PRISM fears give private search engine DuckDuckGo its best week ever
venturebeat.com
venturebeat.com
http://commons.wikimedia.org/wiki/File:Upstream_slide_of_the...
They're logging all your URLs and headers. How much are you willing to bet they can't decrypt https? I dont understand all the hubbub _is focused solely_ on direct server access (the bottom half of the slide), when "Upstream" access is just as big a concern.
EDIT: rephrased my concern about direct vs upstream
I don't think there's a way to guarantee your mail always travels over TLS/SSL secured connections, but I suspect more of it does than you think.
This is a hard one to solve. GPGmail seems to get broken with every Mac Mail.app release. Vast numbers of people rely on webmail - which'd need server-side or in-browser GPG decryption. My Mom's not going to use command like gpg tools. How the hell do we bootstrap our way up to ubiquitous encrypted email?
If I implement this, will I become famous?
I think there are complications though - you need to be very sure that rogue javascript can't dig around in your plugin and extract my private key. I'm not sure how securely sandboxed plugins can be.
It's upsetting. It's a breach of trust for the provider and the government. It's more principle than technical.
Both the "upstream" and "direct" methods are upsetting, just in different ways and for different reasons.
If it's less expensive to ask someone to hand over the data (in bulk) rather than burn CPU cycles cracking SSL (again: in bulk), then go for it.
Even if it's feasible to crack SSL for a few crucial messages, it's likely not so for the volumes of data the NSA are capturing.
I'd bet quite a bit, though not "my life", that they do not have a generalized "read everything" ability for all forms of SSL. They may have what cryptographers would call "a crack", but that's a low bar, and doesn't prove they have a practical attack.
However, DDG is currently using 128-bit RC4, which is very weak. [1] I wouldn't care to bet anything that the NSA doesn't have an RC4 cipher crack that is practical to run on wide swathes of traffic.
RC4 is very popular, which I believe is because some people claimed it was a defense against the BEAST attack. I researched this for work, and I couldn't find anyone whom I trusted saying that was a good mitigation. The people I trusted merely observed that RC4 was not vulnerable, but never said you should switch to it. Only secondary sources ever suggested that. My conclusion was that there was a reason for the primary sources never suggesting that; in response to a theoretical break of the rest of SSL, the correct move was not to move to a solution that had much more practical attacks already known than what BEAST demonstrated. But now it's even sillier; BEAST has been either entirely or almost entirely mitigated in browsers (there's no server-side defense against BEAST, but there's a client-side one you can use, and browsers now have it). As far as I can tell, RC4 should be abandoned and we should resume using stronger ciphers for SSL. Anyone still concerned about BEAST should update their browser.
[1]: http://nakedsecurity.sophos.com/2013/03/16/has-https-finally...
Not having seen any blog posts screaming, "OMG, my site is being hijacked wholesale," I can only assume that the NSA isn't doing this (or has managed to squelch by legal order every single person privy to the real cert at MITM'ed sites, which is absurd and would beg the question, why not obtain the private key from these people in a similar way?).
For internal (or routed through) US traffic - while Verizon's lack of interest in protecting customer data is probably shared by major backbone providers - I _strongly_ doubt even the NSA has enough gear hanging off backbones to actively MITM any significant proportion of the firehose that'd represent. Even the AT&T "secret room" probably doesn't house enough gear to be able to create fake(signed)certs and MITM every SSL connection for millions or more simultaneous users browsing every https site under the sun.
Having said that, I'd bet good money the _do_ target specific SSL traffic - has anyone checked the SSL connections to TOR entry and exit points recently? That'd be one spectacularly obvious path to try "speculative MITM attacks".
https://www.eff.org/https-everywherehttps://en.wikipedia.org/wiki/ECDHE
Google is using it, a few other sites, too, though they are in the minority. OpenSSL supports it since version 1.0.0 that was released in March 2010.
On the one hand, don't take my word for it; I also have not found anyone I trust who has verified my explanation directly. On the other hand, I did do my best to read the primary sources very carefully, both for what they say and what they don't say, and I was confident enough to implement more conventionally strong ciphers on the services I'm responsible for, so my money is where my metaphorical mouth is.
But in the light of the PRISM documents it's even more likely than it was before that the NSA doesn't have the ability to decrypt HTTPS, or at the minimum that the US considers it too important to risk giving it away by using it on routine Top Secret signals intelligence. (And/or maybe too resource-intensive to use for that.) The strongest evidence for this is that we haven't heard anything about such a capacity yet from Snowden, Greenwald et al., who all have the full PRISM deck (along with other documents) in their possession and would surely tell us about it if they knew of it. So either 1) the PRISM slides do mention the ability to decrypt SSL or SSH streams but Snowden and the journalists haven't picked up on it (not impossible given the apparent incompetence they displayed over "direct access"), 2) it's too sensitive to mention in a self-aggrandising Top Secret overview of upstream and "direct collection" Internet signals intelligence, which probably means it's not in use (or at least not in regular use) for upstream collection or 3) they really don't have it.
A supporting reason to think that they don't have it, or hardly ever use it, is the apparent emphasis on "direct collection" in the PowerPoint. Why go to the hassle of dancing the frenemy minuet with Google and other fairly-anti-surveillance Silicon Valley firms when you can just get what you want from upstream collection at the apparently more-accommodating telcos? This isn't conclusive because even if you could understand all the traffic into and out of someone's Facebook account you'd still like to be able to see the internal state of the account, in particular so that you'd know what they'd been doing before the upstream surveillance began. But I think it's at least as likely that the whole new focus on direct collection is a workaround for the fact that, thanks to SSL and SSH, upstream collection just isn't what it used to be back in the days of ECHELON.
As the slide said, You Should Use Both: direct collection to give you access to US-company servers, probably bypassing the HTTPS problem, and upstream access to give you data, probably only unencrypted data (email!), that passes through the US without going to a US-company server.
(If you want an exotic alternative theory, you could speculate that the PRISM document is a fake, a limited hangout http://en.wikipedia.org/wiki/Limited_hangout by the US spooks, maybe precisely to direct attention away from their ability to decrypt HTTPS streams. But this now seems unlikely, for example because DNI Clapper would surely have to have approved a managed release of a set of documents that both gave away the Verizon metadata surveillance and so also implicated him in perjury.)
They still don't have the private keys of the sites if they break into the CA.
Also, given that the world's best engineers work at either high-tech companies or the NSA there will be some who have switched between these industries, giving the NSA/CIA a headstart to get any information these companies hold through old-fashioned spy-tactics.
When you combine that with the beam splitter logo, things get a bit scary.
They were doing the spying and actively sending the data out.
https://duckduckgo.com/goodies#Science
https://duckduckgo.com/?q=how+much+magnesium+is+in+43+cubic+...
Still looks 2nd rate. I replicated one of my last searches (learning rails): rails find if element is in array
First hit on google is the stackexchange answer with .include? (which I was spacing-out on)
DDG yields the Array docs, which is correct but is a helluva lot of info when I'm looking for a concise answer.
Now you could argue that I should have omitted "find", and there was a time where that was how search engines were used, but the fact that google got the semantics right is why it is first rate.
...and of course, I had no idea if !so would work before I tried it. The obvious one always seems to work:)
DDG's bang notation uses SO's search rather than the search engine's results.
Note that DDG's bang notation is also redundant with Chrome and most other browsers that let you set your own search engine keywords. Chrome's is especially nice, just type the first few letters of the site's URL and hit Tab and you're in a site specific search. It works automatically for any site implementing OpenSearch (or you can add it yourself by right-clicking the search box), and you don't have to memorize any keywords, so that's two advantages over DDG right there.
On the other hand, did DDG just use Bing API, and only Blekko crawls the web? Or do I get my search engines mixed up?
Every web search engine depends on one of these indexes: google, bing, blekko, yandex, baidu.
In this case you and I think that our respective search engines are providing the better result.
If you ever find yourself wanting to fall back on Google's results, just throw !sp at the front of a DDG search for StartPage's proxied Google service (or !g if you absolutely must go to Google). DDG has many, many shortcuts for directly searching StackOverflow, GitHub, Amazon, Wikipedia, etc.
It's not much, but at least I'm no longer leaving a huge slimy trail behind me online.
The USA was founded as the most free, exemplary democracy in history and what we saw in this scandal is precisely the opposite of what this Nation earned so Google could exist. Then Google betrayed us all and was in bed with the government in the most sinister way possible since 2009.
Honestly? I'd rather give someone else a chance. Then if DuckDuckGo spies on us in the future, I'll switch again.
"While our indexes are getting bigger, we do not expect to be wholly independent from third-parties. Bing and Google each spend hundreds of millions of dollars a year crawling and indexing the deep Web. It costs so much that even big companies like Yahoo and Ask are giving up general crawling and indexing. Therefore, it seems silly to compete on crawling and, besides, we do not have the money to do so. Instead, we've focused on building a better search engine by concentrating on what we think are long-term value-adds -- having way more instant answers, way less spam, real privacy and a better overall search experience."
That said, maybe there'd be an issue if you enter personally identifiable information as a query. But who does that?
This does not mean that it is not compromised, of course. But its why people would believe it isn't compromised. And its a much better reason than your sarcastic imitation.
The same is true of Hushmail. How did that work out?
Mostly, I don't like seeing condescending, inaccurate statements.
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
There is nothing inaccurate about claiming that people believe that DDG is protecting their privacy because of how the website presents itself and the claims made by the company. That is exactly why people believed (and many continue to believe) that Hushmail is protecting their privacy. The way companies advertise themselves is not necessarily reflective of reality.
https://duckduckgo.com/privacy#s2
Of course, they could be completely full of shit or unknowingly compromised.
My concern is this: even though they don't _collect_ information, they could still forward it on to authorities and not violate this policy.
However, they have a freaking TOR node, so it's almost a moot point.
And even if you wrote your own OS and compiler from the ground up - who wrote your BIOS? Your network card firmware? Your disk controller software? Your CPU microcode?
We _all_ abdicate our trust-chain _somewhere_
The "merely technical" solutions are going to be important in the meantime. Duckduckgo, encfs, Tarsnap, GPG, Tor, ForceSSL - things like that will (probably) help in the meantime (especially if we can help convince "regular users" to use them), as will encouraging places like DDG to implement TLS cyphers that use forward secrecy.
Shifting use away from, as Bruce Schneier puts it, feudal architectures, both puts the Government on notice that its methods aren't appreciated, and creates a damaged class (the SAAS feudal lords: Google, Facebook, AWS, Apple, Salesforce, and others) who can petition the government to lay off the tactics as it's hurting business. https://www.schneier.com/blog/archives/2013/06/more_on_feuda...
Hell, push this hard enough and a sufficiently feasible decentralized VOIP might become sufficiently common enough to put the WiFi carriers out of the voice business, relegated to carrying encrypted bits. They might know your handset location, your data usage, and the Tor entry point you're using, but that's it. It's something I've been giving though to.
Asking for a friend.
If Google can't oppose the NSA in installing backdoors (by the way, this has to be demonstrated), DuckDuckGo can't oppose them neither.
Best luck to the team of DuckDuckGo, it's a nice project.
Tapping off the fiber.
there is no need to know what the public key should be - only that there are several [more than expected] different keys. Any distributed organization (including Google itself who can be fully expected to monitor which certs their users receive especially after Iran/Diginotar story) could notice it and thus identify the MITM. Thus Google must be on it. Thus no need to involve extra certs from CA though of course i'm not arguing NSA's ability to do that.
I mean _seriously?_ Helicopters, silenced assault rifles, security dogs, and 72 cops - sent in against someone accused of _copyright infringement?_ And then a Hollywood showreel of the raid gets produced and publicised?
I _like_ New Zealand, they talk the talk, but when it comes to walking the walk - they're lead around by the nose to do whatever the US wants.
Part of that would be replacing Gmail. That can be done, but what good (free) options exists for a webmail solution?
I'd also love this instant to cut gtalk (or "hangouts" which it is called now. hopeless), but Google just declared hate on XMPP, so setting up your own node will land you on your own tiny island.
The trend is clear though: Google is stuffing the exit-holes while the US government is requiring more and more of Google's data.
If you haven't started moving out yet, you better get started. And for the love of God, ditch Chrome. Support someone who supports the open web and respects your privacy.
Does it somehow make tracking my every move online okay if it's done for profit?
EDIT: phrasing.
We really need something better than having these MASSIVE amounts of callouts. It's like those pictures of Internet Explorer totally taken over by toolbars, except it's a different set on every single site on the web. Bah!
Now I can't even look at Google anymore, they're like a spouse that cheated on you. You knew the spouse may have been watching you, but at least they weren't fucking with someone else while you trusted them.
Can someone explain to me (or point me in the direction of something that explains) what Google and Bing store in terms of tracking when you are not logged in?
Obviously you can use VPNs or TOR to be really safe, but do you need to go that far if you want an untracked search on Google and Bing?
IP+time is enough to get your personal identity information from your ISP (physical location of the endpoint, billing information), I have no idea if Google's relationship with ISPs is good enough to buy that or if it's only available to cops.
> They have access to IP+time, your search query, and
> cookies for correlation to other requests. It's
> valuable information
Valuable for blackmail, but not really useful for anything else; the commercial value of information rapidly degrades over time. Knowing I want to buy a new fridge today is very valuable, knowing I wanted to buy one last month is nearly worthless. > IP+time is enough to get your personal identity
> information from your ISP (physical location of the
> endpoint, billing information), I have no idea if
> Google's relationship with ISPs is good enough to
> buy that or if it's only available to cops.
Despite what the RIAA think, a user agent's IP is nowhere near accurate enough for use as identification.I hope that ISPs do not release personal identity or billing data to arbitrary third parties. I know my ISP (sonic.net) claims they don't[1], and even privacy-insensitive companies such as AT&T have privacy policies that would forbid them from selling personal data[2].
Even if it were possible for random companies to obtain personal data from an ISP, I doubt that Google would have any interest in participating.
>>Valuable for blackmail, but not really useful
>>for anything else; the commercial value of
>>information rapidly degrades over time.
>>Knowing I want to buy a new fridge today is very
>>valuable, knowing I wanted to buy one last month is >>nearly worthless.
I think that blackmail is already bad enough. Considering which topics somebody might want to learn about on the internet, various diseases for example. >>I hope that ISPs do not release personal
>>identity or billing data to arbitrary third parties.
I hope that too. But this information is gathered and stored somewhere in flawed systems which are operated by humans which might decide to follow their own interests more than the interests of the customers. I know of at least one story where an employee of a search engine has been using his privileges to stalk other people.That depends on what they can get out of the data, besides the obvious. I'm thinking of the story about Target knowing that a girl was pregnant before even her father did[1]. Even longer trends can probably be derived, regarding personality traits, income, etc. That information is worth a lot even months or years after it was captured.
[1]: http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...
I search for a lot of random crap with more curiosity than intent to buy. I looked up the price for several windmills , the late 19th/early 20th century style, (~$1000, by the way). For weeks or months afterwards, I saw windmill ads on a sizable fraction of the websites I visited.
To be fair, it's far more likely that I am going to by a windmill than a random ad viewer, but the probability is still staggeringly low. There had to be a hundred other products I was more likely to buy than the windmill, that would be more valuable to show me. But no! I had viewed their product and I! Must! Be! Targeted!
I really wonder what the set of products that do well from targeted ads looks like.
Interestingly, from the CPMs I've seen re-targeted/re-marketed ads perform on par or below contextually targeted ads. No one even comes close to Google for contextually targeted ad inventory (unless you are operating in a narrow niche and you are selling inventory directly, but lots of time and money to even match them.)
Maybe not when I'm coming from our company's NAT (700+ employees behind a single IP address) - but the number of people on my Comcast connection is limited.
My ISP, Time Warner/RoadRunner, claims that they will do so. It's kind of ambiguous because their declaration combines several services and kinds of data covered by different laws. I think the applicable part for their cable ISP service is:
In the course of providing Time Warner Cable Services
to you, we may disclose your personally identifiable
information to [...] consumer and market research firms,
credit reporting agencies and authorized representatives
of governmental bodies.
Selling their DHCP logs and customer records to a commercial data aggregator (who could then sell it to anyone) appears to be compliant with their privacy policy.I don't know what data Google and Bing are collecting, but here is one quote from the wikipedia entry on internet privacy concerning the AOL search engine:
A search engine takes all of its users and assigns each one a specific ID number. Those in control of the database often keep records of where on the Internet each member has traveled to. AOL’s system is one example. AOL has a database 21 million members deep, each with their own specific ID number. The way that AOLSearch is set up, however, allows for AOL to keep records of all the websites visited by any given member. Even though the true identity of the user isn’t known, a full profile of a member can be made just by using the information stored by AOLSearch. By keeping records of what people query through AOLSearch, the company is able to learn a great deal about them without knowing their names.
As for Google the thing is that they’re also an advertising network so basically they track you all around the web.
It's not that simple, otherwise there wouldn't be any value in using an Onion architecture. Assuming you're using HTTPS, which every decent search engine supports, they either also need to create a fake but acceptable certificate for the domain, or to also control entry nodes and match the entering requests with the exit ones.
The NSA might be able to do it, but it's not just a matter of controlling an exit node.
Not if you are using TLS, which you should be using regardless of Tor.
http://duckduckgo.com/l/?kh=-1&uddg=http%3A%2F%2Fwww.dmv.org... (every time you click on a search result you actually click on a link like this,which redirects you to the actual page)
Is it just for pagerank?
However, I noticed that if you use their HTML version (i.e., use duckduckgo.com/html/<query> instead), that they don't do the click-tracking. The only downside I've noticed is that there's no infinite-scrolling mode, you have to hit "next".
Whether they're still tracking the search queries, though, I have no idea...
From memory the main reason they do this is to allow downstream websites to determine if a user was referred to them by DuckDuckGo without the actual search term. IE you know they came from DDG but with no leakage.
I run searchcode.com (which provides a lot of the code doco and sample results) and since this was done I can now determine how much referral traffic actually comes from DDG but have no idea what you were searching for when you click through.
Look at the source of a search page and you'll notice that they include scripts directly from google.com...
Why do you think it is called PRISM? It's probably named for the way they are splitting the fiber and recording everything.
(The NSA may very well be doing both.)
As long as the SSL cert isn't compromised, I don't see how this is possible.
They were doing this in 2007 at AT&T Worldcom I expect it only got better over the past 6 years.
So rather than being redirected to a secure connection, I happily communicate with the attacker instead.
I don't see them in the current lists, so DDG should contact Mozilla and Google to get added to their preloaded HSTS lists[1][2] so all connections will automatically happen only over HTTPS.
[1] http://dev.chromium.org/sts
[2] https://blog.mozilla.org/security/2012/11/01/preloading-hsts...
I wonder though if now all services regardless of their real focus will start marketing privacy as a feature and muddy the waters, making it hard for consumers to discern who is really about privacy and who just uses it as a marketing ploy.
>Why step into the footsteps of the dinosaurs?
I'd think adding E2EE to email would be like what pagerank did to the search engine. Why build from the ground up when you can build on the shoulders of the giants?
It's not like google or anyone else is going to do it. And looking at DDG traffic, it seems like it is a growing need. Then again, how to you monetize encrypted emails? contextual encyrpted ads? ;)
(I agree. The only thing I use Chrome for is Facebook)
I especially dislike its name, it's odd and too long to type, and again, duck 'walks' slowly, not a good sign.
can this be renamed to something better, and shorter? sometimes name does matter.
2. DDG is SSL, so there's some hope that the traffic is not visible to a passive observer, even the NSA.
Then you can go to Settings and make it your default.
I'm also in the process of selling my surface pro and going back to a Linux laptop (OneNote 2013 sucks with touch on the Desktop for me .. and Microsoft's Windows8 version won't allow you to not use Skydrive)
Also, I pay Microsoft .. why won't they let me save my OneNote docs in a secure way using their Windows8 apps?