3 ms·
I stopped using DuckDuckGo when it introduced its email relay service. This service had (and I think still does have) the peculiar requirement that the user mus
by toomanyusers 3y ago
I stopped using DuckDuckGo when it introduced its email relay service. This service had (and I think still does have) the peculiar requirement that the user must install a browser extension in order to use it.
I can think of no valid reason why a (supposedly privacy-respecting) email relay service should require a browser extension to be installed.
This made me realize DuckDuckGo may not actually value privacy. I stopped trusting all of its services.
- eks391 3y agoI have two email relays from DDG and have never installed their extension nor even knew they had an extension when I got their relays. (I know now but at the time I didn't) If you download the app on your phone, you can get a relay and then immidiately uninstall the app.
- toomanyusers 3y agoYes, but you had to install an app. Why? They already have your email. They're forwarding email to you as part of the service. And you probably had to verify your email with them when you started using it. So why should you be required to also install either an app or a browser extension? Doesn't the very act of installing something on your devices increase their technical ability to collect information about you and your devices? That doesn't sound very privacy-oriented.
- caslon 3y agoMost likely a feeble attempt to avoid the domain from getting blacklisted from most services by restricting the amount of relays a user can have by device.
- gondaloof 3y agoReading your comments made me realize how a service like DDG could never succeed. The only people who care about its advantages are the same users they lose for anything that remotely helps the company grow. Apple is a regular company and gets points for adding privacy features. DDG? “Nah, F that, they suggested I run code on my device for a brand-new unrelated service. Reprehensible.”
- eek2121 3y agoApple does add privacy though. The company does not collect and sell your data. Folks regularly read the ToS and freak out, without understanding why the ToS says what it says. Most privacy oriented companies don't care about your data, but they need to be able to see diagnostic information about your session for when things don't work. Oh and guess what? Things don't work for many users due to all kinds of crazy stuff, with viruses, proxies, crap internet, crap browsers, crappier browser extensions, or just plain user stupidity causing 99% of it. Diagnostic data and basic telemetry allows software engineers to find the root cause.
- George83728 3y ago[dead]
- derefr 3y ago> I can think of no valid reason why a (supposedly privacy-respecting) email relay service should require a browser extension to be installed. I can answer this one: they're fine with not knowing who anyone is, but they're trying to make sure that each account maps to one real person — they're trying to prevent spammers from registering thousands of accounts to use to send spam, and from continuously registering more accounts whenever they get banned. A browser extension that feeds their service a heartbeat packet every once in a while from a particular IP address, is a Proof of Identity. It ties the email account accessed through that browser, to a browser installation of the extension, such that you can only actively use as many email accounts as you have devices x installed browsers (which might be a surprisingly high number to you, a normal person with legitimate use-cases for multiple email accounts; but is still a problematically low number compared to the number of accounts the average spammer wants to register — especially when most of those accounts get banned in short order.) This is a workaround for the fact that there's as-of-yet no such thing as an "anonymous identity verification service" — something like an OAuth IdP that deduplicates users on the client-to-IdP side through strong identity verification on registration (photo of your passport, webcam picture with this hand gesture, you know the drill); but then protects client anonymity on the IdP-to-service side. If you had to SSO to your DDG email through such a service, then they very likely wouldn't be asking you to install the extension.
- crossroadsguy 3y agoCompanies like DDG and Apple don’t do privacy. They do privacy theatre. Just that Apple is too big with too much of a PR/marketing budget and has an ultra/rabidly loyal fanbase so it works for them. There are companies that do privacy but they’re usually too small to be noticed outside the crowd of extremely privacy conscious people. Mozila is a famous one though. Yup, even after their Pocket fiasco and some more I do believe they try to real and long term privacy. DDG is just hustling to stand apart and then maybe hope for a financial exit. (Have had a really bad experience with the company, other than using their product - their search is unusable though - that told me they do not have a respectable culture as an organisation either).
- ericmay 3y agoCan you describe the difference between “privacy” and “privacy theater”?
- scarface74 3y agoThe same Firefox that gets most of its funding by funneling search to Google?
- stonogo 3y agoIt also funnels all your nearby access point names to Google, and it does that for free!