Live data from Hacker News

Duck Duck Go: Illusion of Privacy (2013)

etherrag.blogspot.com

91–100 of 128 posts

Re: Duck Duck Go: Illusion of Privacy (2013)

#91
post #43

Earlier quoted context omitted.

Sure, if you're a fairly affluent and educated hacker news reader. But there are far more people who I routinely work with who struggle with the concept of a password but need to use the internet to apply for work, register for disability, social security, communicate with family, etc. Do those people deserve less privacy?

Nom they deserve the same privacy. I wish there was a solution for them, but I don't think there is. Better software and newer generations that know how to use them will, however, come before anyone can make a government that respects his population.

Stuff like Apple's FaceID might help. I am eagerly awaiting to see how will Apple entrench it in their services because I am sure they will.

Re: Duck Duck Go: Illusion of Privacy (2013)

#92
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

There are two levels at play here: who is saying what and who is talking to who. The second one is extremely hard to protect against and already plenty useful on its own.

A fact is a fact. IMO we should approach the problems one by one, even if that means that privacy will remain a pipe dream for a while still. But we can gradually tighten the grip and I think every little bit will make the adversaries panic a little.

Example: make a strong standardized crypto (I still have to workaround API requests to several servers and hardcode TLS v1.2 as a requirement which is not okay!), then work on making a Tor-like net tech, then integrate the blockchain in the picture so anonymity is stronger, then probably put all that in mesh networking, etc. etc. The current internet is broken, many of us know it.

I am not an expert so my example might be naive and stupid -- but recently I am very interested in the area and I'd contribute. After I educate myself first, though.

Re: Duck Duck Go: Illusion of Privacy (2013)

#93
My beef with this article is that it's unreasonably reductionist to conclude that DDG provides an "illusion" of privacy based on the fact that they're as vulnerable to being targeted by the NSA as anyone else. The issue of privacy is so much bigger than that.

If you use Google Search and someone obtains access to the data they have on you, legally or illegally, they could end up obtaining many years of your browsing history. If you use DDG they have nothing, and the most they can do (as the article states) is start collecting your search habits from that point onward.

I don't want huge companies to amass giant archives of data about me. There are so many ways it can be abused by a multitude of actors. It's a selling point to me when a service retains little or no information, and if it needs to retain something, it requests limited permission in clear and simple terms.

Re: Duck Duck Go: Illusion of Privacy (2013)

#94
This is something that's always been fascinating to me. In any thread about privacy, there's always a comment along the lines of "if your threat model is a nation-state, then you're screwed." You hear it about DDG, Tor, client-side but web-delivered encrypted email, etc.

What if your threat model is a nation state? What's the proper way to ensure your privacy that does not require abstaining from the internet? Is a high degree of privacy even possible?

Re: Duck Duck Go: Illusion of Privacy (2013)

#95
post #66
post #39

Earlier quoted context omitted.

If I were a conspiracy theorist, I'd think there was something nefarious going on when I see articles like this. What if the intended result is not actually browbeating DDG but, rather, making people think that DDG is no better than Google in the privacy arena so why invest the energy in switching? If DDG isn't any better than maybe nobody is, so we might as well get used to the lack of privacy. Why switch if you're…

Conspiracy just means multiple people working together in secret toward some common goal. People do that all the time. Why just last week we had a closed door meeting at my company about how we might conspire to create more interest in the user community for our product. That's a conspiracy. Of course there are nutty conspiracy theories but there are nutty math and physics papers too. I feel like the blanket ridicule…

>Conspiracy just means multiple people working together in secret toward some common goal.

I checked various dictionaries available online and all of them have a common definition like "a secret plan by a group to do something unlawful or harmful."

Re: Duck Duck Go: Illusion of Privacy (2013)

#96
post #94

This is something that's always been fascinating to me. In any thread about privacy, there's always a comment along the lines of "if your threat model is a nation-state, then you're screwed." You hear it about DDG, Tor, client-side but web-delivered encrypted email, etc. What if your threat model is a nation state? What's the proper way to ensure your privacy that does not require abstaining from the internet ? Is a…

Privacy from the state never really existed, even before the internet. Paperwork always allowed the state to know things. Information has always been power, and information is an important tool for governments so they can be able to work. I think it always has been.

I'm more worried about privacy from private interests. The issue is what the governments do with data, and if the government let private parties access it, and where do you draw the line between the government having right to access, and companies being allowed to access it, because you will often have situations where things are not clear.

To be honest I will always have a problem with the whole privacy/surveillance debate, because there are things the government should know, but only because it is the government. Private companies are now being able to track people and have the same kind of data the government has.

So there is a big nuance, and it is often shut out by the outrage, which frankly comes from a libertarian agenda, which I have a problem with.

Re: Duck Duck Go: Illusion of Privacy (2013)

#97
post #8

I think DuckDuckGo is unfairly singled out here. They do more than most companies to protect privacy, and most of their users are specifically trying to deprive Google of more feed for its data silo. Of course they can't protect you from the NSA. Extremely few actors can. If your threat model includes actors within the US Federal Government (especially the intelligence community), run. Yesterday. That's a statement a…

The article was a response to a guardian article that ultimately cited https://siliconangle.com/blog/2013/06/14/duckduckgo-the-pris... > “By not storing any useful information, DuckDuckGo simply isn’t useful to these surveillance programs,” says Weinberg. “We literally do not store personally identifiable user data, so if the NSA were to get a hold of all our data, it would not be useful to them since it is all truly…

>But what if DuckDuckGo provided a splitter-feed to the NSA? DuckDuckGo can claim without lying that they store no personal information, but that speaks nothing of a collaborating partner storing it.

Not to mention they don't need to provide anything themselves. Unless DDG has their own cables to users homes, after DDG connect to the internet backbone and before the user connects to DDG, the various agencies have all kinds of opportunities to get their feeds. It surely isn't SSL that will prevent them.

Re: Duck Duck Go: Illusion of Privacy (2013)

#98
post #3

The only conclusion I can make from this article is to avoid services hosted in the USA but even that is not guaranteed to work -- having in mind that US agents have been known to go abroad to request access to foreign company's servers. (They were even supposedly thrown out from Iceland once -- assuming that wasn't a honey pot propaganda operation to lure people to host stuff in Iceland, of course.) What's left for…

> The only conclusion I can make from this article is to avoid services hosted in the USA

The thing is, there are absolutely no guarantees it's any better in other countries : the fact that NSA activities were revealed doesn't mean other countries don't do as bad.

It's probably still a good idea to segments services across countries, though, so that it's not a single country who have access to all data.

I was thinking something else, lately (and it was really weird to me, since I'm a webdev): why do we need webapps for everything? Maybe we wouldn't have so many problems if we weren't centralizing so much data. There are probably many apps for which native apps and p2p would do.

Re: Duck Duck Go: Illusion of Privacy (2013)

#99

Earlier quoted context omitted.

Not to get off topic but there's a part of me that suspect the Equifax hack has the NSA (or will ultimately filter back to them). When I read Dragnet Nation a couple years ago one of the things that left an impression on me was the fact that the gov can buy "private" personal data on the open market just like anyone else can. That is, it's not spying (and a violate of right / laws) if the data is on the free market.…

> there's a part of me that suspect the Equifax hack has the NSA This is ridiculous. It makes no sense why the NSA or any other members of the US Intelligence Community would cause this sort of reputational damage and nationwide outrage to a company when they could simply walk up to them with one of those fancy national security letters with a built in gag order and take the information with much less of a fuss. Othe…

Ridiculous? Not at all.

In the context of the history of the CIA and NSA it's standard procedure. And that's just the stuff we know about. Certainly Snowden taught us anything is possible, that they have no restraint.

B

On the other hand, politely asking an outfit like Equifax for (just about) ALL their data with no real reason would be out of character. Why bother? Why go on record?

It's pretty simple. Why would they get via hack? Answer: Because they can.

Re: Duck Duck Go: Illusion of Privacy (2013)

#100
Recently I had a series of unfortunate plumbing mishaps at my home that set me back a bunch of money. I did very minimal google searching (just confirming the spelling of the plumber's name), but ads offering emergency home loans have started popping up in my browser.

If I can go to a search engine that doesn't sell the fact of possible financial problems to whatever loan shark is willing to pay the most to get to me, I see that as a win.

Post reply on HN