DuckDuckGo Privacy Pro
spreadprivacy.com
spreadprivacy.com
The product should have strong privacy built into it and a commitment from the owners to keep it this way. Calling it something mundane and then competing on the merits of the product will favor mass adoption.
How many users of WhatsApp really understand the implications of E2E? Would they have installed it if it was call 'Chat App Privacy Pro'?
> we use the open-source WireGuard protocol
Any info on how that is implemented?
Did they build some plug-in, where a user can enter VPN details/credentials?
Asking since I'd love to have something, where I can add my own self-hosted VPN details to have browser only (not the whole machine) connected through VPN.
They claim to use wireguard, which might be something a browser extension can start on-demand?
AFAIK, there's still no proper SOCKS user authorization. So if I do something like that on my own VPS, I'll quickly have like 10 000 open connections from Pakistan there.
> At least in Firefox there's builtin UI for configuring it separately from OS
Yes, also extensions like FoxyProxy.
SOCKS4/5 configuration in Firefox is a pure joy. Adding a Putty tunnel there is probably the only simple way to achieve what I described in the comment above.
Add a dynamic tunnel there.
Start the session.
Then enter 127.0.0.1 and the port you've chosen as a SOCKS v5 proxy in Firefox options.
Congratulations! Your poor man's VPN is ready :)
So if you'll pardon my pun, I think they've probably just duck-taped a standard VPN client app into their browser app.
If it's true, then I'll only double the pun.
But that's why I'm also curious about the "No need to install a separate VPN app" part.
Never tried WIreGuard in Windows, but AFAIK it tries to mean serious business, "no connection runs past". So there should be things similar to WinPcap or something like that under the hood.
And they're unlikely to work without installation. Moreover, quite likely require a reboot after the install. But I could be wrong.
These days the bar for privacy should be higher than "we don't log your activity, trust us." We should aim higher than VPNs.
I've been enjoying iCloud Private Relay. Basically it's a type of onion routing. From a privacy perspective, it narrows your leap of faith to "trust that the system is architected the way we say it is and there's no out-of-band collusion among the relays." With that, the entry node (Apple) shouldn't be able to see your destination and the exit node (Apple partner) shouldn't be able to see your IP.
Fun fact: it breaks Google search for me and forced me to switch to DDG! I got a captcha almost all the time. In a way, I see that as a positive sign that it's really working to protect privacy.
Good:
- I like that you can pin websites for easy access, the grid is visible when the address bar is focused or when you open a new tab. Similar to Firefox but more intuitive!
- It blocks a fair amount of ads (incidental blocking, because they block trackers)
- The history is cleared after a period of inactivity or when you dismiss/quit the app, and you can "fireproof" specific websites that you want to preserve
- The accessibility features like text size and page zoom actually work, unlike Chrome or Brave where it's been broken forever (at least for me)
Less good:
- The search settings are often "forgotten". It doesn't seem to be related to the history clearing but things like "disable ads" or "safe search off" are often reset...
- I believe all the icons on the favorites grid that I like so much are fetched via a duckduckgo service, ie DDG sees the domains you've favorited...
- Some network errors result in a black page, especially anything SSL-related. Very frustrating when it happens in a captive portal...
>We scan dozens of these sites for your info and, if found, request its removal, even handling back-and-forth confirmation emails for you automatically behind the scenes.
But using a VPN for privacy is a bad idea in the first place. At least Apple and Vivaldi get that and have moved to two party privacy designs.
To hide the IPs of the servers you are visiting from your internet provider?
With a VPN, the VPN provider sees those IPs. How is that better?
And why would I care that my internet provider sees those IPs in the first place?
Because someone may trust the provider of the VPN more than they trust their ISP?
>And why would I care that my internet provider sees those IPs in the first place?
You might not. Other people do. It's not your place to decide what other people care about.
My VPN provider has a vested interest in not sharing or re-selling my data, if caught doing so it would cause a major loss of business for them and potentially permanently tarnish their reputation. Additionally they provide a stable IPv4 shared with many other users. Tracking is still possible, but is far less trivial and not so easily correlated with a county/state.
So I use a VPN. It keeps me safe from script-kiddies who might discover my IP when I visit their website. I provide free help for people having trouble with HTML/CSS, so I visit a lot of strange places.
The use cases for VPNs include hiding piracy from your ISP, evading IP bans, accessing geoblocked content.
You're right that at the end of the day, it's just someone else seeing where you visit. And frankly, I think VPN users would be a higher target of surveillance anyways.
And if the VPN's company is from any 5-9-13-whatever-eyes country, you can assume all that information is being collected by them anyways.
>You're right that at the end of the day, it's just someone else seeing where you visit
You write this as if it's some trivial little detail. Who that someone is that is privy to your browsing habits is a significant detail.
“… many of the ISPs in our study surveil consumers, use and disseminate consumer data, and the privacy implications of such use and dissemination. “
source: https://www.ftc.gov/system/files/documents/reports/look-what...
Everyone with an internet connection should at least read the Key Findings, just the first few pages of that report.
I assume that regional or small ISPs have similar practices, but these big ones have been M&A’d into massive orgs having control of “a much larger and broader cache of consumer data than ever before, without having to explain fully their purposes for such collection and use, much less whether such collection and use is good for consumers.”
And I get to circumvent the prying eyes of my ISP, office's BYOD network, etc.
I would wait to see what DDG does, rather than base it on what other companies have done in the past.
[1] https://docs.searxng.org/ [2] https://4get.ca/about#what-is-this