4 ms·
Unless you work at Kagi I am not taking that too seriously.
by SanderNL 3y ago
Unless you work at Kagi I am not taking that too seriously.
- cowthulhu 3y agoIt looks like their privacy policy backs this up. It’s also written in plain English, which I adore. “Searches are anonymous and private to you. Kagi does not log and associate searches with an account.” https://kagi.com/privacy https://kagi.com/privacy
- exitb 3y agoNot so plain. We do not (log AND associate), or we do not log AND we don’t associate? Am I supposed to believe that if their backend crashes after a user query, that can’t tell what has been queried?
- bthrn 3y ago" Kagi does not log and associate searches with an account." > Am I supposed to believe that if their backend crashes after a user query, that can’t tell what has been queried? I'm sure they'll know the query. They just won't know which user made the query.
- exitb 3y agoAnd here lies the problem - there’s a difference between “we have no process that associates queries and users” and “the system is specifically designed to make this association impossible”.
- Cu3PO42 3y agoI don't Work at Kagi either, but I can ready their Privacy Policy: https://kagi.com/privacy https://kagi.com/privacy > Searches are anonymous and private to you. Kagi does not log and associate searches with an account. They also double down on this in their FAQ: https://help.kagi.com/kagi/company/faqs.html#i-am-still-worried-about-my-private-information-and-searches-being-linked-together-why-should-i-trust-you https://help.kagi.com/kagi/company/faqs.html#i-am-still-worr... I find their reasoning solid and choose to believe them (for now).
- jefozabuss 3y agoAs you mentioned they don't track (for now). I mean anyone can write anything into a privacy policy and who will enforce they are sticking to them really? Usually we only see what actually happens in the background when there is a breach. For financial systems we have regular audits so rules like PCI DSS are enforced, but do we have these for search systems?
- dijit 3y ago> I mean anyone can write anything into a privacy policy and who will enforce they are sticking to them really? Dunno, but a "decent" chunk of my time went into vetting our privacy policy for my company because it is something we could be sued over. So at least lawyers are taking it very seriously.
- TisButMe 3y agoI do, we don't log searches.
- SanderNL 3y agoSo if the feds stop by you have nothing to hand over. That sounds great, but legally dubious. Aren't you required to keep a log? Thanks for the info nonetheless. I think I'll give it a shot and maybe don't look up how to get rid of bodies - for a friend. Oh, damn, did it again.
- outime 3y agoIANAL nor close to it but is there any legal requirement in the US to keep logs avoid user activity besides access logs? I'd be surprised that the US federal law forces you to keep a full activity log so that they can take a look later for some reason.
- orlp 3y agoDoes it matter if it's a law? One day a national security letter from some three letter agency shows up at your doorstep, requiring you to keep logs (or let their engineer install a room 641A), and forbidding you from saying you do.
- gassiss 3y agoFor that kind of risk profile, you can't have an account anywhere (not even HN), nor a cell phone