29 ms·
DuckDuckGo browser seemingly sends domains a user visits to DDG servers
- tananaev 6y agoVery weak argument for why they do it. Using a service to retrieve a favicon? Surely there's a way to implement the same logic locally.
- heavyset_go 6y agoBitWarden does this, too.
- slenk 6y agoIf you host your own Bitwarden server you don't have to worry about that. Also different expectations
- yoavm 6y agoYeah, I would just have to worry about losing all my passwords ever.
- slenk 6y agoIt's really easy to back up the server and never lose passwords.
- heavyset_go 6y agoI can attest to this.
- heavyset_go 6y agoI host my own BitWarden server and had to explicitly deny using BitWarden's favicon lookup feature.
- toyg 6y agoBW already has all the URLs of services you use: you saved them yourself for them to keep safe. It's obvious you already trust them enough to know that sort of data.
- ghewgill 6y agoSo if favicons were gathered locally, then you would prefer that your own browser would reach out and make multiple requests to every (potentially dodgy) site listed on the search result page? Note also that these are favicons for results that DDG has already given you. This isn't tracking your clicks. The list of sites that appear on the search result page is not new information to the search engine that just gave them to you. EDIT: Like other commenters, I was not previously aware that DDG had a browser, and my comments were about this behaviour for the search engine results page.
- tananaev 6y agoAre we talking about search results or sites you visit?
- detaro 6y agoWhat about the issue linked suggests to you that it is about search results in any way?
- colecf 6y agoCan you explain your edit a little more? I still only understand your original viewpoint. Just because there's an app doesn't mean they don't have to contact DDG servers at all, right?
- tagawa 6y agoWe had already had created this anonymous favicon service for our private search engine. In addition, doing it this way avoids another request (and potentially multiple) to the end site. The service is private as we do not collect any personal information (e.g. IP addresses) on any requests for this or any service and the requests are all end-to-end encrypted.
- systemvoltage 6y agoWhy not do it locally? It is one extra request to the favicon link in the header and cache it. Or cache it when the user visits the website. Or explicit button in the settings UI to refresh favicons locally. There are so many options.
- haggy 6y agoYour answer to all these criticisms is a lazy one. You are saying "this already exists for other things so we use it regardless of what the correct method is". Just because something exists in one form doesn't mean it's the correct choice.
- oska 6y agoPlease don't downvote this reply from a DDG staff member (as I'm currently seeing). Even if you don't like the reply it's good that we're getting replies.
- aronpye 6y agoGood privacy is not based on trust. Even so, this incident is even less reason to trust you.
- marcinzm 6y agoThis is concerning because it indicates a lack of care in terms of privacy and understanding that the best privacy is achieved by knowing the least. Does this approach permeate their backend as well?
- Stevvo 6y agoA privacy focused browser shouldn't even have a backend.
- fulafel 6y agoI'm not so sure. I think the privacy-functionality trade-off is understood and expected by the users, it woul be used by very few people if it were extremely spartan. (But this instance, the favicon service, is not a good privacy-functionality trade-off)
- bad-apple 6y agoWhat would a browser even need a backend for? The only valid use that I can think of is Google's Safe Browsing list, but if ad blocking can be implemented totally on-device, surely that can, too?
- jeltz 6y agoThe use case I was going to suggest was a safe browsing list. Possibly also something like Have I been Pwned. So, yes, there are valid reasons to have a backend but they are very narrow and privacy is key when building them.
- markholmes 6y agoDoes this only occur in DuckDuckGo’s Android browser?
- jakejarvis 6y agoAnd the iOS browser it seems: https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf6f7f06922a96335cf75/Core/AppUrls.swift#L43 https://github.com/duckduckgo/iOS/blob/1ae03d7221180bd6791cf...
- BuckRogers 6y agoEssentially a way to collect where people are visiting. I believe them that it’s anonymous, this valuable info wouldn’t need to be identifiable to be of value. They should probably change the behavior to how it’s suggested in the thread, but I’m still going to use DDG over alternatives for the bang feature.
- coronadisaster 6y agoI don't really trust DuckDuckGo, but I use their search service because I trust Google less... I still trust Firefox more for a browser although it won't take much at this point to make me switch.
- projomni 6y agoa paranoid android-:)
- coronadisaster 6y agoyeah Android is a lot worst than using Google search
- kovac 6y agoThere's Qwant, a search engine. I'm using that. It's not as fast as Bing, but it does the job and seem to be trustworthy.
- stan_rogers 6y agoThere's always Startpage. You use Startpage; Startpage uses Google for you, with their own user agent - no history, no tracking.
- Nextgrid 6y agoHow does that work? What does Google have to gain from it? Google has pretty aggressive anti-scraping protections to protect against this exact behavior, so why would they allow Startpage to get away with it? What does Startpage have to gain from it? Unlike DDG, they don't seem to have any core product, so they fully depend on Google's goodwill which is very shaky grounds when it comes to a long-term business.
- smoe 6y agoStartpage.com says they are paying Google: "You can’t beat Google when it comes to online search. So we’re paying them to use their brilliant search results in order to remove all trackers and logs."
- lopmotr 6y agoNevermind privacy. How are favicons so complicated that they need a special service that understands edge cases. Just do it one standard way and if a minority of websites don't work, then exclude them. We've been through this mess before with all kinds of web standards devolving into mess.
- fiddlerwoaroof 6y agoThe standard way involves a meta tag, right?
- jakejarvis 6y agoThat's my understanding of how it's worked for decades... 1. Check for <link rel="icon" ...> tag(s) 2. Check for /favicon.ico 3. ...give up? Someone correct me if I'm wrong!
- plorntus 6y agoYou can also set it in JS still a meta tag and image I guess though. It's how some sites do the notification badge thing that is animated.
- plorntus 6y agoCan't seem to edit my comment on this app, but I believe you may also be able to set these in a web manifest json file too.
- FalcorTheDog 6y agoOne major issue is that the "standard" favicon size has historically been 16x16 pixels... which, in the age of high density displays will render either comically small or comically blurry. There are other meta tags like Apple's "apple-touch-icon" which has some higher resolution options. But already you can see the logic here isn't trivial.
- 6y ago
- CivBase 6y agoThis is a bad look for a company that is trying to build its brand on privacy and trust. Even though I don't use the DDG browser I hope they own up to this, rectify it quickly, and learn from it.
- projomni 6y agowell... i'd much rather fix their deep search so it's as good as google's and not worry about this like this:)
- haggy 6y agoPrivacy has to be scrutized constantly and be the top priority. If it isn't, then you're going to end up with another google. A direct correlation exists between the revenue Google receives for selling data and the quality of its search. Google focuses completely on tracking and search, with privacy behind a far far away afterthought (if it's a thought at all).
- CivBase 6y agoI'm sure Google's thinking about privacy. They're thinking "will our latest privacy violation create enough of an uproar to affect our bottom line, or will the users just accept it like they usually do?".
- dabbernaught420 6y agoIn my view, anyone who trusts ddg is a bit silly - founder has a bad track record on user privacy. Founded Names Database[1], a social media website designed to collect user information as aggressively as possible, before selling all the information to classmates.com. [1]https://en.wikipedia.org/wiki/Names_Database https://en.wikipedia.org/wiki/Names_Database
- Torn 6y agohttps://en.wikipedia.org/wiki/Ad_hominem https://en.wikipedia.org/wiki/Ad_hominem
- akent 6y agoDo they release the source of the webservice? Seemingly not. This is extremely shady.
- donedealomg 6y agothe owner of duckduckgo is extremely shady. he made big money in the past selling user data to the highest bidder. you can google all about it. I never understood why people trusted duckduckgo
- Carpetsmoker 6y agoWould it matter? I can release all the source I want, but what guarantees this is also what's running on the actual endpoint?
- bangonkeyboard 6y agoEDIT: I didn't notice that this topic was about the DDG browser (which I didn't know existed) and responded assuming this was about the site/extension. For a browser, yes, a client-side solution is possible and probably preferable. Please check and upvote other comment trees. This makes sense to me and is not alarming. Getting favicons actually is difficult to do robustly; many applications and websites use Google's service to do so, which then leaks the request to Google: https://www.google.com/s2/favicons?domain=ycombinator.com https://www.google.com/s2/favicons?domain=ycombinator.com Putting this logic in the client is not feasible. You want to send requests directly to every shady site that shows up in your search results, load their pages in the background, work through network delays and HTTP errors, and parse out the location/format of the favicon files? DuckDuckGo hosting this functionality themselves is also a positive. They have previously been burned when the Web of Trust service they were originally using was found to be farming data, and turned it off immediately once discovered. Processing, hosting, and serving the icon themselves prevents that from happening again. This is not to say that DDG is perfect: links you click do seem to be redirected through a /l/ page on their domain, which can cause problems: https://lapcatsoftware.com/articles/duckduckgo.html https://lapcatsoftware.com/articles/duckduckgo.html
- harry8 6y ago> Getting favicons actually is difficult to do robustly So if you're a privacy browser. Don't. Favicons are not essential. Or, at the very least make them "opt in" and explain it.
- projomni 6y agoGeez, overreacting.
- bangonkeyboard 6y agoI don't see how this is a privacy violation in any way. The headline is that DDG is tracking the domains you visit, but favicons are loaded for every search result you see unconditional on whether you click them, and DDG already knows what those results are when they serve them to you.
- rygh 6y agoDon't think it's air tight. But still better than most browsers.
- rickyc091 6y agoLooks like this was an issue posted in 2019. From the looks of it, the code remains unchanged. https://github.com/duckduckgo/Android/blob/b2131d7d2f47fb09d88e1a7768c67454a639518b/app/src/main/java/com/duckduckgo/app/global/UriExtension.kt#L83 https://github.com/duckduckgo/Android/blob/b2131d7d2f47fb09d...
- deleted 6y ago[deleted]
- niftylettuce 6y agoFormerly worked with DuckDuckGo My advice: Install ungoogled-chromium: https://github.com/Eloston/ungoogled-chromium https://github.com/Eloston/ungoogled-chromium Install these extensions: https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock https://github.com/ilGur1132/Smart-HTTPS https://github.com/ilGur1132/Smart-HTTPS There is also a Chromium extension that lets you install from Chrome Web Store: https://github.com/NeverDecaf/chromium-web-store https://github.com/NeverDecaf/chromium-web-store Set duckduckgo.com as your default search engine with a blank home page. But you could also use @pkrumins home pages of https://techurls.com https://techurls.com or https://finurls.com https://finurls.com as nice home pages. Use Mullvad VPN: https://mullvad.net/ https://mullvad.net/ (They are EVEN available on F-Droid now, which is AMAZING) Security harden your Android device: https://niftylettuce.com/posts/google-free-android-setup/ https://niftylettuce.com/posts/google-free-android-setup/ Security harden your Mac: https://gist.github.com/niftylettuce/39597a7b3bc0660ffe1e09d77588bcf6 https://gist.github.com/niftylettuce/39597a7b3bc0660ffe1e09d... P.S. If you need email forwarding for your domain name, you can use something I made. https://forwardemail.net https://forwardemail.net - it is 100% open source. Follow me @niftylettuce on GitHub and Twitter for more
- RandomBacon 6y agoWhy ungoogled-chromium over Firefox?
- niftylettuce 6y agoFaster + less bloat
- tomtomtom777 6y agoI have a hard time understanding the problem. The favicon is acquired from DDG servers for the result you've just retrieved from DDG servers. How is this leaking anything? What additional privacy would you gain from getting the favicons from the domains directly of search results delivered by DDG?
- marcinzm 6y agoThis is the DDG mobile browser app, NOT the DDG search engine.
- tagawa 6y agoDuckDuckGo staff here. As mentioned in the linked page, the purpose of the request is to retrieve a website's favicon so that it can be displayed in certain places within the app or on the results page. We use an internal favicon service because it can be complicated to locate a favicon for a website. They can be stored in a variety of locations and in a variety of formats. The service understands these edge cases and simplifies retrieval within our apps and our search engine. Like our search results, the favicon service adheres to our strict privacy policy[1] in that the requests are anonymous and we do not collect or share any personal information. [1] https://duckduckgo.com/privacy https://duckduckgo.com/privacy
- fiddlerwoaroof 6y agoThis doesn’t make sense for a browser: just embed the service’s logic in the browser, the browser has all the same information the service could get.
- tagawa 6y agoWe had already had created this anonymous favicon service for our private search engine. In addition, doing it this way avoids another request (and potentially multiple) to the end site. The service is private as we do not collect any personal information (e.g. IP addresses) on any requests for this or any service and the requests are all end-to-end encrypted.
- baby 6y agoI think people here are more interested to know if you’re going to fix it.
- systemvoltage 6y agoIt seems like DDG just doesn't want to do more work to make the browser do the sensible thing and instead piggy back on their existing favicon service, and then going to make the argument that it is safe with us. The domain of browser is totally different from reaching out to the website and rendering favicons server side. Do you not see this as a problem? I think it is acceptable to say "We agree this is a problem, and we are gonna look into fixing this" instead of pushing back on an obvious problem.
- awinter-py 6y agoseems like the ticket author found this by reading code (presumably was grepping for duckduckgo.com URLs) this would never happen with a consumer-facing product from apple or google; someone would have to MITM their whole OS to discover phone-home
- LeoNatan25 6y agoIt actually happens very often. People monitor their networks often, and pay close attention to such problems. Just search for “Apple phone home” and you’ll find many cases where people complain about Apple’s various services making worrying requests.
- awinter-py 6y agoright sorry -- didn't mean to say that they'd never get caught, rather that you can't read source
- TabbyCatKirk 6y agoEveryone is missing the point here. Let me break this down as simple as I can: 1. End user does a DDG search for "food" 2. The "food" query returns a list of search results, these results have each have a link, DDG wants to display the favicon for each link. 3. To be clear, DDG does not store or log the IP address of the user doing the query. They do, however, know what was queried, so they know "somebody" somewhere searched for "food". They have to know this, they are a search engine after all. 4. Since DDG wants to show the favicon "privately", and they dont want to put that logic/work on the client side (which could leak your IP), so instead DDG finds the favicon internally. 5. A DDG server, completely separate from anything search-related is then tasked with finding the favicon for your "food" query results, lets say the #1 result is www.allrecipes.com, so a DDG server goes to www.allrecipes.com and finds the exact favicon location. 6. The "found" favicons are then stored in a cache, and displayed from the cache like this: https://external-content.duckduckgo.com/ip3/www.allrecipes.com.ico https://external-content.duckduckgo.com/ip3/www.allrecipes.c... (and if no favicon is found in the local cache, you get a grey arrow by default) 7. I'd like to note, even with all this action, DDG doesn't know if you actually "visited" www.allrecipes.com, they simply know that some anonymous user did a search for "food", www.allrecipes.com was a search result, and a favicon was displayed. They dont know who searched for it because the users IP is not stored anywhere, they dont know if you visited www.allrecipes.com, they prevented you from leaking your IP to allrecipes.com since they didn't force the end user to load the favicon. So whats the issue? What am I missing here? PS: You know this works because after doing all these searches for food and seeing allrecipes.com (and even clicking allrecipes.com result in the DDG Mobile App or browser extension), guess what? allrecipes.com doesn't follow you around with re-targeting ads! Why? Because DDG prevented that from happening!
- ddevault 6y agoThis is not duckduckgo.com. This is the DuckDuckGo-branded end-user web browser.
- deleted 6y ago[deleted]
- 6y ago
- glouwbug 6y agoLooks like its time to ditch duck duck go
- hota_mazi 6y ago> At DuckDuckGo, we do not collect or share personal information. That's our privacy policy in a nutshell Except that you do, exactly in the way that the reporter of the issue explained to you. But you choose to patronize them and ignore the issue.
- Geee 6y agoI guess they collect statistics of the sites that people visit. This is anonymous but valuable information.
- foxhop 6y agoDDG mobile apps ~= Web Browser or == Web Browser I think that distinction needs to be made. I think DDG should treat this app as a web browser which means phoning home to this endpoint is unacceptable.
- pochamago 6y agoThis doesn't seem like an issue to me.
- zeckalpha 6y agoSeems a bit much, but k-anonymity could work here. Hash the domain, take the prefix, get a batch of favicons back. They won’t know which you visited, but still get the benefits of consistent favicon support.
- bad_user 6y agoAnd how would they get the "batch of favicons" in the first place?
- jhasse 6y agoWhen there's a miss, send the domain to the server so that it can fill the cache. You probably won't even have to do that as DDG could have already filled the cache with their search results.
- bad_user 6y agoOK, at what point does it become complicated enough to just implement that shit client side? :-)
- smolder 6y agoThat's an elegant fix, but for a problem that wouldn't exist if the feature was properly designed. (IOW, designed as a local function.)
- bad_user 6y agoSpeaking of leaks, I never understood why people use DDG's bangs. By using bangs you're sending your search history to DDG even when using search engines that aren't DDG.
- Nextgrid 6y agoBecause it's the easiest (and sometimes only) way to get this functionality on major browsers and browser developers have no plans to implement this functionality natively.
- bad_user 6y agoBoth Firefox and Chrome have custom search keywords: https://support.mozilla.org/en-US/kb/how-search-from-address-bar https://support.mozilla.org/en-US/kb/how-search-from-address... I maintain a set of such keywords in my Firefox, that I use on iOS and Android too. The easiest would be to just use Google btw, as it does a reasonable job to give you the website you're thinking of just by mentioning it in the search query, e.g "Frozen imdb" (though it does a perfect job in this case with just "Frozen"). If you use DDG, because I'm assuming you value your privacy, sending your search history to DDG when you could avoid it doesn't make much sense.
- tingol 6y agoI use chromium and I just type IMDB and it automatically tells me to press tab if I wan't to search imdb.com. What do bangs do better than this?
- joveian 6y agoThe main issue for me is that they only work in the url bar not the search bar. For the same reason people are upset about the favicon thing I don't want anything (mis)typed in the urlbar to be sent to a search engine. I've failed to find the correct setting to make this happen a few times before but just looked again and setting keyword.enabled to false prevents it from searching from the url bar (the setting is confusing and not related to the search keywords feature). I did try firefox search keyword anyway once a while ago but it isn't that easy to configure and the setting were lost not too long after I started using it (I don't remember the details but I think my profile was corrupted by ecryptfs and the keywords didn't import to a new profile or something like that). Not importing them isn't a horrible choice (if that is what actually happened) considering there doesn't seem to be an easy way to even list them, but there should at least be a distinct import/export for keywords. The search page of preferences has a keyword field next to search engines but it doesn't seem to actually list them nor can you add a keyword from that page. All in all, it doesn't seem like a feature Mozilla cares about at all, although it would be a nice feature with a bit more work. Use from right click search on text selection would be another thing that would make it much more useful. I tend to use ! in two circumstances, one as others mentioned when a DDG search didn't return what I wanted (and I am fine with letting DDG know that since it is the exact same search I just searched DDG) and secondly when I am looking for something on a particular site. Some of the second case would be best done via Firefox keyword search but the advantage of DDG is that they have a lot of obvious names going to the obvious place so rare specific searches are much more convenient than doing anything to set up a list. Since I very rarely use such searches, there isn't anything DDG could learn about me from avoiding just those searches going to DDG. OTOH, using site searches more frequently would be a win for privacy.
- deleted 6y ago[deleted]
- jpangs88 6y agoThe favicons on the duckduckgo browser are often worse than other browsers in my opinion. For example the BBC website where DDG interestingly enough just uses /favicon.ico and the other browsers use the apple touch icon. (Information I found from just looking at the pages headers) Don't really understand why they do extra work to get worse results... This feels to me slightly worse than just a privacy concern, it's a misunderstanding of their domain which leads me to the question of what else do they not fully understand. The good news is that you can have the DDG search engine as a default in other browsers. (I understand that the DDG browser is probably not their main focus and any lack of knowledge can potentially be just on their mobile browser.)
- davidhyde 6y agoUbiquity did the same thing with their routers. They couldn’t understand why users had such a problem with their phone home feature that was on by default when the purpose of it was to ultimately “improve” the user experience. I didn’t buy their router as a result. I also removed kaspersky from my computer because I didn’t like their phone home feature. Turns out they were selling my data despite holding my trust as a security company. DDG, don’t turn this into a PR nightmare. We don’t trust anyone anymore. Privacy policies are worthless. Nobody cares about favicons anyway. Source: https://www.theregister.com/2019/11/07/ubiquiti_networks_phone_home/ https://www.theregister.com/2019/11/07/ubiquiti_networks_pho... https://palant.info/2019/08/19/kaspersky-in-the-middle-what-could-possibly-go-wrong/ https://palant.info/2019/08/19/kaspersky-in-the-middle-what-...
- pelliphant 6y agowow, didn't know that, thnx for the heads up. Time to check what my ubiquity router is up to once I get home from work.
- mhaberl 6y agoProduct description (play store): "Tired of being tracked online? We can help." And then they track you. Yes, that might not be intentional and is used "just" for the favicon, yes they might not use the info on the domains you visit for tracking you today, but the data is there. Why not use that data tomorow "just" to see what kinds of pages their customers (browser users) are visiting so they can better place their ads.. and then maybe some other idea.. this is a path that many such companies went ("don't be evil"). You either respect the user privacy or you don't - there is no middle "just for this little feature" ground
- deleted 6y ago[deleted]
- mikaeluman 6y agoI don't want to have to trust everything follows a policy. It's much easier if I don't even have to trust you. Please change this.
- throwaway_pdp09 6y agoThere's an interesting disease showing up here in the responses. I accept DDG's statement that this is about a favicon and that they "do not collect or share any personal information", and despite that, I also agree with others that DDG should be on the safe side and just stop doing this small thing. It's just the safer and more moral thing to do (So DDG, as many are suggesting, plz stop doing it. Today is good). But... the reaction here is "they made a mistake, let's pile on like kids in a playground" ignoring the genuinely huger issue of the amount of info and mining that google et al. do. There's no measure of proportion in the responses, someone is making a mistake then there's a wolfish, pack-like desire to get stuck in and hurt someone. Which is why politicians rarely admit mistakes, because it's taken as a sign of weakness, not strength, to admit you were wrong. DDG isn't the big evil on the web but from reading some of these you'd think it was the 2nd google. This isn't about DDG, just the proportionality of responses in public errors and what society you'd like to have. (no affiliation to DDG)
- warpspin 6y agoI think what angered people was actually that a company saying to hold privacy high was simply refusing to change something after a mistake was pointed out and instead kept on defending it with a technical argument, which makes no sense at all. The reaction would have been actually a lot different if someone from the company admitted the mistake and promised it will be changed. Update: Gabriel Weinberg has promised to change it, linking it here so it does not get buried in the pile of comments: https://news.ycombinator.com/item?id=23711597 https://news.ycombinator.com/item?id=23711597
- deleted 6y ago[deleted]
- asjw 6y agoYeah people burnt witches in the past ... If they are confident that this feature has no privacy implications they are right to defend the point, despite what people say or think People don't run DDG, the company People can use another search engine if they want I'll keep using DDG anyway
- trashburger 6y agoFrom st3fan's links, this[0] seems to be something that DDG developers can use. Took me about 30 seconds to dig it up from the repository. [0]: https://github.com/mozilla-mobile/android-components/tree/master/components/browser/icons https://github.com/mozilla-mobile/android-components/tree/ma...
- yegg 6y agoHi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and reading the comments here. I’m new to this issue and happy to commit us to move to doing this locally in the browser and will have us move on that ASAP. That said, I want to be clear that we did not and have not collected any personal information here. As other staff have referenced, our services are encrypted and throw away PII like IP addresses by design. However, I take the point that it is nevertheless safer to do it locally and so we will do that.
- deleted 6y ago[deleted]
- pelliphant 6y agoThank you, this is the response people here want to hear. And if this gets fixed in a reasonable timeframe, this is just one of those "everyone makes a mistake one in a while"-things, no big deal.
- azalemeth 6y agoIf anything, it's much better than 'no big deal'. It's "We made this design decision, thought you would like it -- we've learnt, changed, and will avoid it later". Can you imagine Google doing something similar? Heck, they're just about to throw the Android rooting community under a hardware-attestation DRM-filled bus.
- pelliphant 6y agoTrue, it is better
- bluesign 6y agoMore like we made a design decision, than someone warned us this is bad for privacy, we ignored, after 1 year it blew up on HN, now we are fixing it.
- ajani 6y ago
- polycaster 6y agoIf DDG cannot fetch the favicon in different, reasonable way, then the question is whether or not the ability to display a favicon in search results is really worth it. Personally, no.
- gowthamgts12 6y agocreated a new issue to track this again: https://github.com/duckduckgo/Android/issues/876 https://github.com/duckduckgo/Android/issues/876
- renewiltord 6y agoHaha, amazing to witness. This is the problem with catering to this crowd: your audience is suddenly full of people who just want to see you fail. Good luck, DDG.
- mhaberl 6y agoI don't agree. I really like DDG - it works good, it is fast and it does not use my personal search for giving me "better ads" or "better search results" that put me in a filter bubble. But there is a different issue here at play; because of errors like this the whole DDG brand gets a bad rap - and thats not only bad because of the risk of people losing a google alternative but because it is real easy to exploit situations like this for google-like companies to give an impression that "all this privacy thing is bs, all companies work in a same way". There are a lot of people that are not really sure is this "privacy thing" is worth the inconvinience of swiching to some other search engine/browser/app and situations like this one are not helpful in that regard. Lot of folks are aware of this and are displeased for risking brand confidence of such a visible privacy-concerned company for miniscule gains like performance gains for fetching a favicon for the first time - just fetch the favicon after you display the rest of the page and cache it, maybe dont even try to fech it if the connection is poor - who cares really
- classified 6y agoBy now it has been sufficiently proven that it is physically impossible to even exist without sending surveillance data to someone on the internet. We should probably update the laws of thermodynamics to include that.
- olafure 6y agoI think we're due a full disclosure on this favicon service, what information is collected and what is stored. DDG has repeatedly said that they have "not collected any personal information". For example, 1. Does the service store the fact that it got a request for a domain? 2. Does it store any ID along with that information and if so, how unique is that ID? How is it generated and what is it linked to? 3. What other information is stored along with the request? 4. How does DDG process this information? 5. Who has or can get access to this information?
- eightlimbed 6y agoCan someone please explain like I'm five how this line of code sends the domain a user visited to DDG's servers?
- oplav 6y agoEvery time you visit a website on the Android version of the browser, instead of requesting the favicon from https://example.com/favicon.ico https://example.com/favicon.ico, the app is calling out to https://icons.duckduckgo.com/ip3/example.com/favicon.ico https://icons.duckduckgo.com/ip3/example.com/favicon.ico. Since DDG owns the icons.duckduckgo.com service and the domain you were interested in is in the request to icons.duckduckgo.com, you've sent the domain to DDG's servers.
- sonicggg 6y agoSomething is not adding up. Why would you go through so much trouble and over-engineer a favicon retrieval service? Really, favicon? Since when did they become so essential? I'm pretty sure 90% of websites provide one in a standard way. If not, just draw a letter there, or anything. But I don't know. I think that either there is more to this story, or DDG team completely lost common sense.
- thedonkeycometh 6y agoWhy is this not optional default deny in settings?
- WClayFerguson 6y agoIt is a hilarious excuse for DDG to claim they are doing this for a favicon. Even if DDG is legitimately not using the data they are definitely collecting the data. The problem with that is that it requires users to "trust" DDG, which is not how the world works today. If you are a company that collects info, and you expect users to trust that the info will remain safe, secure, and never get misuse that is downright foolish for anyone to believe a word of that. We all know that DDG cannot claim it's impossible for them to get hacked and have all that data leak out. Hacks happen all the time and so the solution for DDG is to simply NOT collect the data, rather than collect and claim it's all secure. And we all also know DDG has (or will) get a NSL (National Security Letter) from the NSA to secretly turn over the data anyway, and when that does happen the DDG employees are not even allowed to admit it ever happened.
- twirlock 6y agoI didn't know they had a browser. I'll have to give it a try. Can't be any worse than Google's browser. Or their OS. Or their video monopoly. Or their search monopoly. Or their secret partnerships with governments. Or their ad monopoly. Or their email monopoly.
- dng88 6y agoIs it possible to double check some basic interaction of the searching engine so this kind of mistakes can be avoided. Not just favicon?
- Angeo34 6y agoWhoever ever put their trust into American for profit companies which use slogans like "private secure and fast" should not be surprised at leaking all their data. I never got how people trust companies like ddg or Brave. If you don't trust Google and Apple why would you trust a smaller company in the same jurisdiction. They will be forced to hand out all data as well regardless what they say.