Epic, The Privacy Browser
epicbrowser.com
epicbrowser.com
What we need is not yet another startup that tries to make money on our private data (yeah, read Epic's FAQ how they make money). We need a stack of hardware and software you can easily trust. My dream is to use a computer that is produced on an open design by one of hundreds of fabs that would call out a competitor that puts backdoors into the chips to boost their own reputation. My dream is a software stack that is completely signed by tons of trustful developers with the possibility to easily add my signature after bit-reproducibly compiling code I checked. If this comes true, people will identify easier the packages that were developed by companies only and find ways to replace them for a trustworthy stack.
Open source apps distributed via Android market for example are closed source apps compiled by the developer from code he maybe shared and that was possibly modified by google running on video-audio-multi-sensor-bugs with several agencies having a direct wire to them. If you still use windows, your PC is not better than that. Think about it. Thanks to Snowden we can finally talk about these issues without a single person calling us paranoid.
We don't make any money from anyone's private data or any data (period). We make revenues at this point exclusively from searches you do via our private search engine & always protect your searches' privacy.
Thanks for other ideas...others can comment...
Also, the example they make at the bottom asking the reader to imagine hundreds of people following them around and watching their every move is a bit disingenuous. It's more like a handful of people following millions. At that point in time, you're not much more than a data point.
And then there's no way for you to know when the line is crossed between what you consider tolerable and what you feel infringes on your privacy.
They were detectives, not FBI agents.
[1] Provided that you think a simple Googling of "backpack" and "pressure cooker" in the days following the Boston Marathon Attack implies a probable link to terrorism.
Personally I'm not terribly bothered by the targeted ads themselves, but I see them as one symptom of a deeper problem. The data being used and sold is not data that I volunteered; much of it is data that is leaked unintentionally as a side effect of technical design of the web and other information systems. (This includes data like "the person who is visiting site A today also visited site B several times last week.") These leaks make it hard to know or control how much we reveal about ourselves (and to whom) when we use these systems.
Even if you aren't concerned with any specific information you may accidentally disclose today, you should still be interested in ways that our software and networks could be designed to give users better knowledge and control over these disclosures, because (a) other people are legitimately concerned about this, and (b) you may have reason to be concerned in the future.
Please do not forget that intelligence isn't all-pervasive in a person. Privacy tends to be a trigger issue for many intelligent people on a forum like Hacker News.
For example banks and insurance companies want to know everything possible about you. So do potential employers. Profiling people and putting them into categories and calculating their risk profiles makes their position weaker.
For example: Google "lump in the testicles" and browse medical sites. Then wait one week and try to get mortgage or insurance.
Actually, wait a sec. So is government snooping of communications, the problem is they're not following the existing regulations.
So your scenario doesn't exist.
2) "[they] have no incentive to do so". They have no incentive in trumpeting that they are doing it. But without having read their ToS, I'm sure they got that covered.
Of course this is pure speculation and I have exactly zero proof that this is the case. I would actually never have believed those claims 6 months ago, but today, I wouldn't be surprised.
As the person who originally replied to you mentioned: it'd be political suicide for Google to provide the information they use for their own ad targeting to others, even for a fee, beyond users' explicit consent. It'd also be business suicide, given that it would allow people to cut Google out of the loop, rather than using Google as the advertising platform.
1) Nobody really actually wants to buy that data in the first place. Companies that buy ads just want to sell you shit, they really, really don't care about you in the slightest. Sorry, but your personal information by itself isn't actually worth a damn thing. Hell, if companies were willing to pay for my browsing history I'd sell it to them myself.
2) Why on earth would Google sell one of its advantages? If Google sold data Facebook or Microsoft would buy all of it in a snap and Google would be screwed.
And how is that relevant anyway? Do you think the government then turns around and hands it to other companies for shits and giggles?
In other words, neither Google nor Mozilla has to be involved to track you.
Let me lay out a specific scenario.
It's easy enough for insurance companies (or a 3rd party who's willing to sell that data to an insurance company) to run genuinely informative health sites that have good rankings on Google's SERP, and thus get high clickthrough. Such a site can on clickthrough set a cookie on your client for you, and/or fingerprint your browser (c.f., EFF's panopticlick), and/or use an ETag as a 'cookieless cookie'/browser identifier.
Once they've got a way to identify past behavior for a browser (i.e., look up health concerns for an identifier), they have something to sell to insurers.
Okay, well, clicking on an organic result is a weak signal of health risk / pre-existing condition, all you know is they ended up on a page.
Suppose you, as an insurer, want a stronger signal of whether the person using that browser has a health risk/pre-existing condition. Just put out some AdWords. Here's where Google really helps a website build valuable, saleworthy data.
Search for something:
https://www.google.nl/#q=breast+check
Click adwords ad for breastcancer.org
Opens a page to: http://www.breastcancer.org/symptoms/testing/types/self_exam/bse_steps?gclid=CMC0rI74uLkCFQSS3godSSAA_Q
With this value in the HTTP request's Referer header:
http://www.google.nl/aclk?sa=l&ai=CA_XBGe0qUqOhD4e--QbWkoHoBqzGitEBlN6ongr-x6YMCAAQAVCVu9RFYJGEk4X8F6AB7qeO_wPIAQGqBCBP0MOny_HlmSNBJ-QDgpzV0OqbNNjg7FAjv3nX9hy9u4AH-tdx&sig=AOD64_1DSbXWQm-KpW0fMRFiY3lcjn3kQg&rct=j&q=breast+check&ved=0CCwQ0Qw&adurl=http://www.breastcancer.org/symptoms/testing/types/self_exam/bse_steps.jsp
I was logged into my Google account while I did this.
Google empties the Referer for organic results always (if I've read&remembered correctly, for a few years they scrubbed Referer only for logged-in users, as a privacy boon). But they still leave it for their paying advertisers!
So, if you run breastcancer.org and put out some ads and are selling your data to insurers, you now can link search terms to impressions to clickthroughs to a browser identifier. Then you just need to offer a low-latency service that serves the insurer a list of health conditions for which a particular browser seems to be at-risk for.Note that all of this works end-to-end, so SSL/TLS doesn't prevent the host serving a clickthrough from sharing data.
The part where your browser is identifiable (uses etags, sends cookies, presents a consistent fingerprint) is the weakest link.
Disclaimer: I have no reason to believe breastcancer.org is anything but altruistic, I just needed to find a medical condition for which there was a clickable AdWords ad and which is expensive to treat.
>For example: Google "lump in the testicles" and browse medical sites. Then wait one week and try to get mortgage or insurance.
I'm calling bullshit on this one unless you can provide a concrete example."Life insurers are testing an intensely personal new use for the vast dossiers of data being amassed about Americans: predicting people's longevity.”
http://online.wsj.com/article/SB1000142405274870464860457562...
It was just a pilot test, but that was three years ago, so who knows where is now.
There is a huge difference between publicly stating for the whole world to see that you have cancer by posting it to Facebook and searching google and browsing webmd and an insurer somehow surfacing that search and browsing intent and then acting on it. You backed up nothing.
Many advertisers screamed (and are still screaming) bloody murder over Do Not Track settings being on by default, and this is a message to send to them: your screams are irrelevant and you have no right to track me.
It sounds like you are saying: "I'm not doing anything wrong, so why do I need any privacy".
On the Do Not Track, I think turning it on by default is a bad idea. It gives companies no incentive to follow it and abide by it. (Yes, they have no reason to abide by it right now either). There is no law that says they have to abide by it, but it seems to me they might be more willing to abide by DNT if those that are tracking conscious were to turn it on, rather than it to be turned on by itself. They wouldn't lose as many people to track if it was opt in instead of opt out.
Maybe read some of the many posts around about privacy and freedom and rebuttal of the "I don't do anything wrong so I don't have to hide" argument: you could start with the schneier's blog: https://www.schneier.com/blog/archives/2006/05/the_value_of_...
But let me try to make a point of why you should personally care even though you don't know or understand why. This is a case of closing the barn door after the horse is gone, if you later learn the hard way you should have cared and go the extra step of protecting your data, you couldn't go back and get your data back. And the sad reality is that if you have to learn this way, it means that history has indeed repeated itself again and you're enjoying living under a tyranny.
Sorry, but this sounds like the cr*p touted around by politicians and over zealous "patriots", along the lines of "if you don't support the war then you are not a patriot and therefore must support the terrorists".
Despite what most on HN would like to believe, outside of the tech community most people don't care about their privacy being invaded, and the OP is entitled to his opinion of not caring just as you (and I) are too overly caring. I believe that is the true definition of freedom, to be able to make ones own choice?
2) Taking one cent from your back account every day wont make your day to day life worse. Day to day being worse is not a standard that is useful.
2) It is a useful standard. I avoid being nit-picky about the little things, and so I like to make a distinction between things that are worth worrying about. If ~$273 is taken from my bank account over my entire lifetime (based on average lifetime), I'm really not going to worry about it. If data tracking is on the same side of the distinction as taking 1 cent from my bank account, I'm fine with that.
But this nazi example is one everybody can relate to because we're all familiar with it. But if this is too strong we could go a bit further in history and talked about richelieu "If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged." and the current state of us law [2].
[1]: http://americablog.com/2013/03/facebook-might-know-youre-gay... [2]: http://www.harveysilverglate.com/Books/ThreeFeloniesaDay.asp...
There's a few point to raise here: how do you object or prevent the sale of your data ? how much of the money from the sale of your data went to your pockets ? what control do you have on your sold data over time ?
Then it's not only about you and your life, ever heard of first they came [1]?
I'll go further to suggest that you are unaware that knowledge, intellect, understanding, and the capability to grasp these concepts is in no way correlated with susceptibility to fear and worry.
I think this along with the source itself should be something really high on your todo list if you want to establish a trustful image
That said, I completely agree - before believing this browser to be completely secure, I need to see the source and be able to compile it myself.
...not that I'd necessarily personally do that, but I'd like to know that people have.
History, Password saving, Auto-suggest, Web Cache, Automatic Browser Updates, Spell check, DNS pre-fetching & cache.
How does Epic protect against browser fingerprinting?
There is no agreed-upon way to prevent browser fingerprinting or device fingerprinting at this point. There are many fingerprinting techniques which a solution would need to protect against. While we are working on a more thorough solution [...]
I imagine it could send the default plugin/header/user agent of IE/Chrome/Firefox, or random stuff each time...
As for plugins, that's a bit more difficult - I wouldn't mind an option to ask if I wanted to let a site enumerate plugins, but you start getting into header games & pointless reloads there if you're not careful.
[1] I force my own fonts for everything, so no UX issues for me. No idea how much of an issue it is for other folks.
I think you meant, "will not" rather than "will".
I wonder if they did a really poor job at researching what already exists and are truly clueless about iron, or if they outright lied for marketing purposes. Hopefully they're not clueless about privacy and are not lying about features, though I would not bet my privacy on "hopefully" specially when epic browser website lacks an https version and epic browser bears a unique fingerprint on panopticlick.
I want to know what's on sale at the nearest grocery store, and I wouldn't be too creeped out if you knew where I was geographically. But maybe that's just me.
Sounds sketchy.
I've never heard of Spotflux before, and don't know that they aren't owned and operated by one of your advertising partners.
The truth is companies don't know what to do with all of your data.