If Google can't oppose the NSA in installing backdoors (by the way, this has to be demonstrated), DuckDuckGo can't oppose them neither.
Best luck to the team of DuckDuckGo, it's a nice project.
Tapping off the fiber.
https://duckduckgo.com/privacy#s2
Of course, they could be completely full of shit or unknowingly compromised.
My concern is this: even though they don't _collect_ information, they could still forward it on to authorities and not violate this policy.
However, they have a freaking TOR node, so it's almost a moot point.
And even if you wrote your own OS and compiler from the ground up - who wrote your BIOS? Your network card firmware? Your disk controller software? Your CPU microcode?
We _all_ abdicate our trust-chain _somewhere_
The "merely technical" solutions are going to be important in the meantime. Duckduckgo, encfs, Tarsnap, GPG, Tor, ForceSSL - things like that will (probably) help in the meantime (especially if we can help convince "regular users" to use them), as will encouraging places like DDG to implement TLS cyphers that use forward secrecy.
Shifting use away from, as Bruce Schneier puts it, feudal architectures, both puts the Government on notice that its methods aren't appreciated, and creates a damaged class (the SAAS feudal lords: Google, Facebook, AWS, Apple, Salesforce, and others) who can petition the government to lay off the tactics as it's hurting business. https://www.schneier.com/blog/archives/2013/06/more_on_feuda...
Hell, push this hard enough and a sufficiently feasible decentralized VOIP might become sufficiently common enough to put the WiFi carriers out of the voice business, relegated to carrying encrypted bits. They might know your handset location, your data usage, and the Tor entry point you're using, but that's it. It's something I've been giving though to.
Asking for a friend.
This does not mean that it is not compromised, of course. But its why people would believe it isn't compromised. And its a much better reason than your sarcastic imitation.
The same is true of Hushmail. How did that work out?
Mostly, I don't like seeing condescending, inaccurate statements.
http://www.wired.com/threatlevel/2007/11/encrypted-e-mai/
There is nothing inaccurate about claiming that people believe that DDG is protecting their privacy because of how the website presents itself and the claims made by the company. That is exactly why people believed (and many continue to believe) that Hushmail is protecting their privacy. The way companies advertise themselves is not necessarily reflective of reality.
I mean _seriously?_ Helicopters, silenced assault rifles, security dogs, and 72 cops - sent in against someone accused of _copyright infringement?_ And then a Hollywood showreel of the raid gets produced and publicised?
I _like_ New Zealand, they talk the talk, but when it comes to walking the walk - they're lead around by the nose to do whatever the US wants.
there is no need to know what the public key should be - only that there are several [more than expected] different keys. Any distributed organization (including Google itself who can be fully expected to monitor which certs their users receive especially after Iran/Diginotar story) could notice it and thus identify the MITM. Thus Google must be on it. Thus no need to involve extra certs from CA though of course i'm not arguing NSA's ability to do that.