3 ms·
The site is giving me a 429, but discussion Reddit seems to indicate this is misleading. DuckDuckGo has code that includes calls to `getBoundingClientRect()` wh
by bfrydl 8y ago
The site is giving me a 429, but discussion Reddit seems to indicate this is misleading. DuckDuckGo has code that includes calls to `getBoundingClientRect()` which can be used, most likely with other metrics since it just tells you the size of the window, to fingerprint visitors. However, inspection of the source reveals it's just part of normal layout code.
https://www.reddit.com/r/privacy/comments/ad4h0u/duckduckgo_now_fingerprinting_visitors/ https://www.reddit.com/r/privacy/comments/ad4h0u/duckduckgo_...
- garrettj 8y agoHad a feeling that this entire post was just privacy “purists” taking something a bit too far. I’m not confident that knowing the size of your browser window is enough to definitively ruin your life.
- adetrest 8y agoThis is frequently some of the most identifying bits of information about you. Have you try the eff's panopticlic? It'll tell you how much the combination of things like your resolution, available fonts and available extension can identify you 1 in a few hundred thousand or million of visitors. This is a legitimate concern for a privacy oriented search engine that claims not to track you. https://panopticlick.eff.org https://panopticlick.eff.org
- yellowapple 8y ago1) Just because it's possible to use this in an aggregate fingerprint doesn't mean the collection of this one datum in isolation is actually for fingerprinting 2) Given the context of the actual API call, this is probably for benign purposes and not for fingerprinting
- snazz 8y agoOne comment on that thread does call into question some of DDG’s previous actions and suggests that we might not be able to trust them regardless: https://www.reddit.com/r/privacy/comments/ad4h0u/comment/eddmri9 https://www.reddit.com/r/privacy/comments/ad4h0u/comment/edd...
- joering2 8y agoWe been there before! Google’s “Don’t be Evil” made everyone trust google until it came up they are working for all sorts of LE. Now its Duck supposed to be secure. Let me say again what I said multiple times: unless they are incorporated in some offshore or Switzerland, and none of their servers are on US soil (they are), then they either must work with the US government or US government using NSA already sees and read all your searches and can pinpoint them directly to you. They may even be forced by government to lie to their clients/users telling them we don’t spy or log your searches. Any other idea that in modern world american company working on american soil can build a web search engine that doesn’t give out / leak / cooperate with US government is very naive.
- throwawaymath 8y agoWithout commenting on its veracity, here is the essential claim quoted from the post: > DuckDuckGo is using the Canvas DOMRect API on their search engine. Canvas is used to make unique geometry measurements on target browsers, and DOMRect API uses rectangles. This can be verified with the CanvasBlocker Firefox add-on by Korbinian Kapsner. DDG has recently been redirecting some website navigations to cute pictures with remarks about their privacy promises. The organization is now seeking to expand their Internet presence. DDG are without question data brokers, and commercial websites that make promises like DDG does will not survive for long if they actually keep them.