{"id":19169,"date":"2022-05-28T19:09:43","date_gmt":"2022-05-29T03:09:43","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/05\/28\/news-12902\/"},"modified":"2022-05-28T19:09:43","modified_gmt":"2022-05-29T03:09:43","slug":"news-12902","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/05\/28\/news-12902\/","title":{"rendered":"DuckDuckGo Isn\u2019t as Private as You Think"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/629152087f1e2151f5dd8db4\/master\/pass\/GettyImages-1358638143.jpg\"\/><\/p>\n<p><strong>Credit to Author: Andy Greenberg| Date: Sat, 28 May 2022 13:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/andy-greenberg\">Andy Greenberg<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">After another week<\/span> of dismally tragic news and moral failures by the powerful, it&#x27;s good to know that you can at least depend on the small things, like &quot;privacy-focused&quot; search engine and browser DuckDuckGo resisting the temptation to sell out and help corporations to surveil its users. Oh, wait.<\/p>\n<p class=\"paywall\">Yes, a security researcher revealed this week that even DuckDuckGo, which markets itself as &quot;the internet privacy company,&quot; <a data-offer-url=\"https:\/\/techcrunch.com\/2022\/05\/24\/ddg-microsoft-tracking-blocking-limit\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/techcrunch.com\/2022\/05\/24\/ddg-microsoft-tracking-blocking-limit\/&quot;}\" href=\"https:\/\/techcrunch.com\/2022\/05\/24\/ddg-microsoft-tracking-blocking-limit\/\" rel=\"nofollow noopener\" target=\"_blank\">made an exception for its business partner Microsoft to its browser&#x27;s blocking of some advertising trackers on websites<\/a>, sparking accusations of betraying its purported privacy ethos. The <a data-offer-url=\"https:\/\/knowyourmeme.com\/memes\/milkshake-duck\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/knowyourmeme.com\/memes\/milkshake-duck&quot;}\" href=\"https:\/\/knowyourmeme.com\/memes\/milkshake-duck\" rel=\"nofollow noopener\" target=\"_blank\">milkshake-ducking<\/a> of DuckDuckGo comes amid a rising awareness of how the stakes of online surveillance are rising as signs grow that the US Supreme Court will overturn <em>Roe v. Wade<\/em>\u2019s protections on abortion rights: A new report this week from the Surveillance Technology Oversight Project laid out all the <a href=\"https:\/\/www.wired.com\/story\/surveillance-police-roe-v-wade-abortion\/\">technological means available to law enforcement and private litigants to surveil those seeking abortions<\/a>, should <em>Roe<\/em> be struck down. And more than 40 members of Congress called on Google to <a href=\"https:\/\/www.wired.com\/story\/google-urged-stop-tracking-location-data-roe-reversal\/\">stop tracking location data in Android ahead of a potential <em>Roe<\/em> reversal<\/a>.<\/p>\n<p class=\"paywall\">In other privacy news, we looked at how the European Union&#x27;s General Data Protection Regulation <a href=\"https:\/\/www.wired.com\/story\/gdpr-2022\/\">has failed to meaningfully curb Big Tech&#x27;s privacy abuses<\/a> four years after its passage. Australia&#x27;s digital driver\u2019s licenses turn out to be <a href=\"https:\/\/www.wired.com\/story\/digital-drivers-license-forgery-identity-theft\/\">far too easy to forge<\/a>. China has been <a href=\"https:\/\/www.wired.com\/story\/china-us-hacking-accusations\/\">saber-rattling with accusations about American cyberespionage<\/a>. We spoke to the inventor of the browser &quot;cookie&quot; about <a href=\"https:\/\/www.wired.com\/story\/what-do-cookie-preferences-pop-ups-mean\/\">how to handle cookie settings for privacy<\/a>\u2014and those ubiquitous cookie-related pop-ups on websites. And we also interviewed the CEO of Protonmail, now rebranded as just Proton, about its <a href=\"http:\/\/www.wired.com\/story\/proton-mail-calendar-drive-vpn\/\">ambitions to offer a broader range of privacy-focused services beyond email<\/a>\u2014hopefully without, ahem, surveillance exceptions for its business partners.<\/p>\n<p class=\"paywall\">But there&#x27;s more. As usual, we\u2019ve rounded up all the news that we didn\u2019t break or cover in-depth this week. Click on the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">Cybersecurity and privacy researcher Zach Edwards discovered a glaring hole in the privacy protections of DuckDuckGo&#x27;s purportedly privacy-focused browser: By examining the browser&#x27;s data flows on Facebook-owned website Workplace.com, Edwards found that the site&#x27;s Microsoft-placed tracking scripts continued to communicate back to Microsoft-owned domains like Bing and LinkedIn. DuckDuckGo CEO Gabriel Weinberg responded to Edwards on Twitter, admitting that &quot;our search syndication agreement prevents us from stopping Microsoft-owned scripts from loading&quot;\u2014essentially admitting that a partnership deal DuckDuckGo struck with Microsoft includes creating a carveout that lets Microsoft track users of its browsers. Weinberg added that DuckDuckGo is &quot;working to change that.&quot; (A company spokesperson reiterated in an email to WIRED Weinberg&#x27;s <a data-offer-url=\"https:\/\/www.reddit.com\/r\/technology\/comments\/uxiah9\/duckduckgo_caught_giving_microsoft_permission_for\/i9xxjsn\/?context=3\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.reddit.com\/r\/technology\/comments\/uxiah9\/duckduckgo_caught_giving_microsoft_permission_for\/i9xxjsn\/?context=3&quot;}\" href=\"https:\/\/www.reddit.com\/r\/technology\/comments\/uxiah9\/duckduckgo_caught_giving_microsoft_permission_for\/i9xxjsn\/?context=3\" rel=\"nofollow noopener\" target=\"_blank\">assertion<\/a> that none of this applies to DuckDuckGo search, adding that both its search and its browser offer more privacy protections than the competition.) In the meantime, the revelation blew a glaring hole of its own in the company&#x27;s reputation as a rare privacy-preserving tech firm. Turns out this surveillance capitalism thing is pretty hard to escape.<\/p>\n<p class=\"paywall\">Staying on that surveillance capitalism theme, Twitter agreed this week to pay a $150 million fine after the Federal Trade Commission and the US Department of Justice accused it of selling user data that it had collected under the guise of security. Twitter had asked users to share the emails and phone numbers for security purposes, such as two-factor authentication and account recovery, but had ultimately sold the data to advertisers seeking to target ads to its users. That bait-and-switch violated an agreement Twitter made with the FTC in 2011 after earlier privacy misbehavior.<\/p>\n<p class=\"paywall\">If the world had any doubts that China&#x27;s&quot;re-education camps&quot; for Muslim minorities in its Xinjiang region were in fact prisons with euphemistic names, a massive leak known as the Xinjiang Police Files should correct that delusion. The leak, provided by an unknown source to researcher Adrien Zenz, who in turn provided the info to a group of global media outlets, includes a vast collection of tens of thousands of internal files, manuals, and even detailed photos revealing life in one of Xinjiang&#x27;s prisons. The files reveal, for instance, shoot-to-kill orders for any prisoner attempting to escape the camps, and guidelines for shackling the inmates when they&#x27;re transferred between different parts of the facility\u2014hardly the practices of a &quot;vocational school,&quot; as China describes the camps to the world. It also includes <a data-offer-url=\"https:\/\/www.bbc.co.uk\/news\/extra\/85qihtvw6e\/the-faces-from-chinas-uyghur-detention-camps\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bbc.co.uk\/news\/extra\/85qihtvw6e\/the-faces-from-chinas-uyghur-detention-camps&quot;}\" href=\"https:\/\/www.bbc.co.uk\/news\/extra\/85qihtvw6e\/the-faces-from-chinas-uyghur-detention-camps\" rel=\"nofollow noopener\" target=\"_blank\">photos of the camp&#x27;s detainees<\/a>, who were as young as 15 and as old as 73, often jailed for years without trial for offenses as simple as studying Islamic texts.<\/p>\n<p class=\"paywall\">In a strange replay of events from 2016, Google researchers and the UK government revealed that a site publishing leaked documents from a group of pro-Brexit UK politicians was, in fact, created by Russia-based hackers. The site, called Very English Coop d&#x27;Etat, described its collection of leaked emails as coming from an influential group of hardline right-wing Brexit supporters, including former MI6 head Richard Dearlove. But Google&#x27;s Threat Analysis Group told Reuters that the site appears to have been created by a Russian hacker group it calls Cold River. Former UK intelligence head Dearlove cautioned that the leak of his emails should be understood to be a Russian influence operation, especially given the West&#x27;s current icy relations with Russia over its illegal and unprovoked invasion of Ukraine.<\/p>\n<p class=\"paywall\">An accidentally unsealed warrant, spotted by Forbes, revealed that an Iraqi man had allegedly sought to assassinate former president George W. Bush in Dallas, going so far as to take video of Bush&#x27;s home in November. According to the warrant, the FBI says it foiled the plot through the use of a confidential informant and surveillance of the would-be assassin&#x27;s WhatsApp messages&#x27; metadata. The case shows how, despite law enforcement&#x27;s claims that end-to-end encryption can stymy its investigations, the FBI has managed to monitor encrypted apps like WhatsApp and even penetrate communications on them through the use of undercover informants.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/duckduckgo-microsoft-twitter-ft-bush-assassination-whatsapp\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/629152087f1e2151f5dd8db4\/master\/pass\/GettyImages-1358638143.jpg\"\/><\/p>\n<p><strong>Credit to Author: Andy Greenberg| Date: Sat, 28 May 2022 13:00:00 +0000<\/strong><\/p>\n<p>Plus: A $150 million Twitter fine, a massive leak from a Chinese prison in Xinjiang, and an ISIS plot to assassinate George W. Bush.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358,21382,21357],"class_list":["post-19169","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks","tag-security-privacy","tag-security-security-news"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19169"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19169\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}