DDG founder says Google's phone, manufacturing partnerships thwart competition
apnews.com
apnews.com
However, antitrust doesn't (and shouldn't) protect you from competition. Too often I see companies just do a really bad job and the leadership just sits there collecting a paycheck and complaining to Congress about [big bad company].
Yelp is the poster child for this. Arguably even Mozilla is guilty of this [1].
DDG ultimately is just repackaged Bing search results. Bing itself lags behind Google and has the resources of a trillion dollar company behind it. It's not just a question of how much money you have but how you spend it. Look at Blue Origin. Look at the Metaverse.
So DDG's upper bound seems to be however good Bing is and honestly Bing isn't that good. What is their path to improving? I'm not sure they have one. But I don't think Google's relationship with Apple is the core problem.
Back in the day, Microsoft got in trouble (rightly) for bundling the browser. That's because the barrier to installing a new browser was quite high. Here phone manufacturers give you a dropdown to change it (which I think they should be required to do, as they are).
Antitrust won't solve poor execution.
To improve it you need money, and you won't get any if the competition field isn't even. So, it's part of the core problem. It's very reductive to look at it and say you are bad because you lack research and development in this front, but you have to look at the whole picture.
"What is their path to improving? I'm not sure they have one." Doesn't mean they don't have one.
DDG could improve if Bing improves so the problem isn't Google, it's Bing and DDG's strategy.
So, I am wondering how much money you would really need. Because if Kagi can do it, why can't Bing do it?
[0]: https://kagi.com
Which is a lot. So I use Google a lot. But still, very impressed with Kagi.
Kagi is awesome otherwise, by the way. I'll keep saying it so more people hear about it.
DDG, on the other hand, has gone way downhill. I still sometimes use it if I am using a private browser window. It's flat out terrible. Even with safe search turned off, it's clearly been dumbed down to be PG-rated. It misses a lot of things it used to not. I don't get how they are going to stay solvent down the road without money being continuously set on fire.
i can't stress enough how right you are on this.
we literally got the IBM PC as a fairly open platform because IBM at the time had just got out of a very lengthy and serious anti-trust case and didn't want to even risk getting into another one.
we literally owe the revolution that the ibm pc has been to antitrust laws.
That was true at one time. I've been using DDG for many years; daily drive it and Firefox, but have been experimenting with Edge and Bing, now Copilot.
Honestly, Bing search is amazing, better than google in my head-to-heads for quick reference or learning about something your not as familiar with. Both have a lot of "data field" results, which I want to curmudgeon about being distracting but are honestly quite handy sometimes, same goes for suggested searches. DDG is very old school by comparison, but that's also what I want when I'm drilling down.
An aside, I'm surprised that nobody really talks about Edge. I run Firefox specifically because I don't want to run V8. Edge has a really good implementation Tree style Tabs, another feature I refuse to sacrifice, and overall it's featureful but still fast, the only thing it's missing is never getting implemented, containers. The LLM integration though is super cool, and makes me wonder what iPhones will be like when Apple finally gets this tech in it's products.
This is hard to take seriously.
30–50 steps across all of your devices, maybe if you have 10 devices.
And a desired "one click" is similarly silly. Just opening an app takes a click. It's pretty reasonable to take another couple clicks to get to the setting, and a final click to set it.
I mean, Chrome has larger market share than Edge or Safari, and it's not default, and I'd say it takes more work to download and install a browser than change a search default.
So it's pretty clear that when users perceive something as better, they switch. None of my non-tech friends have ever even heard of DDG, so that's going to be the start of the problem right there. Not Google's payments.
Interesting, our own (anecdotal) data is the opposite. Better search results trump everything and this is the main selling point of a paid search engine. Privacy is important, but less people would be ready to pay for a privacy respecting search product without also better search.
People who would have rather not ventured within a mile of an ‘as closed as it gets’ iPhone are kind of forced to, because Google on the other hand makes it between a rock and a hard place.
If there were a lot of people like that, I think the Microsoft Phone would still be around.
Maybe postmarketOS will gain support for more devices but without WhatsApp support it's hopeless.
This must be personal preference. For me the #1 thing I do on my phone is browse the internet, and having choice of browser is a vital priority in this. Android allows you to choose browser, the other big maker only supports a single browser engine.
But I just can't wrap my head around Google tracking every single thing I do on my phone, even the things I don't do explicitly and there is no fathomable way to stop that unless I start everything from scratch. From the bricks, to sand, to water, and cement to setup a phone using some ROM that might or might not support the Android phone model I bought and if it did then even a patch might upend everything I had setup (including but not limited to bricking my phone for good) and then do that all over again. Not to mention that if I used that ROM a lot of essential apps might just don't even work to begin with or I might not even be able to install them, forget working.
A browser is important but a kinda small, part of overall phone usage. At least for me.
No, you can't. Your device will fail hardware attestation because you "tampered" with it. Then everyone starts refusing you service based on that alone. Your bank app stops working. Your streaming app stops working. Your games stop working. No doubt one day WhatsApp will stop working as well and at that point my phone might as well be a paperweight.
This is a good point. Foundational/Frontier models already pack lots of contextual knowledge that makes user behaviour data collection less relevant.
Whilst building AskPandi, I have only found user’s location to be the only major signal that would greatly improve search results and answers.
For some people, directly supporting a huge, unethical, advertising company with money is a show stopper.
> when my phone lost support
This is another serious problem: e-waste. My phone will not loose support, ever.
This is false: https://news.ycombinator.com/item?id=26784382 and https://old.reddit.com/r/Purism/comments/pcos2x/would_it_be_...
> neglected an IOMMU, so the baseband (or any other device on the bus) can wreak unlimited havoc
The Librem 5 doesn't need an IOMMU, because it uses separated components, and it uses serial buses (USB 2.0/3.0, SDIO, I2C and I2S) that don't allow direct memory access, so there is absolute no chance of the WiFi/BT, cellular modem, GNSS and USB controller being able to access the RAM or the SoC's cache
From https://news.ycombinator.com/item?id=30769589
Do you think that all laptops are also totally insecure, since they use USB?
The USB URB structure have a field named 'dma_addr_t transfer_dma', used for DMA access. I've abused that to chain vulnerabilities. To boot, it is possible to develop an I2C-B2C or SPI bus master which is capable of DMA toward the host memory. Linux 2.5 kernels and later, USB device drivers have additional control over how DMA may be used to perform I/O operations.
Do any of these guys actually read the hardware specs or do any real hardware hacking?
Android runs mainline Linux. The Linux phone has no benefits.
PostmarketOS fills the plaything niche like the Librium 5 and pinephone do but much cheaper with much better old hardware. Aside from a checkmark of running the latest kernel and hardware switches what can the librem 5 do an Android phone can't do much better? They aren't good phones.
Can you name any good real world uses?
Why on earth do you need two separate devices (phone and laptop), when you can use one for both use cases (phone with convergence)? No synchronization or double-backups and maintenance required. Also, decreasing the amount of e-waste is a good thing as well as fighting with the user-restricting duopoly.
It looks like for you Linux itself is also just for tinkering, since you can already do everything with Windows and MacOS, isn't it?
More: https://forums.puri.sm/t/which-applications-do-you-find-to-b...
Their device depreciation policy is literally just Google, they refuse to support anything that isn't a Pixel (because of the security chip, although as I understand it, there's other manufacturers who could probably work as well - Pixel is simply chosen because Google promised to open up the microcode on the security chip, which hasn't happened yet) and their stance on user privacy is so extreme that it gets in the way of user freedom - they literally offer their own SafetyNet implementation and are aggressively against rooting whilst refusing to understand why people root to begin with (the most common reasons is by far hosts based adblocking and their recommendation, VPN based adblocking, gets in the way of a normal day-to-day VPN or something like Tailscale).
(Relatedly - the toxicity problems of their community against criticism of GOS or even being interested in non-GrapheneOS privacy projects are well known at this point and with a smaller community, you're bound to run into something that isn't answered on the general internet at some point. This makes that component somewhat unavoidable. I've never seen a non-corporate, non-FSF run community be such extreme NIH types.)
For freedom, I'd moreso point towards projects like LineageOS.
I don't see why we can't have both, but this doesn't really a fair criticism of GP's comment. The specific word GP used was 'privacy', not 'freedom', and you are attacking GrapheneOS's stance on the latter, not the former.
GrapheneOS is more focused on privacy over freedom, as you said ("their stance on user privacy is so extreme that it gets in the way of user freedom"). They have chosen to prioritize one over the other.
> For freedom, I'd moreso point towards projects like LineageOS.
This might be true, but LineageOS doesn't have access to microcode either, and certainly GrapheneOS is more 'private' than Lineage, assuming that GrapheneOS hasn't been compromised either internally or at some point in the AOSS supply chain. Except for niche mfgs like PinePhone et al, Google is probably the most free of the major manufacturers (ironically, less private but more free).
I agree that we should aim for both freedom (as in free speech, not necessarily as in free beer although it'd be nice!) and privacy.
Both are critically important, and the efficacy of the latter depends in large part on the former.
If you hadn't noticed, we get a zero click RCE on phones basically couple every years. That's the type of stuff GrapheneOS worries about, not whether its users can block ads, however nice that is.
Can you elaborate on this? I've never talked to them but found strcat's posts here on HN to be extremely informative.
I also wanted to address a few things:
Applying updates quickly is extremely important. You seem to consider GrapheneOS supporting devices that get timely updates and make developing for them easier to be "cheating", for some reason. Regardless, every GrapheneOS change has to be ported to each monthly, quarterly and yearly release of Android, which isn't a trivial task, as I'm sure you can imagine, but it's done correctly and quickly, because it's important.
Now, I also wanted to address the last part of your comment here, because judging from your other comments in these thread, you seem to have a bone to pick with the project and its team. It's unfortunate that a lot of the time, project members and community members taking the time to properly answer questions and explaining how things work is seen as a bad thing because it is not the thing that you (or anyone else, I'm just using you as an example here) wanted to hear. The team considers it very important to help people understand how things work, as there is unfortunately a lot of misinformation about these topics. The fact that we're passionate about explaining how these things work, and the fact that it clashes with people's preconceived notions about things often means they're hostile in return, which is unfortunate, but still, it is important.
An RCE that only affects a non-root component or a component that ran with system privileges anyway will not be enabled or facilitated by this.
Of course current root implementation may be not be as secure or convenient as they could be. For example after each update they must be re-applied, from a downloaded app, leading to people updating later and opening another problematic supply chain. But that could be remedied if they were better integrated into ROMs.
The problem is that GOS is taking a privacy approach that's so niche that it borders on being useless[0]. If you're the type who is at threat of say, state actors (or has convinced themselves they are), then it makes complete and total sense to use GOS with all the anti-user crap it entails. You get a completely secured fortress of a phone out of it.
What makes the GOS community toxic is the subsequent attitude taken by developers to other privacy models. Most people aren't "state actor" degrees of paranoid, they just don't want Google enabling hidden settings and pass the users photos onto their servers; they might want to reign in Play Services (without abandoning it entirely) or take advantage of GOS' anti-background GPS capabilities. These are all legitimate features that aren't undermined by having root. Google isn't generally a malicious actor with these things (you're not worth enough to them to do these tactics) and if someone is capable enough to install GOS they are also likely capable of maintaining decent app installation hygiene which limits that too.
The response from the GOS community when these things are brought up amount to 1. Fork Off (not happening because user != developer), 2. "You're holding it wrong" or 3. Ban the user for being a Calyx/Divest shill or whatever else (not endorsing either project).
There's also the projects noted history of using license trickery to prevent non-Vanadium browsers from implementing a System WebView that are why I'm considering them toxic to Android privacy as a whole. (And general trademark nonsense to prevent people from achieving the fork off bit) The GOS community is extremely "GOS or nothing" and it sucks because GOS itself is genuinely a technical achievement.
[0]: Which to be clear - multiple online privacy communities have this specific issue, that's not just on the GOS community.
You cannot have 'privacy' without 'security', because your privacy measures can easily be circumvented and defeated otherwise. That's why calyx os or other grift projects are useless on both.
The design goal IS security. And each decision is motivated by such design goal. An unconstrained system user that circumvents the security model just to allow some users to intercept network requests to do adblocking is irreconcilable with the design goal of having a secure OS. What's stopping the adversary from terminating TLS requests and snooping on your plaintext traffic when such privileged API access is possible?
If you really want some adblocking, you can set-up to use a DNS server that does that. Such measure is not the best there can be, obviously.
Finally, if an user can bypass the security model, so can the attacker. The security boundary between "adversary user" and "not hostile user" is hard to define and enforce.
GrapheneOS is a security and privacy project, and puts significant effort into advancing both. Security is a prerequisite for privacy, and getting that right is extremely important, but all of that is exactly so that you can then safeguard privacy.
GrapheneOS has many features which are heavily towards the "privacy" side of the scale, rather than the security one. Features such as Storage and Contact scopes are features which allow you to preserve privacy by granting apps just the information you need, instead of giving them bulk access to your data. The network permission is as much as a privacy feature as it is a security feature. Being able to deny sensors access from apps so that they can't access them is a privacy feature etc.
I'm mentioning the above because it seems like people tend to split security and privacy into completely different camps in a way that doesn't make sense. Those two things play off each other, and one needs the other to be effective. GrapheneOS focuses on both.
I hope that helps make things a bit more clear!
Not OP, but: Google. I don't believe Google can be trusted with Android. I'm stuck with the iPhone, or getting a phone that can run CalyxOS, because I basically only need apps that a solely available in the Play Store. The thing is, I don't care for messing around and trying to make my phone work and flashing alternative operating system. So I'm stuck on the iPhone, because I trust Apple slightly more than Google.
I still use Android, but the lifespan of every Android device I've ever owned is two years or less. They just don't survive that long. Whether it was the old Nexus 7 tablet that hit a boot loop issue, or charging issues that I've run into on most Pixel phones. My previous pixel even had to be repaired (thankfully under warranty) because of the charge port failing. But again it died 6 months later right around the 2 year mark.
The only saving grace is that I'm usually spending around $300 for the Pixel phones, so it's still likely cheaper than if a bought a higher end Samsung that lasted longer.
Funnily enough, the longest lasting "Google" device I've owned is a ChromeOS Lenovo Duet that I purchased back in 2020. The tablet is decidely sluggish these days, so I don't really use it anymore, but at least it still functions.