DuckDuckGo Searches Are Not Anonymous
secure.grepular.com
secure.grepular.com
Referer: https://duckduckgo.com/
"Hello dear user, you probably know exactly what you're doing, but on the off-chance that you don't, please realize that disabling the POST option for https connections may leak your search terms to the visiting site".
Or something to that effect.
After all, then the referring url would just be the search page without any parameters.
So if you switch off the post then leakage would occur, with the 'post' enabled you're fine.
edit: I see what you mean now, if they switch to 'get' mode it leaks the info even to sites they don't visit. One more good reason to use that post!
For users who are annoyed, you could explain to them somewhere on the site that you don't put it in the URL because it exposes their query. If they really want a secure search, I imagine they'll understand the tradeoff.
Requests for:
http://duckduckgo.com/?q=hacker+news
Should HTTP redirect to something like:
http://duckduckgo.com/?enc=34g7h3giuh3g
Where 34g7h3giuh3g would be the ciphertext generated by encrypting "hacker news". That page knows what the search term was because it will have decrypted the parameters on the server side, but any referers would just contain "garbage", and it would also mean people can copy/paste the address bar about.
They have a button on their website that adds it to you list of search engines in chrome (chromium in my case), so it definitely can be done.
EDIT: it turns out that ixquick switches to a different URL and uses get instead of post for this, so forget what I said.
PS: the opera urlbar inline search has post support.
Exactly. Sure you could use Tor and disable everything and log on a random wifi from a stolen computer that will then be smashed to bits and melted, but that's beside the point; if DDG advertises privacy, it should do everything it can to deliver on that promise.
But as for a fix, at least Opera offers the option of never sending referrer information. That would be enough in this case.
<?php
header("Location: the-result.com");
header("Referer: ");
?>So maybe you should have tested it ;) ?
Sure, Amazon S3 could be spying on your searches just like any web host (especially a cloud host) could spy on connections to its customers' sites. I don't think this is very likely, however.
Nothing shown in this blog post indicates that DDG's S3 account is logging IPs or that there's anything at all wrong with the privacy policy.
Knowing that, DDG may as well log the IP+Search themselves, as it makes no difference. The data is already logged and retrievable by contacting Amazon, therefore what is the point in DDG not logging it anyway?
Whatever happened to that 'mixed content' security warning, I thought that was pretty effective against stuff like this?
It's extraordinarily user-hostile, and would just add to the pile of pointless wankery that keeps people from using https (see also: shitting all over self-signed certs when in reality the CAs don't do shit for their rent and identity is useless anyway).
The actual solution is to never send Referer headers for cross-site requests from an HTTPS page.
That should be on someone's todo list at the major browser vendors. You're right, there really is no point in sending that header along, and sending it can cause all kinds of trouble.
Rightly identified and well addressed by epi0Bauqu. And also worth noting that this sort of constructive criticism is a great sign of positive market traction. I'm bumping into DDG more often on the web, which is excellent.
1) Embed the images in iframes, which are then embedded in the page. The iframes will swallow the referrer, so provided they are hosted somewhere where logs are discarded then it should be fine (I'd want to cross-browser test this before relying on it though).
2) If the browser supports data: URIs, then embed the image in the page. Obviously this might have some costs, but you could do it for HTTPS only perhaps?
3) Request the images in Base64 encoded form (or binary strings) via XMLHttpRequest after the page has loaded. You can overwrite the Referrer header in XMLHttpRequest
4) Preload the images BEFORE the search is done (ie, on the search page). With appropriate headers Amazon won't see a request (this won't work from the browser bar, though. I could imagine some ways around that, but I'm not sure they are worth it)
https will swallow referer automatically.
There are valid reasons why serving everything under HTTPS isn't always a good idea. The obvious one is CPU cost, but cache performance can also be affected. See, for example: http://blogs.msdn.com/ieinternals/archive/2010/04/21/Interne...
http://blog.pluron.com/2008/07/why-you-should.html
(I'm not saying that https isn't the best option. I'm just pointing out other options that can work with plain http.)
The worry is not that the information is sent. The headers, IP address, and search query is always sent to any search engine regardless of their privacy policy or whether it's sent as POST or GET, so the worry is not that information is being sent, but rather that the query string in GET requests is most likely kept in a log file at least for a few days.
If Duck Duck Go was upfront about how long this HTTP request log was kept, would that make the default search with GET requests acceptable? I think having search queries sent by default as POST would be irksome for a default setting.
People serious about privacy will be using a proxy with flash/javascript disabled and headers scrubbed.
"They certainly could log that information if they wanted to."
This is a problem with ANY site and ANY system that I know of.
"We don't log your IP address with the search term"
As it stands, they should append this to the end:
"but the architecture of our site lets Amazon log it."
>"but the architecture of our site lets Amazon log it."
This is the best suggestion yet. Of course there are numerous hacks possible to make it more secure, but each one at the cost of user experience. DDG has so many things going for it, I don't think for the majority of users security is at the top of their list.
However, at the end of the day, everything can be logged anyways. If someone is really concerned about this, they shouldn't be using the internet.
Edit: I want to be clear. If someone is concerned about the fact that things can be logged, then they are better off not using the internet, as pretty much everything has the potential to be logged. This is, after all, what the complaint is: the potential of being logged.
That sort of gives it all away.
So if duckduckgo would just send back the answers to the query and not use a page that requests resources from third parties they'd be fine.
Fixing this will make duckduckgo.com even better, which is awesome.
Well, Cant blame DDG for it though
http://en.wikipedia.org/wiki/HTTP_referrer#Origin_of_the_ter...
I knew about this for years, having stared at a bug for a whole day before I realized it was the header that was misspelled. It never even crossed my mind until I was away from the keyboard for a few hours.
Oh, yes, good catch.
Well exposed.