This is vague. It seems like it just means: "we have a TLS certificate and will be a proxy between you and Google"
This is vague. It seems like it just means: "we have a TLS certificate and will be a proxy between you and Google"
It's a bit more than that -- the search query is encrypted client-side. This means that the private.sh search proxy cannot see what the query is. Then, the query is delivered to the search engine. The search engine does not know the IP origin of the search query.
This means that the search query and the identity of the searcher is decoupled, providing significantly more privacy.
Hope this is clear!
Is this client side encryption the same regular TLS encryption that I would normally (no proxy involved) send to the search engine or is there some kind of buy-in from the search engine to handle it a different way?
It requires the search provider to utilize NaCl to decrypt (requires buy-in from the engine).
That said, I agree, you could absolutely do the same with an onion router. This simply provides the benefit without having to do so.
As someone who uses tor everyday, you basically can't get any higher quality general purpose search than duckduckgo or searx to actually load over onion routing. If you position yourself in such a way that your results engine returns queries on par with those two (or preferably better) you will have a rock solid product in your hands.