Patriot Act amendment needing a warrant for browsing history fails
theregister.co.uk
theregister.co.uk
For home grown terrorism, how many school shootings happen when the people who know the shooter literally tell police/fbi beforehand about the state of the shooter. Are school shooters not terrorists? They have a social/political gripe and the terror is their way to get their voice out, avenge (like jihad) or inflict change. So why are they failing so bad even after almost 20 years of patriot act?
Politicians don't want to be blamed because they know the next terrorist attack will happen soon and it can't be prevented,except the politicians that gut the patriot act will be blamed for it. On the flip side,information on voters,tracking them like this helps politicians
Not everything bad is terrorism. A mentally ill person going on a murder-suicide rampage after beijg ignored by a girl is not a terrorist. A person acting in their self-interest in a way that contributes to systemic racism or oppression is not a terrorist. Hunting or threatening people of a certain race or gender or orientation or hobby to scare them and others away is terrorism. Blowing up buildings to pressure decision makers into a policy change is terrorism.
Maybe manipulating a single individual via threats or minor violence could be considered small scale terrorism (but their are better words, like harassment or abuse or stalking or assault).
So like the shooting of a black church by a white supremacist explicitly for the purposes of espousing white supremacy?
> Hunting or threatening people of a certain race or gender or orientation or hobby to scare them and others away is terrorism.
So like the lgbtq club shooting, or the black church, or the 1989 shooting specifically targeting women?
(+) “minority” has apparently been redefined to be 60-66% whenever the goal is to stop congress from doing something reprehensible.
Trying to change the behavior of a group of people by using violence is what I’d consider to be terrorism.
By that definition, some school shooters would qualify as terrorists. When they target a category of people (like athletes) who haven’t bulled them, they’re trying to scare all people away from becoming athletes.
I’d say, if you target specific people who directly hurt you, you’re seeking revenge.
If you target a category of people, you’re saying that those people who haven’t done anything to you are targets and you’re trying to influence their behavior through fear.
The fact that it strikes fear into the rest of the nation is ancillary. They're usually more interested in the notoriety they gain than trying to create some kind of policy change.
This really is similar to jihadist terrorism,jihadism took away american's privacy and mass shooters with gripes against american socio-politics have americans living in trauma over active shooter drills and gun toting teachers. Not only are they both terrorism, they both won!
Al-qaeda is eradicated but they won, I fear many would credit 9/11 as the begining of the end of america. Much like insurgent warfare,terrorism will be studied as a means of warfare where due to extreme imbalances on weaponry and digital surveillance the only way to fight is by terrorizing your enemy. War is horrible but terrorism is a cancerous form of war where destroying your enemy does not translate to success.
I would argue most school shootings are also not terrorism. They do create fear, but my impression is that the intended goal is revenge rather than fear. It would be hard to frame them as terrorists; most of them leave behind notes expressing a clear desire for revenge but mentioning no kind of policy changes they want.
I do think most of the race/religion inspired mass shootings were terrorist acts though. Their goal seemed to be spreading fear in those communities.
Won what? As far as I know, they didn't achieve their goal of driving out the Americans out of the Middle East. The loss of privacy and rights is incidental to their goals.
Now, does all that snooping and invading countries increase the background desire and willingness for bad guys to do terrorist-type things, almost certainty.
They are not. Terrorism is supposed to be a political tool. Whereas school shooters are often just deranged or troubled people lashing out.
You either need to narrow the definition or carve out explicit exceptions. If you are carving out exceptions, the definition is just “people we don’t like”.
I guess that is pretty close to the definition prosecutors like to use in the US.
That they're similar in this manner doesn't mean that we can't have laws and law enforcement because they're inherently violent and tyrannical or anything, but it does inform how seriously and dispassionately we should approach their means and ends. I don't think that it's particularly radical to call an abuse of judicial power terrorism. What else to call, for example, a judge who robs entire communities of their youth in exchange for backroom deals with private prisons?
You have no evidence that most school shooters communicated such a goal (although there might be an outlier). Or if you do, I'm curious what it is.
Terrorists have a tangible goal, typically coupled with demands, not some hidden intention you make up to shoehorn a person into the definition. Even Elliot Rodger, who had a "manifesto", did not communicate any sort of demands or goals.
I cant recall one who would act like normal person and multiple disturbed ones.
Unfortunately, the narrative that resulted colored later discourse with less-than-accurate assumptions about the nature of mass school shootings. They're overwhelmingly not carried out by bullied loners, but instead by entitled, ostracized bullies who aren't stopped because they don't fit the American conceptualization of who commits violence. To that point, even high-profile black and brown mass shooters tend not to be gangbangers or whatever, but men with military or law enforcement backgrounds.
Inst that simply because men with military or law enforcement backgrounds are more violent in general?
Shit like this is said all the time on HN with absolutely nothing to substantiate it.
The logic goes like this: It would be utterly stupid for terrorist groups to rely on digital communications simply because of how well locked down the various government agencies have made it. We assume that they are not utterly stupid.
I don't think it's a crazy statement or needing further justification. I doubt terrorist groups are that sophisticated but I would assume they have plugged the simplest holes.
"Terrorists don't use digital communications[0]
[0] Example of a terrorist identified and killed via surveillance of their digital communications"
What the above is talking about well known, even privacy-aware people tend to not use digital communication that much, no facebook, or other social media, no smartphones. In the post-Snowden era, I am not sure why somebody thinks otherwise.
3 letter agencies have the means, the reason, the legitimacy, and the resources to penetrate every type of telecommunication, the worst-case just trojan the entire GSM infrastructure if necessary. The USA conducted thousands of drone strikes. What do you think drives locating the target?
Yes. In fact I don't know of a single terrorist who doesn't use digital communication of some kind.
I'm slightly confused because you seem to be justifying your belief that no terrorists use digital communication on the back of examples of terrorists identified and killed via surveillance of their digital communication use
The logic is that active, dedicated terrorist groups already know: "They literally get a drone strike for having called a known terrorist or for going to a wedding other terrorists with cell phones go to."
The reasoning that knowing this information you would be very careful about what you communicate over the internet is very sound to me. To convince me that this reasoning is incorrect would require an abundance of data to the contrary.
Thank you so much for saying this.
I think terrorists make mistakes (or take risks), and I'm not convinced that we catch all of those either.
Was the US being irrational with nuking of japan?
Actual terrorists were found because of using cell phones or internet.
The claim directly conflicts with the supporting anecdote.
And here it has led you astray. Terrorist organisations have propaganda mouthpieces, and use social media like any other. One of my previous jobs involved building network analysis tools to identify and locate terrorists combing through their Twitter feeds.
For some, you could easily identify the point in their lives when they were radicalized, and trace connections to others who were also, and identify the people they had in common.
Inductive reasoning opens room for questions, not answers, because it does not account for unknown information.
Yeah. The truth is that groups like ISIS use Telegram pretty heavily. Same with some of the Persian threat actor groups, Hezbollah, others.
Then why is terrorist content discussed so much in content moderation circles, specifically the fact that content moderators are viewing it so often it induces PTSD in them?
ISIS has put out high definition videos of executions. That's the opposite of "not touching digital comms"
https://www.theverge.com/2020/5/12/21255870/facebook-content...
The original incidents are terrorism, and the people doing them are targeted.
I don't think you're being fair to the context. They've been showboating killing online for decades. But showboating should not be conflated using digital communications to coordinate their efforts. I'm not saying they don't use digital communications. But this is hardly proof of that.
How long did bin laden evade capture? 20-30 years? And did they catch him because he used the internet?
Or even put up a serious threat of one
Tech workers especially have little excuse, since it’s a matter of leaving that work laptop closed
No one in tech seems to remember SOPA
Workers seem oblivious to what recent teacher strikes achieved
Hong Kong protests in the face of a tyrant
Y’all bloviate all over your screens
Who is more exceptional?
Terrorists don't use cell phones because terrorists use cell phones?
Theatrics to make it look like they are doing enough. Truth is, if someone immigrated or gets radicalized without detectio, the IC is relying on them not having good opsec. Spying on everyone (instead of with a warrant) , E2EE subversion,and these silly laws won't give them additional capacity when the actual terrorists and mass shooters that slip through already have bad opsec,don't use mainstream platforms or E2EE
Always look at the incentives. The Boston Bombing intelligence "failure" is not a failure of intelligence. We got exactly what the incentives were set up to deliver. The system works, it's just not spec'd out to deliver what people think it is.
A mostly law abiding protest group that dares loudly complain about the government "doing it wrong" is an actual threat to law enforcement because it is a threat to the status quo. The voters might listen to them. The voters might install politicians who make promises of "doing it right" which usually includes allocating resources on things other than law enforcement. Drug treatment instead of drug crime task forces for example. That's a real risk to law enforcement agencies and gets treated as such.
On the other hand you have two dudes with some bombs. Worst case they kill a couple hundred people and make the public hate them in the process. Sure that makes you look like incompetent fools but the public already thinks of you that way so you don't lose anything. No politician is going to get elected on a promise of turning your organization upside down because you failed to catch some lone wolves. Maybe you can even find a way to blame someone/something else and get some extra power out of it. Those guys were not a real risk to the organizations tasked with stopping people like them and were likewise ignored.
That said, as much as it pains me to defend the MA state police the failure mode of the status quo they have settled into is pretty benign. The false positive rate on terrorism is so high and they are so eager to LARP as combat troops that if they did thoroughly follow up on every tip they got they'd likely have a much higher body count than the real terrorists. Doing unethical things to maximize their incomes and minimize their work (the gripe most people have with the MA state police) is pretty harmless by comparison.
I'm not arguing that we should get rid of encryption, (nor am I saying it's even possible to defeat encryption at scale, so it was probably a bad example to go with when call detail records would have been better, but I should really be working right now), rather, I'm saying we should let law enforcement keep up with the level of technology, but we should have strong auditing processes and don't allow for situations like the FISA/FISC situation where proceedings are nearly always literally one-sided (only prosecution, defense is necessarily excluded from the proceeding) [0].
New powers will be required to deal with new situations. The SARS-CoV-2 virus, for example, has killed more Chicagoans in the past 2 months than homicide has in the past 3 years, and that is also ravaging the economy as people are correctly afraid of going out in public. Currently most people are isolating because we don't have a more precise way of separating the infected from the uninfected, but China's digital contact tracing QR-code scheme provides a much more precise separator (and per an episode of This American Life [1] that I just listened to, it actually made at least the interviewee more comfortable being in public because they knew infected or risky people were separated out). If legislators implemented very tight controls over who could use the data (and how) and there was (sufficiently) transparent and rigorous auditing, we could save lives, jobs, and businesses. I know the public won't go for it because the public justifiably doesn't trust the government to prevent abuse of this system, but I would love to live in a world where we could develop and deploy technical solutions to major problems and be confident that the technical solution would not be abused.
[0] https://scholarlycommons.law.wlu.edu/wlulr/vol72/iss3/4/
Now's a good time to call you senator (if they voted against this) and tell them that they fucked up by weakening your rights and freedoms.
Then, get a VPN or better use Tor as much as you can.
I do use it frequently and do run a few relays, and that's probably the only way to improve it.
If it were simpler to run a relay on a provider that allows it, and it doesn’t cost much (say $10 a month) to give Tor users a little more speed, that’d be helpful. The last time I looked at the documentation, it seemed quite involved and complex (of course, I wouldn’t want the security of Tor users to be compromised due to any misconfiguration).
If there were something for Tor like Sandstorm for web apps or Algo for WireGuard, more people could run relays and help everyone.
Here's a giant list of hosts you can look into - https://community.torproject.org/relay/community-resources/g...
I spent maybe an hour researching based my in criteria. You can host just an exit (most helpful), or a couple of relays (aim for 100mbps+, and decent bandwidth). You can get a lot for $5/month for each relay.
That way, the executive branch can tamper with state and local elections with impunity.
The supreme court just heard oral arguments in a case where Trump’s lawyers argued he was allowed to shoot people for no reason in public. (Really. This is not hyperbole.)
Presumably the next step is to (perhaps selectively) cancel elections (or some ballots) because “emergency”, and then refusing to step down if the resulting impeachment somehow succeeds (which it won’t).
What I find most interesting is the complete hijacking of a large portion of the conspiracy crowd such that this is all permissible to them, as long as it keeps the Other out of the power structure.
2016 was a total catastrophe of an election. The courts intervened in one primary earlier this year, in bid to get a conservative judge elected. That backfired, fortunately.
The Senate is intentionally blocking funding for election security, and now, with COVID, they’re refusing to provide funding to allow mail in ballots in many states.
Some of the leaders responsible for underfunding the election have publicly said they are withholding the funding because the republicans will lose if there is high turnout this fall.
Groups that use terrorism to get their way almost always fail. This should not surprise us. Terrorism is the last available option for a weak interest group that has no better way to make their will felt. Therefore as scary as it is to face, the fact that they are resorting to it is evidence that they are underdogs and we should not be surprised that they later fail.
Given that fact, the extreme efforts that we take to drive the nail even farther into terrorism is overkill.
Totally untrue. When the US used atomic bombs to level cities in Japan, that was terrorism. The goal was to strike fear into the regime and the people for an unconditional surrender. It was not an attack against the military or government, it was an act of terrorism.
When the US uses drone strikes to blow up weddings, that's terrorism. They are not actively engaged in a military conflict, even if there is allegedly some 'terrorist' they are trying to kill.
The communist revolutions in various places heavily employed terrorism.
Point being, the label of terrorism in the eyes of Western political discourse necessarily connotes violence of an unjustifiable or unsanctioned by the majority nature. I'm curious on your view of the Civil War. Would the secession and war waged by the Southern States (or by the Union retaking them) also qualify as terrorism?
I don't think this is true at all. Maybe if we define the West as America, but even then I think that's a stretch. I can say anecdotally in my circles that the trading of unwitting Japanese civilian lives en masse in exchange for American military lives is looked on with disgust.
It's okay, these people are terrorists and don't deserve any rights.
I've become increasingly uncomfortable with the power that classification confers to the executive branch to shape the national discourse; but I don't know as that will realistically change without an unprecedented shift in Congressional and Executive sentiment.
As to the narrative still being taught in schools; I certainly don't have a great answer for that one either.
We have to teach them something, and you certainly don't have the most room within a child's worldview for being able to address the type of nuance the historically correct narrative creates without difficulty. At least that is the assumption I'm led to by assuming that there is a compelling reason the "System" has converged on the solution it has (locking the knowledge outside of normal curricula, and requiring extra independent digging to get at the truth of it, notionally done on the student's own initiative once they get older).
You run into the indoctrination outcome more often than not; but you should have an eventual consistency effect over the timescale of generations. That doesn't seem fundamentally unreasonable to me. Pain in the ass? Yes. Fraught with hazard to the stability of the national identity? Assuredly. However, if we respect that we the Citizenry represent the standard bearers of national truth, then we must be the ones to change the history books; just as those who came before us did.
Keeping society moving along is a lot of work.
Would you be okay sending your children to an education establishment that was pro-Nazi? Probably not.
Start treating the system for what it is: evil. Quit letting meaningless current affairs dominate the political dialogue. Speak out against the war criminals.
All terrorists feel justified, or they wouldn't do what they do.
> the label of terrorism in the eyes of Western political discourse necessarily connotes violence of an unjustifiable or unsanctioned by the majority nature
That's not true. There's a definition for terrorism, and it's the use of violence against non-combatants to create fear for the purposes of political change. Most people don't actually know the definition, so they're easily confused.
> Would the secession and war waged by the Southern States
How would secession qualify as terrorism? The battles were mainly among two military parties. Also, the term "Civil Warm" is a misnomer. The most neutral correct term is "War Between the States." Military conscription and execution of defectors, while terrible, also not terrorism, just despotic.
>RE: Civil War/War of Northern Aggression/War of State's Seceession
Eh... The folks who's ancestors were among the victims of Sherman's March to the Sea may beg to differ that the conflict was largely constrained to being between just the military. Again, very fluid and slippery if you're going to allow Hiroshima/Nagasaki as being an act of terrorism. The entire concept of terrorism is so murky and ambiguous that I'm of the opinion it is evolving to become the rhetorical boogeyman of our generation; something kept around to scare people into falling in line.
I don't like it... And I try to make sure kids understand it when they seem capable of it. It's just such a damn complicated swamp to navigate through.
> Sherman's March to the Sea
I'm well aware of this, but try to find a mainstream source that articulates his crimes and they are few and far between.
https://pando.com/2014/11/20/the-war-nerd-why-sherman-was-ri...
https://books.google.com/books?id=FkD26KVW6LQC&pg=PA337&lpg=...
What I meant was asymmetric use of violence where a much weaker force uses their ability to show up unexpectedly and cause damage to cause fear and terror far out of proportion with the true damage that they are capable of inflicting. Those are the defined underdogs.
This is as opposed to war where a force capable of large sustained violence actually engages in sustained violence (though often by following certain rules of conduct - see the Geneva conventions) to force an enemy to capitulate. This use of force may indeed cause terror but does not indicate an inherent weakness in the force using the tactic.
Their plan was to lead the USA into a war in the Middle East. There they would demonstrate that we could hit hard but had no staying power, and so could be beaten. Once that was demonstrated, they would be able to create a religious caliphate that could sweep away the corrupt secular rulers that were oppressing Muslims and recreate the religious empire that used to exist.
We in fact gave them the war that they wanted in Iraq. We did hit hard. We were then sucked into a protracted operation. And as we looked to exit they created the caliphate and named it ISIS. It has since been defeated. Even if things are not going as we hoped in the Middle East, they are more dramatically not going as they hoped either.
For an explanation of how we know that this was their goal all along, read https://www.amazon.com/Americas-Secret-War-Worldwide-Struggl....
But if they're getting the history via companies like Google, they'd link together your records just as easily.
I see VPNs often being touted as anonymity tools, when it's my understand not all VPNS have multiple users sharing one IP.
(Ex: it's my understanding that an Algo VPN might obscure your geographic location, it's an IP unique to you. Not clear on how a commercial service like Tunnelbear works - many services tout no logging but seem to stay mum on if IPs are shared)
If any of the above is incorrect, please feel free to jump in and reply but it looks to me like moving as much browsing over to Tor as possible is the best move if you're worried about anonymity and not simply someone owning the wifi you are connected to.
An easy implementation is to provide no personally identifiable information while using the web, and siloing the personally identifiable information when necessary. 1 email for your bank accounts and unemployment registration that uses your real name. A variety of differing emails and logins for all other websites.
So to be clear, they'd get the data from the ISP? I'm not surprised DNS queries get saved but whole URLs is another thing.
I guess I shouldn't be surprised, but I am a little bit, that they'd expend the $$$ to store that info longer than necessary for core business functions.
>An easy implementation is to provide no personally identifiable information while using the web, and siloing the personally identifiable information when necessary. 1 email for your bank accounts and unemployment registration that uses your real name. A variety of differing emails and logins for all other websites.
I do this + throw the banking and personal email into Firefox containers.
Guerillamail is really useful for creating stuff like a HN account though it's sadly abused often enough many sites won't let you register using it anymore:
https://www.guerrillamail.com/
(The other issue being requiring SMS auth after an initial signup)
The bait and switch the USG loves to use, and in fact all governments love to use, is to point to a (possibly nonexistent) external enemy and use that to scare the population into accepting ever increasing authoritarian measures domestically.
Factor in co-operation from CDN's and really that covers a vast array of data that the US Government could access.
DoH pragmatically reduces their ability to conduct such global surveillance. "Pervasive Monitoring is An Attack".
We speak of man's laws and nature's as though they were the same kind of thing but they really, really aren't. I can no more magically replay the session keys from last week's Wikipedia visit in response to a court order, a warrant or the US Constitution itself than I could dance on the surface of the sun if they required that.
The idea here isn't that Public Enemy Number One today is protected from surveillance, but instead that you today are protected from the hypothetical surveillance of your past that might be authorised if some day you become Public Enemy Number One.
If gov tried to force CF to change that they would likely put up a huge public legal fight to prevent it whereas ATT / Verizon and Comcast would bend over backwards to secretly comply while also simultaneously seeing if they could inject some ads into the pages you visited.
In addition Mozilla put them through a rigorous process when selecting them as their default DoH provider which included them contractually agreeing to adhere to their stated policy. https://wiki.mozilla.org/Security/DOH-resolver-policy
Basically when you connect over https using TLS 1.2 to a site that is hosted on a shared server or behind a load balancer, your browser must tell it in clear text which host name it is trying to connect to. Encrypted SNI in TLS 1.3 also encrypts this info such that if you are also using DoH or DNS over TLS to encrypt DNS query then the ISP can only see the IP of server you connect to which is often going to be a huge cloud provider's load balancer that might serve hundreds or more different sites throughout the day / at the same time.
If you are interested in collaborating or learning more:
Serious question, I was under the impression this was equivalent to warrantless wire tapping, which was already illegal.
We already have secret courts and indefinite pre-trial detention in the US. This is another small step in the creation of a police state.
The precedent this vote created only took 37 votes in a chamber that is skewed much further right than the electorate. It would take about 55% of the vote to get the senate to be 50% democrat. That would give them enough procedural control to stop this sort of thing (if they bothered; they didn’t under Obama...)
This is not democracy in action. This is democracy in its death throes.
I can also encrypt my phone, turn on permanent incognito mode, disable Javascript, and have uBlock Origin running to stop trackers. Good luck trying to pin my legal name to a particular website visit. Then there's the fact that 3G/4G uses vague carrier-grade-NAT IPV4 addresses so countless others all share the same IP address enabling you to 'hide among the crowd' (providing the useragent is something common that many people use like Safari on an iPhone5)
Where is that? My experience in Europe and Thailand is that I have to sign documents and show a proof of identity.
One of the general difficulties with the government threat actor is that law abiding people have to thread the needle of both technical protection and legal requirements.
But how would they ever catch you?
Although this may have changed recently.
They were able to de-anonymize burner phones by mapping what numbers they were contacting, who those numbers were contacting and who the 2nd hop numbers were contacting.
Given that this was the technology 2 decades ago, I’m going to guess that similar behavioral fingerprints have been collected for all sorts of data. I wonder if it’s possible to fingerprint someone from the frequency of the top 5 websites someone visits and the time at which they are most actively browsing a website.
Edit: I found the podcast from my notes. Episode 265 of the James Altucher Show
https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_...
The dynamic here is that Republican politicians often want to present themselves to constituents as being against the police state or big government, but the party/party leadership wants to pass measures such as this. So the individual politicians are accommodated to the extent that they don't interfere with the party passing what it wants.
You see a similar dynamic in quite a lot of votes.
TL;DR: McConnell knows how to count.
ISTM that pen registers not requiring warrants is reasonable -- I'm not sure it's good for society, but it is reasonable.
ISTM that keeping track of cleartext metadata emitted by personal devices on the public Internet is exactly like a pen register.
DNS w/ QName minimization, DoH/DoE, and preferably DNSCurve, are techniques that can reduce the visibility of various metadata involved in gathering browsing history.
However, this popular media framing, which blames the failure of this amendment on Bernie Sanders, is unhinged. It's not just this Register article; you'll see the same sniping at Sanders specifically in most articles that carry a negative opinion on the PATRIOT Act.
Being absent for the vote is shameful, sure. But how about laying the blame somewhere more meaningful? For example, on us Californians who re-elected Feinstein despite knowing she is absolutely abysmal on privacy. Californians like myself should carry this shame, not Sanders and Vermont voters. We Californians are sorry for voting so blindly and continuously re-electing terrible senators.
I used to work directly with these big ISPs, and I can assure you they aren't very sophisticated. Even if they log every IP you send a packet to, and they know every domain that points to each of those IPs, they can't know exactly what you requested or which particular website you visited provided these websites use HTTPS.
Their DNS severs, however, and definitely doing this, and they sell that data to 3rd parties.
TLS SNI also leaks the domain name, but again that would require deep packet inspection to extract and correlate with the clients. Definitely possible, but probably not deployed.
With DNS blocking if you try to look up a "forbidden" FQDN you get back either a bogus NXDOMAIN or A records chosen by the blocker.
DoH bypasses DNS blocking pretty cheaply. DNSSEC would detect it and stop but doesn't bypass it. Tor bypasses it but at considerable cost.
The (eventually indefinitely delayed) UK government plans to institute mandatory censorship of the Internet relied on DNS blocking as their backstop. The idea was if anybody anywhere in the world didn't voluntarily agree to obey censorship rules, they'd be blocked in the UK. The government would just accept that some proportion of users would install Tor to bypass that restriction. DoH means "some proportion of users" potentially becomes "everybody with a modern browser" and that was not palatable.
You can still do DNS over VPN. That is, I could set up an unbound cache on a VPS and secure my traffic to that server using wireguard or openvpn. This just pushes the eyeballs out of my home and into someone else's datacenter, though.
The scheme (https) is implied but isn't transmitted anywhere. An adversary can infer you used HTTPS because it was port 443 and looks like TLS traffic.
The hostname (www.duckduckgo.com) is somewhat implied by the destination IP address on the connection, and is also transmitted in the clear as part of TLS Server Name Indication so that the receiving server knows which service you wanted. In TLS 1.2 and earlier the site's certificate is also transmitted in the clear (but this is fixed in TLS 1.3). Encrypting SNI is a work-in-progress.
The path and query string are encrypted. An adversary can't discover what they are, nor can they tamper with them successfully. The total overall amount of data sent is not hidden, but clients can (though most do not) add padding to hide exactly how much of this was "real".
The fragment identifier (#foo) is not transmitted anywhere it remains only on the client (web browser).
Headers, body and so on of both request and response are encrypted, and the same caveat about an adversary knowing how much data was transmitted and when applies.
I remember when I answered a Stack Overflow question about how Domain Validation for certificates in the Web PKI work thinking that just a year or two earlier the answer would be hazy and probably get marked unsatisfactory even though it was true - because it was so vague and few people would be in a position to confirm it. As it happened they'd asked after the Ten Blessed Methods were formally required and so those are the answer, written down in black and white in a document I could offer as a reference for anyone to look at.
† The hostname part is less obvious than the rest it's fair to say because HTTP's Host header is just a header and thus encrypted, and you need extra insight to realise SNI needs to exist.
If a CA is compromised (which was very rare, even under historically more lax oversight than today) the bad guys would need to issue themselves a cert from this compromised CA, get it logged, and then from an on-path position use the certificate to MITM you and capture your URL which presumably they wanted very badly as this seems like a really expensive approach.
The CA does not have the ability to decrypt eavesdropped HTTPS traffic for example.
What do you think “private mode” is, exactly?
I’ll tell you what it is: It’s a mode where your local web browser doesn’t save its history, which only means that people who has physical access to your device cannot see this saved history. Your ISP can still see everything of consequence, and your DoH provider can see most of it.
[0] https://arstechnica.com/tech-policy/2014/12/newly-published-...
Maybe I'm ahead of the adoption curve here, but I see no overall reason they wouldn't be.
What makes you say that?
It's useless for real "privacy"
i.e. "works until someone actually cares enough to take active measures to track you."
It's also really useful for testing. For example building my WebAuthn implementation I hit "Cancel" a lot. In your ordinary session the browser soon remembers this site tried a WebAuthn registration, the user hit "Cancel" so let's suppress that because it'd be annoying if sites harass you with such requests over and over. Subsequent attempts soon just silently fail - that makes it really annoying to debug the backend. Maybe a refresh will fix it? Maybe I should wait five minutes? Who knows.
But the browser intentionally doesn't remember what happens in a Private window. I can hit Cancel to check that works as expected, then open a fresh Private window and registration still works fine there instead of silently failing.
Likewise I had a Cookie bug, where a typo meant enduring session cookies that were supposed to be cleared sometimes weren't. Private windows don't preserve cookies, so I could walk through all the steps to reproduce from a "fresh start", try something, then just throw that Private window away and make a new one for the next experiment.
None of this is impossible without Private windows of course, but it was more inconvenient when we didn't have them.
With their transition from selling widgets to services I wonder how much longer that will be true. And considering their attempt at iAds the privacy incentive is more historical accident than an unchangeable, core culture.