7 ms·
Google's widespread tracking across the web
- yegg 1y agoThis title is highly misleading, implying that Google tracks DuckDuckGo searches directly, which isn’t true. It also reinforces a conspiracy theory that we’re owned by Google, which also of course isn’t true. Kindly please change it to be more accurate about Google analytics and other Google trackers on websites you may visit. We’ve been sounding the alarm about Google analytics, tag manager, and other Google trackers for years and why we started making our own extensions and browsers to block them and provide more comprehensive protection. On our homepage and everywhere else we can we try to get people to install those to get that additional protection, which you can compare here: https://duckduckgo.com/compare-privacy https://duckduckgo.com/compare-privacy
- unsupp0rted 1y agoAccording to the link, using DuckDuckGo's browser basically eliminates the threat 100%, particularly if paired with a VPN?
- FabHK 1y agoI don't think the title implies that Google is tracking DuckDuckGo searches directly, just that using DuckDuckGo instead of Google often doesn't prevent Google from tracking you. The article also makes clear that using DuckDuckGo is an improvement, just not enough. Furthermore, I don't see any intimation in the article that Google owns DuckDuckGo. All in all, it seems you and the article are on the same page.
- nottorp 1y agoThe way i read it, it implies that DuckDuckGo should protect you from tracking on the sites it points to and it's not doing a good job. They could have done a marketing blog post about the evils of Google Analytics without dragging DDG into this...
- blackoil 1y agoYeah. This is simple fear mongering to sell its own analytics product.
- bentlegen 1y agoHopefully you won’t mind me using their own arguments to promote this OSS web analytics project instead: https://counterscale.dev/ https://counterscale.dev/ Unlike Simple Analytics (the post authors), you deploy Counterscale to your own Cloudflare account and control the code + data end-to-end. It also uses no cookies, has no browser fingerprinting, and has no monetized SaaS offering. It only has 90 days retention though, which could be viewed positively.
- blackoil 1y agoI am all for the hustle. Startups are difficult. So, even though I don't like the post, I understand it is done because it works.
- figmert 1y agoIt's simple fear mongering and aimed at the wrong audience. Companies want people tracked to improve their ads and have a higher reach. The people who are being tracked can't exactly do much about what tracking system a website uses.
- basquiyacht 1y agoEdit: I can see that it reads like that. Thats not the point. DDG are not the bad guys. Google is.
- jacquesm 1y agoAny chance of a Linux version of your browser?
- jannes 1y agoDDG is only one piece in the privacy puzzle. I think the article doesn't make it clear enough that other pieces are necessary.
- RamblingCTO 1y agoThe threat is real though and I've recently noticed an uptick in the google SSO popup, which is just another way of tracking. Most notably on pornhub. I'm not too keen to let them know what I have a wank to.
- deleted 1y ago[deleted]
- randomtoast 1y agoLet's face reality: as soon as you browse the internet, you will be tracked and identified. Here are just a few data points used for fingerprinting: IP address, User-Agent string, Referrer URL, Requested URL, Language, Locale, Screen resolution, Time zone, System time, Installed fonts, Installed plugins, Cookie data, Browser fingerprint, Canvas fingerprint, WebGL fingerprint, AudioContext fingerprint, Mouse movements, Click paths, Keyboard input timing, History sniffing, DNS queries, Destination IP addresses, HTTP traffic content, HTTPS metadata (host, SNI, timing), MAC address, Query parameters, Session ID, Login status, User account info, Geolocation (via IP), Geolocation (via browser API), Page interaction data, Time on page, Scroll behavior, Clicks, Form submissions, Browser type, OS type, Network provider, Client ID (\_ga cookie), Session ID, Timestamp, Pages visited, UTM parameters, Interaction events, Google Ad ID, DoubleClick cookie (IDE), Cross-site behavior, Cross-device behavior, Inferred demographics, Mouse tracking, Scroll depth, Video interactions, Audio interactions, Session replay, Keystroke logging, Facebook login status, Pixel events (Meta, LinkedIn, etc) If you want to avoid that, you need to make a real effort (not just using DuckDuckGo). The Tails operating system might be a good place to start.
- edoceo 1y agoHow is the MAC collected?
- Arnt 1y agoThe WLAN AP collects that. They really track you (they being the AP and Google). You may assume that they collude, or not.
- 2716057 1y agoDepending on your network configuration I could imagine abuse of EDNS(0). This is used for example by NextDNS to identify which device (MAC) on your local network sent the request in order to apply specific filters and log the request. A not-so-friendly DNS could sell such information.
- johnisgood 1y ago
- buyucu 1y agoNo they don't. My PiHole and uBlock Origin stops it.
- nottorp 1y agoAnd as far as i know DDG is a search engine, not a privacy plugin. It only gives you links, it doesn't modify web pages and it's not its job to. For stopping tracking, uBlock Origin.
- tharkun__ 1y agoDDG is a privacy plugin (on desktop). On mobile it's its own browser. The one I'm writing this from. And yes I still use uBlock on top on desktop.
- nottorp 1y agoHuh? I use it daily, but I never installed any plugin...
- tharkun__ 1y agoIt's "all of the above" ;) As in: DuckDuckGo is a search engine you can go to from any browser, such as but not limited to the Chrome browser on various platforms. DuckDuckGo is also a browser for mobile phones. It's an app you can install e.g. https://play.google.com/store/apps/details?id=com.duckduckgo.mobile.android https://play.google.com/store/apps/details?id=com.duckduckgo.... You can then, if you want to, use Google Search exclusively from within that DDG browser ;) DuckDuckGo is also a plugin for desktop browsers (e.g. for Firefox: https://addons.mozilla.org/en-US/firefox/addon/duckduckgo-for-firefox https://addons.mozilla.org/en-US/firefox/addon/duckduckgo-fo..., find the equivalent for Chrome on the webstore ...) that you can install. You can then exclusively use the Google Search engine while having the "DuckDuckGo Search & Tracker Protection" plugin installed if you so choose.
- deleted 1y ago[deleted]
- baal80spam 1y agoIsn't DDG a Bing wrapper?
- Arnt 1y agoIt does lots of things itself, and gets lots of other things from Bing.
- amelius 1y agoUser tracking only exists because it generates money. We should ban the entire practice. No more targeted ads (with very little exceptions).
- tonyhart7 1y agohow you can ban the practice??? in what way ?
- amelius 1y agoYou ban it by making it illegal.
- tonyhart7 1y agohow can you make it illegal?? >make a new law >they just move elsewhere how??? tell me
- aniviacat 1y agoThe EU was pretty successful with mandating cookie banners and GDPR. On the other hand, I think a great firewall would be useful to the US and especially the EU, to be able to enforce their laws even better.
- tonyhart7 1y ago"mandating cookie banners and GDPR." this is only works if your business located in EU, no one stop EU people visit US site and still get tracked
- bayindirh 1y agoI'm not pretty sure about that. I get cookie banners from US companies all the time and choose to reject them. Just visited www.vmware.com. Site is located in the US. Company is located in USA, and OneTrust's cookie banner welcomed me, and allows me to make choices.
- jgalt212 1y ago> Even in countries with strict laws like the GDPR, Google's trackers are still everywhere. That raises questions about how effective these regulations really are in practice. This is basically it. GDPR is a stupid unenforceable law, and should be wiped from the books. Try again with something new.
- cherryteastain 1y agoIt is enforcable but EU has been quite cautious and conservative with its enforcement approach. China has a ton of laws aimed to suppress political dissent, and a good chunk of their laws/regulations would be even more unenforceable if they adopted an EU style approach. Of course, China means business, so they just go ahead and deploy the sledgehammer: you are banned from China unless you comply with the law. You typically can't even read the letter of the law and implement what it says verbatim; if you violate the spirit of the law (that is, don't disseminate anti-CCP content) you will still get the banhammer. It's all about what political capital you're willing to give up to enforce the law.
- simpss 1y agoIt took a while, but is starting to work. Many "cookie banners" have finally started to work in the EU. Once you deny PII processing many sites don't load GA etc... The time of malicious compliance is starting to pass. Some sites have figured it out and realized they really don't need personalized analytics and have replaced implementations with privacy respecting ones(ex, plausible). This lets them remove the dark-patternish banner and no additional consent is required as all data is pooled together and one persons actions truly can't be singled out. GDPR obviously has other good effects but as PII processing through cookies is what most people know, I chose that as an example. Email tracking links & pixels are another good example. There's also a big difference between 2018 and 2025 when discussing GDPR in work contexts and saying that implementing this or that tracking would be illegal. It's a slow process, but it's working as intended.
- jgalt212 1y agoEnforcing sites not calling out to third party data processors via client-side JavaScript is detectable and enforceable, but taking such actions server-side is undetectable (and therefore unenforceable).
- ants_everywhere 1y agoI clicked on this expecting an interesting read, but the big reveal was... Google analytics??
- reconnecting 1y agoIn the case of this particular website, perhaps Google tracks you less, but you get tracked by `https://test-v1.adriaan.com https://test-v1.adriaan.com` — whatever that means. 9: <script src="https://test-v1.adriaan.com/script-v1.js https://test-v1.adriaan.com/script-v1.js" async></script> https://test-v1.adriaan.com/simple.gif?type=event&hostname=test-2025-04-22-v2.simpleanalytics.com&hostname_original=www.simpleanalytics.com&ua=Mozilla/5.0 https://test-v1.adriaan.com/simple.gif?type=event&hostname=t... Gecko/20100101 Firefox/128.0&version=test-2025-04-22-v2&event=onload&path=/blog/google-is-tracking-you-even-when-you-use-duck-duck-go&referrer=&session_id=ab6ceafa-47c1-48e4-b26b-79148e625a15&metadata={"beacon_ok":true,"keepalive_ok":false,"ts_ms":1752496007219,"send_method":"image"}&t=1752496007219 So the correct title must be: "We track you when you're reading about Google tracking you (even when using DuckDuckGo)."
- AdriaanvRossum 1y agoHa, nice find! I'm the Adriaan in adriaan.com. I'm testing some new script features that might improve deliverability. It's not sending any personal data. I use another domain to have the least effect of ad-blockers.
- reconnecting 1y agoNice to meet you, Adriaan. This is slightly incorrect. By sending a request from your business website (SimpleAnalytics) to your personal domain (Adriaan), you actually transfer personal data. In this case, it’s the IP address, which according to GDPR is considered PII. Taking into account the scope of privacy terms provided on your business website, it doesn’t include data sharing with your personal entity through your website. So this is basically illegal, unless adriaan[.]com belongs and operated by SimpleAnalytics company.
- openplatypus 1y agoPII is not GDPR term. PII is used some US-specific acts, like HIPPA. Did you mean Personal Data?
- baggachipz 1y agoThis is an obvious, thinly-veiled advertisement for a company's services. It's widely known that ad companies track you everywhere by many mechanisms. This is why we use ad blockers of all sorts. This has nothing to do with DuckDuckGo, it's merely used as a vehicle to get clicks.
- 1vuio0pswjnm7 1y ago"SimpleAnalytics" by "IronBrands" uses utm tracking in the URL to the study that they have so graciously provided to the reader. Perhaps the name should be "IronyBrands"
- v5v3 1y agoA lot of browser's have tracking blocked and there will be a icon in the top bar which will show this. And many vpns also offer an option to block trackers and ads before they get to you.
- figmert 1y agoVPN providers can't meaningfully block trackers. If they say they do, they have to be intercepting SSL which requires extra work (must install their generated CA on all clients) and you are literally handing over all data to the VPN provider, more so than without of course, as they'd be able to decrypt HTTPS payloads.
- v5v3 1y agoWouldn't they just be blocking the DNS queries? So any client side requests to a known URL is just blocked. So only server side would work.
- deleted 1y ago[deleted]
- daft_pink 1y agoI really wish we could change the search engine in apple products directly to Kagi instead of leaking searches through DuckDuckGo