DuckDuckGo's Privacy Abuses
lemmy.ml
lemmy.ml
The "View ID" + "Fraud Vector" + "anonymized UA" + "anonymized IP" + "search query" are then shared with Microsoft Bing Private Search API.
"Signals" could include raw IP address, just not directly associated with the search query. Microsoft owns both the Azure service and Bing API so it can just match up the two separate requests on the backend to de-anonymize the user.
https://www.searchenginejournal.com/microsoft-announces-priv...
As Snowden's PRISM revelation highlighted, the US has outsourced a huge part of their intelligence gathering to BigTech. Thus US companies have a huge profit incentive to collect as much personal data as they can on their users. (It's not just the tech companies - I remember reading about how Ford downloads your contact list, and recent calls, from your car when you take it for servicing from their service center). So it's a no brainer for US companies to harvest as much user data as they can. Who wouldn't love to have the US government as their client, with their near unlimited wealth?
So companies like Apple and DDG have just resorted to using "privacy" just for marketing, to increase their user base, while they slowly abuse the misplaced trust of the user and slowly keep increasing the data they collect from their user.
And tech people and venture capitals have realised that there's money to be made out of data. And not just for data's sake, eg. selling it by the gigabyte, but by holding to that data and offering features with that data. Take for example Facebook. They don't "sell" the data by the gigabyte, but offer advertisements which are placed to people according to the data (with some algos which are also valuable, might even argue more valuable). Same with Google. However when it comes to DDG, I've yet to see DDG ask permission to my contacts for advertisement purposes. They've yet to create an account system to link all my devices' queries together for a more targeted advertising profile.
So to me this article seems fear mongering. Should I switch back to Google instead, now that some favicons are loaded through their services? I still think DDG comes out ahead.
I have tried using Searx but its user experience is nowhere near even DDG which lacks behind Google, too.
Some privacy issues with DuckDuckGo
A large part of the list is ‘they cooperate with X that I don’t like’ ‘X that I don’t like works there’ and similar conjecture.
And to top it off ‘A judge told them not to link to some sites and they don’t’. Hardly a ‘privacy abuse’. More like a typical attempt at cancel culture.
Exactly. By this standard I should not buy my food from any grocery store on this planet because they sell cereal sold by Nestle which want's private ownership of water that I'm against. This type of logic is not scalable in the least.
Edit: spelling
According to the author's comment, they published 2021 edition at [1], which updates some information and note other issues.
It sucks to have experiences like the author of TFA because it’s very difficult to be taken seriously.
https://searx.space indexes most of the public instances.
Also, would like to say if you have TS;DR extension installed, it has a search engine: TS;DR Search which is an instance of searx and can be set to default in firefox (which I personally use) coz firefox doesn't show option of searx to be set as default search engine.
When you install this, it automatically provides its own search option in the default search engine menu. Its search is an instance of searx.
For example, if I search for "esd windows" in https://metager.org, the first result "Should I delete ESD Windows..." changes to "ESD West Windows". In reality, I actually wanted the former but the result changed and the latter became the first result even after not displaying it after first time querying. For me, this is unacceptable and indicates manipulation (for whatever motive).
So, back to DDG. Search results are comparable to meta search engines (I've now realized). I'll put up with whatever problems it has for now. And man I miss the keybindings, made my life less painful.
- kagi.com - you.com - qwant.com
EDIT: you.com does better on the first page, but then they leak data to CloudFlare and Google via 3rd party JS on FAQ page. Come on.
EDIT2: qwant.com looks promising, thank you for the tip!
Care to explain what exactly you saw as I am curious (Kagi dev here, and no, we don't make such requests - likely to be your browser extensions).
I have advanced blocking in uBlock Origin and all 3rd party scripts are blocked by default. Not sure how DDG came there (maybe because I came to Kagi through it?), but I have checked agsin and for CF it says:
d33q65j1hc8iiu.cloudfront.net
assets.kagi.com
I assume you are using CloudFlare as CDN for your assets (can't check right now)? If so, it is a weird decision for a privacy focused search engine. Of course there are degrees to privacy, but CF is too big to be trusted imho.
EDIT: no, no extensions apart from UBO. :)
Would be nice if you double-chcecked both claims before making allegations publicly (or at least contacted us for clarification) as we do not have the resources of a big company to right all the wrongs said about us.
Everything about Kagi and privacy is available at kagi.com/privacy
If it matters, you sure made the mark for me, and I will definitely check out the engine further.
We do use CloudFlare for our CDN, DNS name server, JavaScript caching, and DDoS protection. We're not planning to move off of CloudFlare any time soon, but we've worked with them to ensure that they do not store user queries in their logs (completely masked out), they redact the last part of user IP addresses so no individual IP address is stored while keeping the benefits of bot detection and DDoS protection, and their javascript analytics tracker is turned off so there shouldn't be anything CloudFlare client-side.
Thanks again for the time you took looking into all this! It's great to have people out there that care enough to look and report what they find. Much appreciated.
One thing they did properly is turn off mail after a single bounce or junk mail marking - the mail loops with the big mail providers and the big mailers tell you exactly who marked your mail as junk and you're supposed to immediately stop mailing them, but that doesn't stop LinkedIn or Facebook.
Just asking, it's ok to be crazy. Admitting it is the first step to enlightenment. We're all a little crazy in one or more ways.
- What It’s Like to Get a National-Security Letter: https://www.newyorker.com/tech/annals-of-technology/what-its...
- Secrets, lies and Snowden's email: why I was forced to shut down Lavabit: https://www.theguardian.com/commentisfree/2014/may/20/why-di...
- PRISM: Here's how the NSA wiretapped the Internet: https://www.zdnet.com/article/prism-heres-how-the-nsa-wireta...