Our XMPP services at DuckDuckGo
dukgo.com
dukgo.com
I personally am a fan of DDG and use it as my primary search engine. I do wish they'd change their name as it makes it difficult to recommend to non-technical people.
The name alone puts me off to a large degree, although the way it seems to go out its way to say "we're not google" puts me off too. Overall I just don't like the way they advertise, I don't feel like it should be appealing to the sort of person I am.
Thanks for using DDG!
Thanks for what you've done with DDG. Privacy is a difficult sell when everyone else is offering "free" services in return for it.
Is there any chance that you could create another brand with a name that I could get non-tech people to use? It could be exactly the same everything except the name. The number of times I've convinced someone to switch until they hear the name...
No immediate plans to change the name or branding, but duly noted! We really do appreciate and consider all feedback.
I want to like DDG and I've switched to it from time to time, but the thing that always gets me is that I loathe the branding. I'm really, really sorry, about that and I appreciate what you're doing with DDG, and wish the branding didn't turn me off to a peculiar degree, but Google is such an easy choice and it doesn't get on my nerves.
I know that I'm an outlier in this, but I don't think it's altogether a completely impossible or uncommon reaction to be turned off by the name.
Thinking about it, the reason UK people don't like it might be to do with the https://en.wikipedia.org/wiki/Glottal_stop
I imagine it's easier to soften the Ks with an american accent. For an english person putting two of them in a row like that is just, shall we say, taking the piss.
Perhaps it's not specifically the glottal stop, but there is certainly some articulatory havoc going on when I try to say your search engine's name out loud. I have to bounce my tongue off the roof of my mouth twice in quick succession in a way that's never normally required and it feels quite unnatural.
(Google, on the other hand, is literally fun to say, even though it's a silly word, and hardly professional.)
I have found it easy to recommend to non-technical people. (In the early days of Google, I had to spell it for people too... at least this is 3 common words.)
I think the emphasis on converting non-technical people is also often misplaced. Non-technical people don't care about any of the issues that lead to development. The number of people using Skype shows most people don't care about privacy. That doesn't mean DDG's offering is not unique or valuable, it's just that the people to recognize that value will not be the majority by any stretch - but, it never is - and converting people who have the hardest time understanding that value should be a low priority IMHO.
In promoting privacy, DDG captures the union of early adopters, technically literate, and digital evangelists - all groups that are most likely to understand as well as turn around and effectively promote it (for example, by setting the homepage and default search engine after cleaning up a system for a friend)... This is the crowd to keep happy (without raising the barrier to entry either... for example, late adopters will not use bangs or care that you search Hacker News too, but the early adopters appreciate it greatly). These were the same types of people promoting the early Internet to the masses, who barely saw the point in having a computer.
In that vein, one of the best things for DDG, IMHO, would be to make setting ALL browsers as easy as possible (homepage+default search). (I know I'm not saying anything new...) There are add-ons for individual browsers, for example (which I tend not to use, because I like vanilla installations without extensions to upgrade later), and conventional methods (which I prefer, but have been de-emphasized in favor of add-ons), but further-centralizing the process of applying these customizations would be nice. For example, I'd rather download a single native app or portable script (WSH) that was capable of searching out browsers and - through check-boxes - setting their homepage and search (ideally to the SSL search), via the browser-native method (or add-on method), in one pass (usable offline, and ideally at an easy-to-type URL like "duckduckgo.com/tools"). This would help high-turn-over scenarios like tech-support shops, which has the chance to affect the most users but are also under pressure, so want to do the minimum possible (Idea: actively promote to these places).
On a different note, I'm curious how the costs associated with this XMPP service are expected to grow and how it is seen from the business side. If 100000 people started to use it for messaging, would it become too burdensome and be discontinued, or is there a plan for cost-recovery (or is the ddg bot enough of a case)?
I can't imagine ever saying "I DuckDuckGoed it" - since that breaks the verb 'to go'.
Although I've conditioned myself over several years to say "I searched for it [on DuckDuckGo]", I sometimes still find myself saying "I Googled it".
Idea: "I duckduck GOT it!"
I ducked-it.
Has a nice ring to it.
I've been using Conformal's Xombrero browser for some time now, and on first run Xombrero offers a choice of search engines, my choice being https://duckduckgo.com/lite
Perhaps DuckDuckGo could acquire a ddg.* domain to make it easier to access?
[1] Hotbotted? AltaVista'd? Lycos'd? Yahoo'd? Asked Jeeves? Did any normals ever say any of those things?
[2] "Tweet" is as close as any other service has come to google-style verbing of their brand by the general public. And that's only the case when you stretch the definition of 'general public'.
Even before the internet, verbing was happening. Hoover is a brand of vacuum and people say "hoovered" / "hoovering".
All become common English words, many of them in the dictionary but started as brands.
There are plenty more if you go back to the 19th century (eg. Heroin)
edit: Wikipedia has a list:
http://en.wikipedia.org/wiki/List_of_generic_and_genericized...
If "Googled" goes the way of "Xeroxed" then the potential value of "DuckDuckGo-ed" is as irrelevant as "Ricoh-ed".
https://duckduckgo.com/?q=test
compare to
http://www.yandex.com/yandsearch?text=test&lr=20996 http://www.bing.com/search?q=test&go=&qs=bs&form...
Shows that the results appear to be coming from Yandex not Bing, which is what DDG says on the page.
https://duckduckgo.com/?q=how+much+wood+could+a+woodchuck
Appears to be sourced from Bing, but to say its just Bing is incorrect.
Also the top zero click info is sourced from all over the place (I should know as I provide some of them).
Thanks for the link. I've been wanting a shorter domain name for duckducgo ever since I first began using it.
I noticed this morning that http://lmddgtfy.net/ now takes you to the developer's blog page instead of to duckduckgo.
Many thanks for the share!
They should really just rename it to Duck Duck Gray Duck.
Non-technical people I tell the name to remember it more for the "controversy".
But then, I always say "teach the controversy" :)
I know it's shallow to judge a product/service by its name, but for most people hearing the name for the first time counts as an initial encounter with the product/service, and since that can leave an impression, it matters a lot.
For any media coverage about Lady Gaga, you are more likely to see column inches dedicated to deriding her appearance than you are to discussing her music.
When the Occupy protests were at their height, there were so many comments along the lines of "They may have a valid point, but no-one is going to listen to them if they dress like that"
All too often I see comments criticizing appearance as being something that indicates their value to be less. frequently it comes in the form of "I know it has value, but you should change the appearance so others can see".
I think this is counter-productive. Appearing business-like may make more people believe you are business-actual, but it also reinforces the attitude that means people judge the business-like as business-actual. It may be good for you but bad for the world. Those who wear the right suits and walk the right walk but cannot actually do the right work can deceive a lot of people.
I think pushing back against this attitude is a worthy endeavour.
- Neil Graham, Screaming Duck Software.A serious product, made by serious people, focuses on serious issue (privacy) shall look like one.
1. SSL/TLS embedded in the standard.
2. Easy to set up OTR encryption, (as well as any other standard I imagine).
3. Messages are "pushed" to clients, rather than "pulled".
4. The standard is simple, and servers like Prosody are super-easy to implement (unlike Exim).
5. There are plenty of clients already available. Admittedly it's not something I've researched much, but I doubt it'd take all that much to get Adium or whatever to work like a simple email client, (but with xmpp).
I'm aware of all of the social reasons why such a thing may not work, but I'd be interested to know if it were just a question of getting people to adopt it, were it to exist.
RAM is cheap.
Start with the core spec, RFC 3920. Right away you'll run smack into the problem of XML namespaces, which is a feature that every XML library pretends to support, but with a whole bunch of caveats. Before you can do so much as initiate a session, you will need to search the universe of XML libraries for one that implements a full parser and has good namespace support.
(When I wrote an XMPP library, I ended up using libxml2 because the only platform I care about is Linux.)
Next you'll have to implement encryption (TLS) and authentication (SASL). As with all security-related code, this part of your application is terribly easy to fuck up in a non-obvious-but-user-endangering way. Does your TLS library check that the certificate is valid? Many don't by default. Does your SASL library implement the spec correctly? SASL is complicated and difficult to test, so it's easy for even experienced developers to break authentication for some subset of users.
(I used gnutls and gsasl to do most of the heavy lifting, but still ran into many problems. For example, my library doesn't work with some versions of ejabberd because ejabberd's implementation of SCRAM-SHA-1 was broken: https://support.process-one.net/browse/EJAB-1632).
OK, so you've found a full-featured XML library, you've figured out TLS and SASL, and you can send "hello world!" to another account. Think you're done? Hahaha, no my friend, you're just getting started.
To do anything interesting with XMPP, you need to implement XMPP extensions (XEPs). There are currently three hundred and twenty seven XEPs, indexed at http://xmpp.org/xmpp-protocols/xmpp-extensions/ , and many of them are at least as large as the core spec itself. XEPs cover such important functionality as multi-user messaging, file transfer, voice/video chat, full encryption, avatars, and away messages.
(I decided to skip all that, not do any XEPs at all, and limit my library to simple one-on-one chats because that's all I needed it for. If you're writing something for use by customers, you will not have that luxury.)
And of course, it's all implemented in XML. Hope you've got a sturdy keyboard.
Implementing a lot of features is a lot of work. How is this different from any other protocol, or any kind of system?
With that said, John I'm very happy to report that thanks to your library I've been developing an XMPP client for months and have yet to even see any XML.
That said, thanks a lot for git-annex & the assistant =)
I still use XMPP with GChat and IMAP with Gmail. Either of those things changes I'm probably going to start using Bing and find a new email provider.
So if Google plans to kill Google Talk server and force all its users to switch to Hangout, it means all Google users will be cut off from the XMPP network. Way to go Google, on the road to evilness.
There are many practical reasons that people and organisations would rather be in control of their communications, so XMPP (or something, the protocol doesn't matter) is here to stay. The challenge is making that open network worth the big players' time, they currently don't seem to think it is.
To deal with an onslaught of spam, Google disabled incoming subscription requests for a short time. During this time, all other XMPP federation features continued to work.
XMPP also has a spec for server-side history storage, that allows for syncing to clients. I don’t know how well it is supported in reality, but understand that there are at least ejabberd modules for the server-side part and a plugin for Pidgin to view this stored history. Not perfect, yet.
I guess it is a long way till we get there, though :|
Half of these things (e.g. carbon copies) are spec'd out but barely supported.
Would it not have been possible to offer a XMPP MUC as a text-based interface to hangouts, to allow ‘legacy’ users to still be connected?
The X in XMPP is for extensible. I guess the point is Skype doesn't support XMPP or federation, and Microsoft is moving towards Skype and away from their SIP/SIMPLE chat services. Likewise, Apple's promise of an open standard for interoperating with Facetime turned out to be empty.
---
Edit: Found this: http://www.joecieplinski.com/blog/2013/03/30/hey-apple-where... http://www.imore.com/apple-fined-368-million-facetime-patent... http://www.techradar.com/news/world-of-tech/virnetx-slaps-ap...
And as you say - there's a bunch of stuff to support if you go the traditional route and try to bolt on more crap to MUC or <message> stanzas. We're considering just building hangouts on top of "ephemeral" buddycloud channels that just disappear when the last recipient leaves them.
A reason why there reportedly are backdoors in skype is because of government requirements.
For eg. see this news article about India asking Skype to setup local servers in India
http://articles.timesofindia.indiatimes.com/2013-05-20/infra...
No major government will forbid effective encryption, because citizens are far more afraid of other citizens than they are of the government. That's why governments request backdoors, or pass legislation permitting warrantless searches.
Think of it this way: your city council will never be able to pass a law forbidding people from locking their car door, because everyone with a car would be screaming about theft. But they could easily pass a law requiring car manufacturers to provide a master key to law enforcement.
Given this, it's better for webmail providers to not pretend to support secure mail.
Sure, the bot is nice to play with, but somewhat cumbersome in the long term for me. So why is this great? :)
Being a search engine is not exactly a prerequisite to running an XMPP server. :-)
[1] http://xmpp.net/
Anything we can fix?
My server was down[0] for a few hours once and so was my XMPP account. After it was back up, I got a small VPS from a friend to act as a backup/fallback/redundancy-whatever. ejabberd offers that out-of-the-box, meaning that I now have two ‘nodes’ hosting my XMPP domains – if one of them goes down, I either don’t notice at all (if I was connected to the other one) or just have to tell Pidgin to reconnect. s2s connections will similarly just reconnect/don’t notice.
I liked Prosody better, though, and the arcane failure modes[1] of ejabberd still annoy me. So if you get that into Prosody (or did, I didn’t check in the last year or so), I will definitely consider switching back.
[0] Apparently Strato thinks you’re being attacked if a large stream of UDP packets from the 26C3 network hits your server. And I was just using my VPN…
[1] I recently moved that VPS and failed to adapt iptables rules on the other host. Instead of telling me that it couldn’t connect (at maximum log verbosity), ejabberd just did nothing/crashed. I can’t exclude an oversight on my part, but the failure to log anything was rather annoying.
Prosody clustering is on the roadmap, but it's a tricky problem to solve properly (and I don't think anyone has to date). We've even had people switch from ejabberd clusters to Prosody, as ejabberd's clustering wasn't working out for them anyway (it seems to be designed more for spreading load than increasing availability).
Our view is that we wanted to get the foundations of the server right before we began tackling such complex problems. Nevertheless I look forward to welcoming you back some time soon :)
But I wish you the best of luck with Prosody, as I said, I really liked it at the time and I trust it only got better :) – regarding the ‘soon’, 2015 is likely an optimistic estimate given Debian release schedules etc…
The value is not that someone has an XMPP server, the value is in having an XMPP server that everyone uses.
The goodies (https://duckduckgo.com/goodies) are really cool. Although they do not seem to consistently work in the chat client. Some do, some do not.
A "we don't track users" XMPP server?? Is this a thing?
Besides, use OTR with XMPP chat and it doesn't matter what the cloud provider says in their privacy policy.
Thanks for the feedback, and feel free to hit me up with questions (if you have any) at my $username at duckduckgo.com :)
EDIT: Or, hop on Freenode and chat with us in #duckduckgo
It makes less sense to chat on a free service that no one is using, but maybe some people will use it if there were a DDG email service.
plus, duck goes slowly and unstably, again, ugly naming.