DuckDuckGo now fingerprinting visitors?
forums.whonix.org
forums.whonix.org
https://www.reddit.com/r/privacy/comments/ad4h0u/duckduckgo_...
2) Given the context of the actual API call, this is probably for benign purposes and not for fingerprinting
> DuckDuckGo is using the Canvas DOMRect API on their search engine. Canvas is used to make unique geometry measurements on target browsers, and DOMRect API uses rectangles. This can be verified with the CanvasBlocker Firefox add-on by Korbinian Kapsner. DDG has recently been redirecting some website navigations to cute pictures with remarks about their privacy promises. The organization is now seeking to expand their Internet presence. DDG are without question data brokers, and commercial websites that make promises like DDG does will not survive for long if they actually keep them.
Let me say again what I said multiple times: unless they are incorporated in some offshore or Switzerland, and none of their servers are on US soil (they are), then they either must work with the US government or US government using NSA already sees and read all your searches and can pinpoint them directly to you. They may even be forced by government to lie to their clients/users telling them we don’t spy or log your searches. Any other idea that in modern world american company working on american soil can build a web search engine that doesn’t give out / leak / cooperate with US government is very naive.
What's important to me, personally, is that platform doesn't share or sell what it has learned about you, and doesn't use potentially sensitive information in its advertising.
It would be unrealistic to expect a platform to not collect any data and still function. Analytics is the foundation for the feedback loop that it takes to effectively develop something like DDG.
If I go to an adult toy store I expect the person at the counter to know, but I don't want him telling everyone else.
uMatrix+disabling Javascript explicitly will help prevent tracking for those who know how.
The privacy aspect of DDG was always their marketing point, and I think we all knew it couldn't be totally true. Surely they must be harvesting data of some type, or else how would they expect to earn revenue? Others' have shown that at least some of their services run on AWS, so if Amazon really wanted your data (like if they were served a National Security Letter), I'm sure they could get it without DDG even knowing.
Simple. They can run display ads instead of targeted ads.
Since they have the search term you just typed, they know exactly what you’re looking for at this moment, and can target with that.
For added privacy, combine DDG with Tor Browser Bundle, because remember that although DDG is 'privacy first'; it doesn't stop some intel agency attributing search queries to specific users inside the Internet (which happen to have unique useragent strings and surf with unique IP addresses)
I'm not convinced that this is a law of nature, but it does seem to have some truth in it. I pay ~$5/month for services like Feedly and Evernote. I'd be willing to do the same for a high quality search engine that does not make me the product.
They can generate artificial scarcity by preventing the search query stream from being joined to user profiles by third parties.
If they end up with a well-educated, affluent userbase (likely, given their selling point), they can charge a huge premium for that scarcity.
This trick is much older than the internet itself.
If you are against advertising full stop then fine. This article, and peoples claimed grievances are with tracking, rather than advertising per se.
Edit: Missed your first post. Ignore me.
As a bonus: Last time I checked The Tor Browser Bundle displays a prompt anytime the canvas API is used in some javascript, and you can opt out of canvas fingerprinting this way.
I know DDG doesn't always have the results you are looking for, but for more long-tail queries and advanced searches I can use Startpage[0] which basically proxies the results from Google (using vanilla Google with Tor is a pain because of captchas).
I know as a software developer I’d design tests to ensure the wa testing is done in the order of the most users impacted.
Only FOSS so projects developed by someone, companies included, with the aim of solving some authors problem or desire can be trusted to a certain extent.
The rest it doesn't count much you may have "ugly dictators" or "less oppressive dictators" but they are still dictators. It's their nature, no matter how good intentions they have at start or they try to keep.
I appreciate that HN might be more likely than most places to be inhabited by people who can't imagine any other motivation except money, but for most of us there are other priorities.
Of course exception may exists and actually I'm sure exists, but they are exceptions, not "the rule"...
I'm sticking this in my "guilty until proven innocent" file.
Because I can't find where they are doing canvas fingerprinting, that or canvas defender doesn't say anything on only DDG. If they are just getting screen geometry, which I suspect, that's not enough to de-anonymize you. As far as I know anyway.
Canvas Fingerprinting: 1 in 3e6
User Agent: 1 in 2e3 (not many using FF on Linux I guess)
System Fonts: 1 in 3e2
Timezone: 1 in 5e1
A few other things < 1 in 10
Screen Size and Color Depth: 1 in 6
Screen Size is nowhere near identifying to me. There are just huge drops in the order of magnitude in this stuff. I can't imagine standard fingerprinting is that reliable. Though I wouldn't be surprised to learn if there were certain trends about things. Like if you identify I'm using FF on Linux it tells you I'm nerdy. That'd be good for targeting ads, but not good for unique identification. I thought that's why cookies are used.