03.15.21

Gemini version available ♊︎

Why You Should Avoid DuckDuckGo (DDG) 2021 Edition, Now Microsoft-Hosted and With Extra Privacy Risks

Posted in Deception, Microsoft, Search at 9:21 pm by Dr. Roy Schestowitz

Reddit seems to be censoring such revelations right now (even a year after publication), as if sponsors are more important than facts


There are substantial privacy and civil liberty issues with DuckDuckGo. Here they are spotlighted:

  1. Nefarious History of DDG founder & CEO:

    1. DDG’s founder (Gabriel Weinberg) has a history of
      privacy abuse, starting with his founding of Names DB,
      a surveillance capitalist service designed to coerce naive users
      to submit sensitive information about their friends. (2006)

      (expand related trivia on Reddit censorship)

      The “history” link above refers to a Reddit post rich in
      accurate facts– verifiable facts. The moderator (trai_dep)
      added flair to falsely flag the content as
      “speculative” to cast doubt (to create FUD whilst falsely
      accusing the other of just that – to project.
      The pot is calling the kettle black). No counter
      evidence was given.

      Then over a year later Reddit censored the post in a manner that
      suggests a rogue/buggy robot “automatically” filtered it as “spam”.
      They duck accountability by blaming the bot. Obviously nothing
      in the post could even remotely be construed as spam. Are we to
      believe that a robot would censor an old archived post, and no
      human reviews censorship by some unleashed bot loose in the
      wild? Anyway, this is why the link is a mirrored WaybackMachine
      document.

    2. Weinberg’s motivation for creating DDG was not
      actually to “spread privacy”; it was to create something big,
      something that would compete with big players, according to an
      interview between Weinberg and Susan Adams. As a privacy abuser
      during the conception of DDG (Names Database), Weinberg sought to
      become a big-name legacy. Privacy is Weinberg’s means (not ends)
      in that endeavor. Clearly he doesn’t value privacy — he values
      perception of privacy.

  2. Direct Privacy Abuse:

    1. DDG was caught violating its own privacy policy
      by issuing tracker cookies, according to Alexander Hanff
      (CEO of Think Privacy and a data security and
      ethics expert on staff at Singularity University).

    2. DDG was again caught violating its own privacy policy by
      fingerprinting browsers. DDG responded not
      with counter evidence, but simply a plea to trust them.

    3. DDG’s third violation (2021): Microsoft hosts DDG’s service and
      also supplies Bing search results for the same
      transaction. This means Microsoft sees both sides of the
      transaction
      and can link your IP address (i.e. identity) to
      your search query that Bing processes. DDG makes this
      false statement: “we never share any personal information with
      any of our partners. The way it works is when we call a partner
      for information, it is proxied through our servers so it stays
      completely anonymous. That is, any call to a partner looks to
      the partner as it is from us and not the user itself, and no
      user personal information is passed in that process (e.g. their
      IP address). That way we can build our search result pages using
      these 100s of partner sources, while still keeping them
      completely anonymous to you
      (emphasis added). While it may
      be true that DDG doesn’t transmit users’ IP addresses to
      Microsoft, Microsoft has already seen users’ IP addresses via
      Azure. That combination of data given to Microsoft makes DDG’s
      statement a lie. The MS Azure privacy policy refers
      us to the general MS privacy policy, which confirms that
      Microsoft collects IP addresses.

      DDG can change their hosting provider at any time. And they
      have– they migrated from Amazon AWS to Microsoft. As of the
      drafting of the article herein, DDG is still MS-hosted. To
      verify for yourself that DDG is still MS-hosted as you read
      this, Linux Tor users can run: torsocks whois "$(torsocks dig +tcp +short +time=4 +tries=1 duckduckgo.com @resolver1.opendns.com)"; web users can verify by obtaining
      DDG’s IP address from digweb and then visit
      https://ipinfo.io/ <IP address from digweb>.

    4. DDG’s app sends every URL you visit to DDG
      servers. (discussion).

    5. DDG is currently collecting users’ operating systems and
      everything they highlight in the search results. (to verify
      this, simply hit F12 in your browser and select the “network”
      tab. Do a search with JavaScript enabled. Highlight some text on
      the screen. Mouseover the traffic rows and see that your
      highlighted text, operating system, and other details relating to
      geolocation are sent to DDG. Then change the query and submit.
      Notice that the previous query is being transmitted with the new
      query to link the queries together)

    6. When clicking an ad on the DDG results page, all data available
      in your session is sent to the advertiser, which is why the Epic
      browser project refuses to set DDG as the default
      search engine.

    7. DDG blacklisted Framabee, a search engine for the
      highly respected framasoft.org consortium.

  3. Censorship:
    Some people replace Google with DDG in order to avoid censorship. DDG is not the answer.

    1. DDG is complying with the “celebrity threesome
      injunction”.
  4. Harmful impact on net neutrality:

    1. DDG attempts to play both sides of the network neutrality fight.
      DDG donated $50k (as of 2020) to an
      opponent of net neutrality who ironically
      calls themselves “TechFreedom”. Then DDG also
      donated $50k to an opponent of TechFreedom, “Public
      Knowledge”, who actually calls for “NO rules
      preventing blocking of website”, yet Public Knowledge blocks Tor
      users from their own website by issuing a “403 forbidden” error.
      Public Knowledge intends to coach Congress
      on “How Interoperability Can Rein In Big Tech”, yet they
      themselves have broken interoperability with Tor as they make
      themselves electronically unreachable outside of Facebook,
      Twitter, Youtube, and Gmail.
  5. CloudFlare: DDG promotes one of the most pernicious
    privacy abusing tech giants and adversary to the Tor
    community: CloudFlare Inc. DDG results give high rankings to
    CloudFlare sites, thus leading users into the largest privacy
    abusing walled garden on the web.

    Supporting CloudFlare compromises privacy, net neutrality,
    democracy, and anonymity:

    1. Anonymity: CloudFlare DoS attacks Tor users, causing substantial
      damage to the Tor network.
    2. Privacy: All CloudFlare sites are surreptitiously MitM’d by design.
    3. Net neutrality: CloudFlare’s attack on Tor users causes access
      inequality, the centerpiece to net neutrality.
    4. DDG T-shirts are sold using a CloudFlare site, thus
      surreptitiously sharing all order information (name, address,
      credit card, etc) with CloudFlare despite their statement at the
      bottom of the page saying “DuckDuckGo is an Internet privacy
      company that empowers you to seamlessly take control of your
      personal information online, without any tradeoffs.” (2019)
    5. DDG hired CloudFlare to host spreadprivacy.com (2019)

    DDG also donated over $186k to a series of
    privacy-abusing CloudFlare sites run by “Demand Progress”, “Fight
    for the Future”, and “Access Now”. Despite getting nearly $70k
    from DDG, FFTF continues to expose their own patrons to the very
    evil they claim to be fighting. Demand Progress, who received
    $100k from DDG, posts their claim to “contest concentrated
    corporate power”
    directly on their CloudFlare site,
    as well as the claim that they educate people on
    “the impacts of corporate power over our economy and democracy” as
    they “confront corporate bad actors”
    , all of which is bluntly
    unaligned with their CloudFlare patronage. Access Now, who
    received $16k from DDG, also used CloudFlare to block Tor users,
    hypocritically acting against their
    own mission to “fight for a free and open
    internet, advocating for the Net Neutrality principle that internet
    access should be offered to everyone on a nondiscriminatory basis,
    without favoring certain websites, applications, or services.”
    DDG
    apparently does little inspection on those they donate to, as if
    they’re merely selecting recipients with names that promote their
    privacy propaganda strategy to boost user loyalty.

  6. Harmful Partnerships with Adversaries of Privacy Seekers:

    1. DDG gets paid a commission when users visit eBay
      from DDG. Note that eBay has been caught
      sending JavaScript that snoops on their own customers by port
      scanning the LAN and reporting back to eBay. Moreover, eBay
      transactions are impossible without using PayPal, and
      PayPal abuses privacy in countless ways.

    2. DDG gets paid a commission when users visit
      privacy-abuser Amazon.

      image of JavaScript event that runs when clicking a DDG result

      DDG also uses AWS to crawl the web, which Amazon
      profits from. The Amazon partnership triggers substantial
      ethical issues:

      1. Amazon is making an astronomical investment in facial
        recognition which will destroy physical travel privacy
        worldwide.
      2. Amazon uses Ring and Alexa to surveil neighborhoods and the
        inside of homes.
      3. Amazon paid $195k to fight privacy in CA. (also
        see http://cal-access.sos.ca.gov/Campaign/Committees/Detail.aspx?id=1401518&view=late1)
      4. Amazon runs sweat shops, invests in climate denial, etc. The
        list of non-privacy related harms is too long to
        list here.
    3. DDG feeds privacy-abuser Microsoft by patronizing the Bing
      API for search results,
      using Microsoft’s ad network, using Outlook email
      service, hiring Microsoft to host DDG’s search site and host
      DDG’s crawler.

      1. The Dutch government commissioned a study which
        found Microsoft Office products to have
        several GDPR violations.
      2. Microsoft finances AnyVision to equip the Israeli military
        with facial recognition to be used against the Palestinians
        who they oppress.
      3. Microsoft paid
        $195k to fight privacy in CA. (also see
        http://cal-access.sos.ca.gov/Campaign/Committees/Detail.aspx?id=1401518&view=late1)
      4. DDG hires Microsoft for email service: torsocks dig @8.8.8.8 mx duckduckgo.com +tcp | grep -E '^\w' ==>
        “…duckduckgo-com.mail.protection.outlook.com”
    4. (historic) DDG is was previously partnered
      with Yahoo (aka Oath; plus Verizon and AOL by
      extension).

      (click to expand details)

      DDG helped Yahoo profit for several years by patronizing Yahoo’s
      API for search results, and also through advertising. Mention of
      Verizon, Yahoo, and Oath have been quietly scrubbed from DDG’s
      disclosures. There was no official announcement, so we cannot
      confirm whether there are still ties to Verizon et al.

      The Verizon corporate conglomerate is evil in many ways:

      1. Yahoo, Verizon, and AOL all supported CISPA (unwarranted surveillance bills)
      2. Yahoo, Verizon, and AOL all use DNSBLs to block individuals
        from running their own mail servers, thus forcing an
        over-share of e-mail metadata with a relay.
      3. Verizon and AOL both drug test their employees, thus intruding
        on their privacy outside of the workplace.
      4. Verizon is was an ALEC member (a powerful superPAC
        designed to put corporate political interests ahead of human
        beings). (edit: Verizon dropped ALEC membership in 2018)
      5. Verizon supports the TTP treaty.
      6. Yahoo voluntarily ratted out a human rights journalist (Shi
        Tao) to the Chinese gov w/out warrant, leading to his
        incarceration.
      7. Yahoo recently recovered “deleted” e-mail to convict a
        criminal. The deleted e-mail was not expected to be
        recoverable per the Yahoo Privacy Policy.
      8. Verizon received $16.8 billion in Trump tax breaks, then
        immediately laid off thousands of workers.
      9. (2012) Will block or degrade calls to disrupt customer use, at
        the request of law enforcement, with
        no court oversight.
      10. (2014) Verizon fined $7.4 million for violating customers’ privacy
      11. (2016) Verizon fined $1.35 million for violating customers’ privacy
      12. (2018) Verizon paid $200k to fight privacy in CA. See also California records.
      13. (2018) Verizon apparently caught taking voice prints
      14. unfavorable record retention policy (scroll down to Verizon)
      15. (2015) Only 2 stars on EFF transparency report
      16. (2016) Yahoo was caught surreptitiously monitoring
        Yahoo Mail messages for the NSA, resulting in EFF lawsuit
  7. Advertising Abuses & Corruption:

    1. DDG exploited a room at FOSDEM for commercial gain, to
      deliver a sales pitch despite its proprietary non-free server
      code, then dashed out without taking questions. Shame on FOSDEM
      organizers for allowing this corrupt corporate abuse of precious
      resources.
    2. Tor Project accepts an annual $25k “contribution
      (read: bribe) from DDG, so you’ll find that DDG problems are
      down-played by those close to the Tor Project (e.g. EFF). This
      is likely why Tor Browser always defaults to using DDG (which
      DDG conceals from their disclosure) and why Tor
      Project endorses DDG over Ss — ultimately against the
      interests of the privacy-seeking Tor community. This default
      search engine exploits
      The Tyranny of Convenience. The EFF also pimps
      DDG — a likely consequence of EFF’s close ties to Tor Project.

      (click to expand details on how Tor Project responds to criticism about their loyalty toward DuckDuckGo [their benefactor] in IRC)
      18:20 < psychil> if torbrowser is going to be recommended, it should also be open to scrutiny.  in the absence of that transparency, you create an untrustworthy forum.
      18:20 < psychil> we've seen a loyalty from TB toward duckduckgo, but DDG is in partnership with Verizon, Yahoo, AOL et. al.
      18:21 < psychil> all CISPA-sponsoring companies
      18:22 < psychil> if ppl choose to trust them fair enough, but this trust shouldn't be pushed on every user weighing their choice of browsers
      18:26 -!- mode/#tor [-b psychil@*!*@*] by ChanServ
      18:27 < YY_Bozhinsky> psychil: i am using Tor (thanks to Tor Devs)... PLUS brain - good bundle. I am happy. And please, don't rush to change Reality (do it slowly with love and respect). Because it's home for many ppl. They construct their lives in it. Think twice before ruining that. Please.
      18:27 -!- mode/#tor [+b psychil!*@*] by ChanServ
      18:27 -!- psychil was kicked from #tor by ChanServ [wont stop the FUD]
      

      Tor Project is notoriously fast to censor any discourse (no matter how civil) when it supports a narrative that doesn’t align with their view / propaganda.


Editor’s note: We published a (now-outdated) version before. The author notes: “The significant changes are: DDG is now MS-hosted (2.3), DDG gets commission when Amazon or eBay links are followed, Verizon-Yahoo is no longer a partner, and there’s more dirt on DDG donees (TechFreedom, “Public Knowledge”, “Demand Progress”, “Fight for the Future”, and “Access Now”)”

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. IRC Proceedings: Thursday, January 27, 2022

    IRC logs for Thursday, January 27, 2022



  2. Links 28/1/2022: GNU Poke 2.0 and OPNsense 22.1 Released

    Links for the day



  3. Links 27/1/2022: Archinstall 2.3.1 and Nix 2.6.0

    Links for the day



  4. On the Internet, Trust Should Not Become Centralised

    “Trust” is a word that lost its meaning in the era of “TPM” and fancier names for 'Palladium'; we need to reject this idea that computers need to check with Microsoft if the operating system is trusted (not just Windows!), check with Gulag/Chrome if a Web site is trusted, and whether it's OK to run some application/s on one's own computer (as if Jim Zemlin et al get to decide what is trusted)



  5. Microsoft-Connected Publishers Suffer and Perish With Microsoft (While Peddling 'Fake News' for Their Beloved Sponsor)

    IDG and other fake news outlets/networks/sites (selling to companies flattering articles about themselves or renting out 'news space' to them, not just ad space) want us to think Microsoft is doing very well, but it's just that same old Ponzi scheme



  6. Links 27/1/2022: Mabox Linux 21.11 Herbolth and PipeWire 0.3.44

    Links for the day



  7. IRC Proceedings: Wednesday, January 26, 2022

    IRC logs for Wednesday, January 26, 2022



  8. [Meme] EPO: Pursuing an Eastern and Western District of Europe (for Patent Trolls and Software Patents)

    With the EPO so flagrantly lying and paying for misinformation maybe we should expect Benoît Battistelli and António Campinos to have delusions of grandeur… such as presiding over the Eastern and Western District of Europe, just like Mr. Gilstrap and Mr. Albright (political appointment by Donald Trump, ushering in “the swamp”)



  9. Gemini at 2,000: 86% of Capsules Use Self-Signed Certificate, Just Like the Techrights Web Site (WWW)

    As shown in the charts above (updated an hour ago), the relative share of ‘Linux’ Foundation (LE/LF; same thing, same office) in the capsules’ certificates has decreased over time; more and more (in terms of proportion) capsules choose to sign their own certificate/s; the concept of ‘fake security’ (centralisation and consolidation) should be rejected universally because it leaves nobody safe except plutocrats



  10. [Meme] UPC: Many Lies as Headlines, Almost Exclusively in Publishers Sponsored by EPO and Team UPC to Produce Fake News (Lobbying Through Misinformation)

    Lest we forget that EPO dictators, like Pinky and the Brainless Benoît Battistelli and António Campinos, have long littered the EPO's official Web site as well as publishers not directly connected to the EPO (but funded by it) with disinformation about the UPC



  11. EPO as the 'Ministry of Truth' of Team UPC and Special Interests

    The 'Ministry of Truth' of the patent world is turning the EPO's Web site into a propaganda mill, a misinformation farm, and a laughing stock with stock photography



  12. Microsoft 'Delighted' by Windows 11 (Vista 11) Usage, Which is Only 1% Three Months After Official Launch and Six Months After Release Online

    Microsoft boosters such as Bogdan Popa and Mark Hachman work overtime on distraction from the failure Vista 11 has been (the share of Windows continues to fall relative to other platforms)



  13. Links 27/1/2022: Preinstalled GNU/Linux (Ubuntu) and Arch Linux-Powered Steam Deck 30 Days Away

    Links for the day



  14. Don't Fall for Microsoft's Spin That Says Everything is Not Secure and Cannot be Secured

    Microsoft keeps promoting the utterly false concept that everything is not secure and there's nothing that can be done about it (hence, might as well stay with Windows, whose insecurity is even intentional)



  15. At Long Last: 2,000 Known Gemini Capsules!

    The corporate media, looking to appease its major sponsors (such as Web/advertising giants), won't tell you that Gemini Protocol is rising very rapidly; its userbase and the tools available for users are rapidly improving while more and more groups, institutions and individuals set up their own capsule (equivalent of a Web site)



  16. Links 26/1/2022: Gamebuntu 1.0, PiGear Nano, and Much More

    Links for the day



  17. IRC Proceedings: Tuesday, January 25, 2022

    IRC logs for Tuesday, January 25, 2022



  18. Links 26/1/2022: No ARM for Nvidia, End of EasyArch, and WordPress 5.9 is Out

    Links for the day



  19. Why the Unified Patent Court (UPC) is Still Just a Fantasy and the UPC's Fake News Mill Merely Discredits the Whole Patent 'Profession'

    Patents and science used to be connected; but now that the patent litigation 'sector' is hijacking patent offices (and even courts in places like Texas) it's trying to shove a Unified Patent Court (UPC) down the EU's throat under the disingenuous cover of "community" or "unity"



  20. Links 25/1/2022: Vulkan 1.3 Released, Kiwi TCMS 11.0, and antiX 19.5

    Links for the day



  21. Gemini Milestones and Growth (Almost 2,000 Known Gemini Servers Now, 39,000 Pages in Ours)

    The diaspora to Gemini Protocol or the transition to alternative 'webs' is underway; a linearly growing curve suggests that inertia/momentum is still there and we reap the benefits of early adoption of Gemini



  22. [Meme] Get Ready for Unified Patent Court (UPC) to be Taken to Court

    The Unified Patent Court (UPC) and Unitary Patent system that’s crafted to empower EPO thugs isn’t legal and isn’t constitutional either; even a thousand fake news 'articles' (deliberate misinformation or disinformation) cannot change the simple facts because CJEU isn’t “trial by media”



  23. The EPO Needs High-Calibre Examiners, Not Politicians Who Pretend to Understand Patents and Science

    Examiners are meant to obstruct fake patents or reject meritless patent applications; why is it that working conditions deteriorate for those who are intellectually equipped to do the job?



  24. Free Software is Greener

    Software Freedom is the only way to properly tackle environmental perils through reuse and recycling; the mainstream media never talks about it because it wants people to "consume" more and more products



  25. Links 25/1/2022: Git 2.35 and New openSUSE Hardware

    Links for the day



  26. IRC Proceedings: Monday, January 24, 2022

    IRC logs for Monday, January 24, 2022



  27. Links 25/1/2022: GPL Settlement With Patrick McHardy, Godot 4.0 Alpha 1, and DXVK 1.9.4 Released

    Links for the day



  28. Proprietary Software is Pollution

    "My daughter asked me about why are we throwing away some bits of technology," Dr. Andy Farnell says. "This is my attempt to put into words for "ordinary" people what I tried to explain to a 6 year old."



  29. Microsoft GitHub Exposé — Part XV — Cover-Up and Defamation

    Defamation of one’s victims might be another offence to add to the long list of offences committed by Microsoft’s Chief Architect of GitHub Copilot, Balabhadra (Alex) Graveley; attempting to discredit the police report is a new low and can get Mr. Graveley even deeper in trouble (Microsoft protecting him only makes matters worse)



  30. [Meme] Alexander Ramsay and Team UPC Inciting Politicians to Break the Law and Violate Constitutions, Based on Misinformation, Fake News, and Deliberate Lies Wrapped up as 'Studies'

    The EPO‘s law-breaking leadership (Benoît Battistelli, António Campinos and their corrupt cronies), helped by liars who don't enjoy diplomatic immunity, are cooperating to undermine courts across the EU, in effect replacing them with EPO puppets who are patent maximalists (Europe’s equivalents of James Rodney Gilstrap and Alan D Albright, a Donald Trump appointee, in the Eastern and Western Districts of Texas, respectively)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts