that left an impression on me was the fact that the gov can buy "private" personal data on the open market just like anyone else can. That is, it's not spying (and a violate of right / laws) if the data is on the free market.…
Re: Duck Duck Go: Illusion of Privacy (2013)
#89Earlier quoted context omitted.
Is it? For who? Do you think people's data would be more secure at the border if - You kernal-hacked iOS so that it booted into a vanilla account upon entry of a certain passcode, and encouraged people to install your hack from GitHub, potentially borking their phones - People couldn't be compelled (or face being denied entry) to allow search of their electronic devices ? What about trying to do everything via a VPN…
Let's say you have your data secured with Ultimate Encryption Method . A couple of thugs appear at your door and mention that if you don't un-encrypt that data, they will send these very compromising photographs of you to very public places. Ultimate Encryption Method has just been trivially bypassed.
Hence, the good crypto is really only the most basic first step. Full privacy should be the second and a very important step. Fine, I might have an account in . Fine, my real name is known there.
OK.
But there are plethora of cases where having a user profile and personally identifiable information is simply not necessary -- like web search. Even e-commerce like Amazon can be mostly anonymized: you can pay with an e-gold kind of currency (Bitcoin, Ethereum) and Amazon can only ask politely another API if the goods are deliverable to your address (while Amazon won't have an idea about your physical address). Then, even if that mystical-another-API has your physical address, at least it's not in the hands of Amazon -- fragmentation of personal info gives us a small degree of protection, even if Amazon can eventually procure the info under the table. Hey, every little bit helps. Make surveillance expensive and many will drop it (not everybody of course, I recognize that). Again, every little bit helps.
Of course, due to a mountain of vested interests, nobody is talking about such technical solutions. "They" want your info all over the net. It's easier for them, so why change anything? The current status quo is sadly very logical.
Back to your example, thugs will just be angrily gnawing at their nails if they have no idea who you are and where you live.
Re: Duck Duck Go: Illusion of Privacy (2013)
#90Earlier quoted context omitted.
Solving the problem with technology is 1000000 times easier than solving it from the "social" side.
A decentralized technology only works until some corporation with large advertising resources creates a proprietary centralized service around it and most people flock to their offering. E.g. Bitcoin is becoming centralized around popular online wallets, exchanges and pools; email was supposed to be decentralized, but now most people use Gmail; etc. We will not achieve full decentralization until it becomes both tech…
However, what we can do is make decentralized tech absolutely idiot-proof and put it in the hands of non-technical users. If it's convenient, fast and reliable, it will at least have an equal footing against the centralized services. Let's get to that point and fight the other battle you mentioned then.