13 ms·
I use DDG as my default search engine, along with NoScript in the browser. Often when I visit a new website, I peruse the (long) list of domains that the site i
by zodzedzi 4y ago
I use DDG as my default search engine, along with NoScript in the browser. Often when I visit a new website, I peruse the (long) list of domains that the site is trying to pull javascripts from.
I keep most of those source sites in UNTRUSTED status (including some of the big names in search/ads/etc). But I've always had DDG in the TRUSTED category because I had only seen its javascript before on the main DDG website.
(Unfortunately NoScript has a limitation that you can't tell it to "only TRUST javascript from example.com when I'm visiting example.com").
But recently I started noticing some websites pulling javascript from DDG (I don't remember which sites).
So now I was wondering if DDG is getting into the tracking business, since they're now having their javascripts load from third party sites.
Obviously this is anecdotal. But does anyone know if they are indeed beginning to track?
- stjohnswarts 4y agoCan you give us a list (or partial list) of sites that are pulling scripts from duckduckgo? We can look at what they're trying to do.
- zodzedzi 4y agoI don't remember the sites; I'll try to find them again, and will share here if I do. I remember seeing 3 sites within an hour, and deciding to change the DDG setting to TEMP:TRUSTED afterwards.
- autoexec 4y agoThe nice thing about DDG is that if you're willing to sacrifice some functionality it can still be used without JS at all (which is how I use it)
- z3c0 4y ago> Unfortunately NoScript has a limitation that you can't tell it to "only TRUST javascript from example.com when I'm visiting example.com" I was under the impression that the custom option allowed this. Am I misunderstanding the point of this option?
- zodzedzi 4y agoI see "Custom" allowing you to choose which elements (frame, fonts, etc.) to allow/block for the domain you're configuring. But it doesn't offer the ability to say "apply these settings to the domain example.com only when I'm visiting example.com, and not when I'm visiting anotherexample.com which happens to load JS from example.com".
- z3c0 4y agoMaybe I'm still misunderstanding, but when configuring the domain in the custom settings, it does allow you to limit the custom rules to only the site you're currently on, via the "Enable these capabilities when top page matches" dropdown. The default is "ANY SITE".
- zodzedzi 4y agoI don't see any of these options in my plugin. I have NoScript 10, and it looks like there is a NoScript 11 out there; is that what you have? Maybe the feature was introduced in 11 and I'm missing that update; checking their changelog now... Edit: Correction - I do have NoScript 11; but don't see those options.
- z3c0 4y agoI think you nailed it - I am indeed on 11. So good news! It looks like NoScript is attentive to user needs. Edit: seeing your edit - the plot thickens. I'm on 11.4.4 - any difference there?
- zodzedzi 4y agoI had 11.2.11. And you're right, according to their changelog [1], they added it in 11.3. >> v 11.3rc1 + Contextual policies (different capabilities for the same origin, depending on the top-level domain) configurable in the CUSTOM panel (thanks NLnet for financial support) Woohoo! Thanks for following up and making me look, I now have a better setup! [1] https://noscript.net/changelog/ https://noscript.net/changelog/
- freedomben 4y agoI run uMatrix and have noticed some DDG showing up on other sites as well. The sites in question appeared to be (at least ostensibly) using it as a "can I reach the internet" sort of check. If I blocked requests, it would say something to the effect of "no connection detected." I wish I could remember which sites they were, but I do remember seeing at least one call to improving.duckduckgo.com from a 3rd party.
- mormegil 4y ago> (Unfortunately NoScript has a limitation that you can't tell it to "only TRUST javascript from example.com when I'm visiting example.com"). uMatrix (which I'm using in desktop Firefox) works exactly like this. Plus it allows you to forbid/allow cookies, styles, images, scripts, media, XHR, and iframes separately (for each origin/domain).
- zodzedzi 4y agoOk I'll set it up sometime soon and give it a try. Thanks.
- moehm 4y agoIt's officially deprecated, but it still works. https://github.com/gorhill/uMatrix https://github.com/gorhill/uMatrix
- mattl 4y agoIsn’t that non-origin?
- stereoradonc 4y agoAny alternative to uMatrix?
- mrob 4y agouBlock Origin in advanced mode also supports this (although only scripts/frames/images, not the full uMatrix list).
- zionic 4y ago> So now I was wondering if DDG is getting into the tracking business Anecdotal of course, but I've been seeing more and more DDG billboards. Those things aren't cheap, and my trust in them has declined the more I see them advertise in the traditional market.
- brewdad 4y agoSo where does one from here for everyday search? Google is out. Bing has many of the same problems as Google. Startpage blocks my VPN. Brave has always felt just a little "off" to me, but maybe they're worth a try. Any others I've missed that are worth looking into?
- californical 4y agoI found Kagi[0] from somewhere on HN -- they make pretty strong privacy claims, and are in a closed Beta stage right now (you can give them your email, and they'll send you a signup link within a week or two). They're planning to charge a fixed rate for their search engine once they're out of beta later this year. So far, it seems to be working really well for me! Results are pretty excellent, and they support the DDG bang queries (like `!g`) if you ever need it [0] https://kagi.com/ https://kagi.com/
- wand3r 4y agoI second this. I use this full time now. A helpful HN user told me about hyperweb for iOS which I use to make Kagi my fulltime search engine on iOS. I have been VERY happy
- user_7832 4y ago> they'll send you a signup link within a week or two Is it though? I think I've been on the wait list for a few months now.
- amelius 4y agoHow do we know these privacy claims are true? What if Kagi was Chinese or Russian, would you still trust it and why? And how do we know Kagi doesn't end up the same way as DDG?
- nonrandomstring 4y agoSuck Suck Blow has many redeeming features. One that's GOLD imho; duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onion/ Running a hidden service is just so jolly gentlemanly. And it works in the total absence of JavaScript and no matter what utter lies I tell it about my randomised-per-request UA, and cookie black holes. The obvious dark side is that it's closely connected to Amazon.
- asojfdowgh 4y agoublock doesn't correctly show beacons and pings beacons and pings fired upon activating a link, happen after the document change, so ublock associates them with the new document, even though they are initiated by the old document
- yegg 4y agoWe don't use third-party scripts on our site and I don't know of any sites using our scripts either.