Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is the whole privacy on search thing really a big issue?

I, for one, want Google to be all Orwellian on me because it will mean better search results. I had a scenario like this a few days ago when I googled for "fabric" -- Being a Python developer I was looking for http://fabfile.org and it shows up as the second result while logged in. If I'm not, it won't show up.

This may be the outlier state of mind on HN, but I think in general, as-in billboard advertising, it's not an issue. Am I wrong?



Is the whole privacy on search thing really a big issue?

Of course it is. Google and Facebook have been pushing the bounds of privacy repeatedly over the years because it is in their financial best interest to do so.

Their primary product isn't search or communication or maps. Their product is plain and simple people's personal information. And, becuase they are a corporation in the USA they are legally bound to maximize shareholder value.

So, of course Google and Facebook have to erode the concept of online privacy. That is their product and that is the value that they are legally bound to maximize.

If they were very clear and up front about this issue, and communicated that information in plain language to their users that would be one thing. But, they don't.

Google doesn't every plainly say, "We track your location with your android phone. We track your searches on Google. We track what sites you visit though our advertising network. We track who you email when you use Gmail. If you use our calendar, we know what your schedule is. We track who you call when you use Google Voice. And, we want you to trust us to do the right thing with that data. We make a crap load of money using everything that we know about you to let other people sell stuff to you. Oh, and by the way, the government can have access to all that data without a search warrant."

So, yes, I do think the privacy issue is pretty important. You have a couple of massive corporations who are for all intents and purposes forced to erode people's concept of privacy. And, if people are going to compete with Google, one of the areas they are very vulnerable is in the area of privacy. Gabriel has been kicking their ass on this, and it's an area where they are vulnerable to competitors.

I say more power to DDG. It's a conversation that needs to be had, and more people need to know about this.


> they are legally bound to maximize shareholder value

Can you point to a single instance where a company was forced to commit some act that its managers reasonably thought was morally wrong because of the "law" that companies must maximize shareholder value? Personally I think this trope has no basis in fact and cannot explain why Google or any other company is compelled to do things that are wrong.

There are many possible reasons why they would do something you disagree with: maybe they don't think it's wrong. Maybe they actively want to do something bad. Maybe you are not correct in your beliefs about what they are doing. But I think the reason you gave why they need to violate people's privacy is a cop out.

There are also a number of counter-examples where corporations fail to maximize shareholder profits by donating to charity, taking principled environmental stances, etc. I don't know how you or anyone could come to the conclusion that the U.S. legal system rigidly enforces absolute profit maximization.

> Oh, and by the way, the government can have access to all that data without a search warrant.

Don't know where you are getting this from.


"Can you point to a single instance where a company was forced to commit some act that its managers reasonably thought was morally wrong because of the "law" that companies must maximize shareholder value?"

I can point to companies that sell tainted drugs, products that contain lead paint, that dump toxic materials in rivers, do shoddy work on oil wells, etc. They don't do this because they are required to maximize shareholder value. They do it because of their pursuit of money. The difference isn't a meaningful one in my mind.

I think if the law was changed and companies were forced to consider societal interest then perhaps things would change for the better. Perhaps not. As it is, the law is a bad one in my opinion.


"Companies do bad stuff" != "Companies are legally required to do bad stuff".


I don't understand the purpose of your post. I didn't come close to claiming otherwise. I'm not claiming otherwise.

I provided examples of companies doing bad stuff in the pursuit of money. I opined that a change in the law is needed. The fact that companies doing bad stuff does not equal companies being legally required to bad stuff supports my position. That is, even though there is no law requiring companies to do bad stuff they still sometimes do. I suggested that a change in the law might lead to companies doing bad stuff less frequently.

Again, I don't understand the purpose of your post. Can you clarify?


You responded to a post arguing against the notion that companies are legally required to do things that are wrong for profit. You responded with an argument that many companies had done things wrong for profit, but without proving that they are legally required to do so. So your response was basically irrelevant, and the GP is pointing that out.

As a technical matter, there are a number of ways that laws already require companies to consider the broad interests of society. Environmental regulations, taxes, tort law, and various other similar regulations, not to mention the natural pressure that the best interest of society tends to be somewhat compatible with profit, all influence companies to choose the option that is best for society as a whole most of the time. I wonder what specific law you are proposing when you say that laws should be changed to make companies consider the "societal interest."


No one is claiming that the law that corporation are required to try to maximize shareholder value is the same thing as requiring companies to do bad things. Some people, me included, are saying that there are unintended consequences with this law and that some companies do bad things in an effort to maximize profit (increase shareholder value).

Pointing out that companies doing bad things is not the same thing as legally requiring them to do bad things is a red herring. It's not germane to the discussion at hand.


On the contrary, the claim in the original post is exactly that Google must do bad things because of some unnamed law that corporations must maximize shareholder value. Specifically:

"So, of course Google and Facebook have to erode the concept of online privacy [i.e. do bad things]. That is their product and that is the value that they are legally bound to maximize [i.e. the reason they must do bad things is because they are legally required to]."

That is what I was responding to when you responded to me. Since you are so mistaken about what exactly the discussion at hand is, I don't know how you can claim to know what is germane to it.


If your intention was not to answer the question you quoted, it would have been best not to quote it, because it looks like you are trying to answer it.


No one is claiming that the law that corporation are required to try to maximize shareholder value is the same thing as requiring companies to do bad things. Some people, me included, are saying that there are unintended consequences with this law and that some companies do bad things in an effort to maximize profit (increase shareholder value).

Pointing out that companies doing bad things is not the same thing as legally requiring them to do bad things is a red herring. It's not germane to the discussion at hand.


The best (but not the only) example of a corporation acting immorally to maximize shareholder value is Ford.

Prior to the release of the Ford Pinto, Ford's managers were fully aware of a design flaw in the Ford Pinto. As most people know, the gas tank on the car made the car explode in a ball of flames if it was involved in a rear end collision.

Ford's management compared the costs of a redesign to the costs associated with wrongful death lawsuits resulting from this design flaw. It was cheaper for them to pay the wrongful death lawsuits, so that's the decision that was made. It's very clear that this decision was made in an effort to maximize shareholder value, and did not take ethics into consideration whatsoever.

More information on this topic at the link below (Link is "Let Me Duck Duck Go That For You, since DDG is the primary topic of this thread):

http://lmddgtfy.com/?q=ford+pinto+lawsuits


> Can you point to a single instance where a company was forced to commit some act that its managers reasonably thought was morally wrong because of the "law" that companies must maximize shareholder value?

Tobacco companies concealing evidence that nicotine is addictive is sort of the textbook case for this, though you are correct that it is not a law as such. Pretty much every corporation has in its charter a mandate to maximize shareholder value within certain constraints.


Yes, I can. I was employed by such a company and laid off when I made a stink.

There is no legal "law" of such: it's an economic reality, however.


Can you point to a single instance where a company was forced to commit some act that its managers reasonably thought was morally wrong because of the "law" that companies must maximize shareholder value? Personally I think this trope has no basis in fact and cannot explain why Google or any other company is compelled to do things that are wrong.

Really? I'm surprised that you have a problem believing that people who manage companies might do things of dubious moral value in order to maximize profit. But, if you insist...

It could be easily argued that BP, Halliburton, et al... maximized shareholder value over environmental safety concerns.

http://en.wikipedia.org/wiki/Deepwater_Horizon_oil_spill

The current recession is largely due to financial services companies creating derivatives out of sub prime mortgages. That is, bundling toxic debt and making it look like a AAA rated investment and selling it for profit.

http://en.wikipedia.org/wiki/Late-2000s_recession

Enron's "...reported financial condition was sustained substantially by institutionalized, systematic, and creatively planned accounting fraud, known as the "Enron scandal""

http://en.wikipedia.org/wiki/Enron

Vioxx was a drug that I've seen people die from. It was pushed through the FDA approval process and then withdrawn after people started dying from it.

http://en.wikipedia.org/wiki/Rofecoxib

Classic example of corporations producing and selling a drug that was toxic, leading to thousands of horrible birth defects.

http://en.wikipedia.org/wiki/Thalidomide

IBM made a lot of money selling automation systems so the Nazi's could efficiently kill millions in the Holocaust. http://en.wikipedia.org/wiki/IBM_and_the_Holocaust Chiquita Brands has admitted to sponsoring terrorist organizations in Latin America

http://en.wikipedia.org/wiki/Doe_v._Chiquita_Brands_Internat...

> Oh, and by the way, the government can have access to all that data without a search warrant.

Don't know where you are getting this from.

Really??? If you insist...

"Under this program, referred to by the Bush administration as the "terrorist surveillance program", part of the broader President's Surveillance Program, the NSA is authorized by executive order to monitor, without search warrants, phone calls, e-mails, Internet activity, text messaging, and other communication involving any party believed by the NSA to be outside the U.S., even if the other end of the communication lies within the U.S." [1]

ref:

[1] http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_co...


You have given plenty of examples of morally wrong things being done for financial gain. That is not news. People have been corrupt and greedy for thousands of years.

What you have failed to do is show any evidence at all that companies are legally obliged to be corrupt and greedy.

On your link about warrantless surveillance, scroll down to the long section on legal issues. While there is no question that the government asked for, and got, a lot of that information, the legality of the request is quite a different matter.

And now for the concrete counter-example, when the NSA asked for Qwest's cooperation, they didn't get it. This decision has materially affected Qwest's financials because they were shut out of a lucrative NSA contract.

Now show me the shareholder lawsuit against Qwest for failing to maximize shareholder value by refusing the NSA on this matter.


All your corporation-evil links fail because they do not show that any law requires this behavior. Please actually answer my question rather than other questions which I did not ask.

Your NSA link fails for two reasons. First, anyone can access your data without a search warrant if they do it illegally. It is deceptive to suggest that the USG can legally access your data without a search warrant. Second, as a technical matter, the USG can intercept communication between Google and you, but does not have access to Google's stored data. The concern is over the data that is going to be stored since obviously that communication between you and Google was going to happen anyway. DDG is no more safe from this attack surface than Google except inasmuch as they offer SSL search, which Google offers as well.


None of your links provide any evidence that the company was legally obligated to do any of those naughty things.


For what it's worth, I'm not saying that Corporations are legally bound to do immoral things. My argument is that people within corporations are required do to things that are in the corporations and the shareholders best interest.

And, that pressure at times causes people within corporations to do actions of questionable morality.


If the goal is privacy, there are many search engines respecting privacy already. The goal is better search results!

Since I don't have a Google account and ban many evil domain names such as googleanalytics.com, facebook.com, they can't track my information already. for me, there is no need to use a search engine with crappy user interface.


There is also a slightly different case - google passing on your search terms to the website that you click through to.

You may trust google with knowing that you searched for "naked bieber pics", but you may not want other websites also knowing your search habits.


Are they passing on search terms for previous searches or just the current search?

In your (frankly terrifying) example, would the site have had to have ranked for "naked bieber pics", showing up in the results and then you click it to pull the search terms? Because that would seem to be pretty innocuous.


Just the current search, but the problem is millions of pages run third-party ads, and most are run by very few networks. These ad networks can aggregate the terms and then they have previous searches as well.


Doesn't Incognito browsing, like present in Chrome, remedy all these worries?


People find ways around it, for example for a while Flash didn't respect incognito so ad networks just used their cookies instead (I think at one point html5 storage was being used too, but could be wrong).

There's been various HN posts about how people circumvent browser privacy settings to track you across websites and even tricks such as generating an almost unique key by hashing together browser, fonts installed, IP address, etc.. I'm not sure of the current state of play in that war though.

I guess if you really don't want people to track private searches with your accounts, use a whole other browser where you're not logged into Google in incognito mode.


not if you are logged in using your google account


Pedophilia is illegal in most countries, I'd be happy if ad networks gather data about your interest on young boys and pass it to the feds! Beasts!

Edit: judging by the downvotes, I guess a good bunch of hackers like to live in atrocity!


I think the downvotes are because you're missing the point so hard that they're assuming you must be trolling.


He who would trade liberty for some temporary security, deserves neither liberty nor security (via Ben Franklin)


You got the oft-excluded part of the quote right -- temporary security -- but the actual quote is, "he who would trade Essential Liberty for some Temporary Security, deserves neither Liberty or Security."

Many people omit the word, "temporary". The suspicious part of me says they do it so their (mis-quoted) statement appears more bold and uncompromising.


When you click a link, you usually send the refferrer url to the site you go to. Naturally google's search terms are a very easy to parse and a well known url. So when you click a site's link they know that you came from google and that you searched for xyz.

Duck duck go actually redirects you in a way so that the referrer is not known to the site. They all think you came from duckduckgo.com. DDG also keeps no logs. Basically your own activity online cannot be used against you.

Now, privacy aside, I really like DDG for other reasons, like search relevance, continuous scrolling, zero-click info, etc. So its kind of win-win for me.


I am fairly sure that the issue is the browser passing on the referrer, not that Google is making websites aware of any additional information. I might be wrong, of course; there's a lot of FUD about this floating around.


The browser does it, and did it long before Google existed.


That doesn't mean Google couldn't or shouldn't prevent the browser from doing it.

When this all started, no one envisioned ad networks and data companies aggregating all this personal information, or even that search terms would be a central part of the Internet.

So now that we know what is going on, why allow this personal information to leak? As far as I can tell, the only reason is so Webmasters can do better at Google SEO. And that reason can be wholly mitigated through the use of Google's Webmaster Tools.


"And that reason can be wholly mitigated through the use of Google's Webmaster Tools."

No, Google's webmaster tools only provide a sampling of the data. We used to provide info for only 100 queries. Now we provide it for more queries, but it's still a sample: http://googlewebmastercentral.blogspot.com/2010/04/more-data...

Please don't make the argument that the data in our webmaster console is equivalent to the data that websites can currently find in their server logs, because that's not the case.


Hi Matt. Is there any technical reason why that tool can't provide full information? Clearly Google isn't opposed to not sending referrer data, given the existence of https search, but doesn't DDG have a point about third parties having access to the referrer data? (Full disclosure: I wrote this article)


Maybe not "when it all started" but we envisioned massive data gathering and analyzing pretty early on.


Yep - if you don't want people seeing your bieberqueries, you should use SSL Google:

https://encrypted.google.com/

... or if you're super paranoid, disable sending referrer in your browser.


Firefox (at least) will still send referrer info when you navigate to a https: site from encrypted Google. You can change this in about:config by changing network.http.sendSecureXSiteReferrer to false.

Source: http://kb.mozillazine.org/Network.http.sendSecureXSiteReferr...


This.

Its silly to rely on trusting the search engine provider to be secure, better be secure on the client side.


I'm curious if it's possible to write a Firefox plugin that would block the HTTP-REFERRER header for certain sites.


RefControl https://addons.mozilla.org/en-US/firefox/addon/refcontrol/

I'm using it since years and I don't understand all that referrer-privacy hype. Just don't send the referrer.


I recently started using RefControl to get around the nytimes.com block which comes up if the referer isn't google.

For privacy reasons, I set it so it forges the referrer to be the root of the destination site if the domain is different too. So when I go to google.com and click on http://www.example.com/foo, the referer it sends is http://www.example.com/ instead of http://www.google.com/searchterm.

I haven't found any sites which this breaks yet...


You do realize this breaks the ability of www.example.com to track its traffic? They have now lost the information as to how their search rank is performing on Google, and have acquired incorrect information that they think you typed in www.example.com directly.

You're entirely within legal rights to do this, of course. But if everyone did, then sites would have no idea where their traffic is coming from. Morally it is a bit questionable: your browser is blatantly and directly lying to www.example.com about how you got there.


You think a website has a right to track where I came from. I think a user has a right to privacy.


If it is from an adwords campaign, you get the search terms.


Even if the site owner doesn't know that the referring url contained the search term "naked beiber pics" they still know you visited their page which most likely contains "naked beiber pics".


Exactly, the privacy issue around http referrers is a red herring.


You're free to opt out at any time:

http://www.google.com/privacy/ads/


AFAIK this doesn't shut off the search leakage in the referrer header.


That's a feature of how the internet works at an architectural level. How exactly is that Google's fault?

If you don't want referral headers to be sent from one website to another, use HTTPS, or turn it off in your browser.


Unfortunately, normal people don't know how to turn them off or use the https version. Google could do a lot of things to make this easier.

The best would be to just prevent ad networks from collecting this personal information altogether. The only reason I've heard against doing so is that webmasters need search terms for SEO, but they can get them via Webmaster tools.

Failing that, they could make a setting in the http version that turns off the headers. They could also make a setting that defaults to https. And they could make https easier to get to. Currently you can't even do https://google.com/ (you have to type in www.)


> Google could do a lot of things to make this easier.

And so could Microsoft, Mozilla, Apple, and Opera.

As others have mentioned, this is a good marketing move, but it's not clear to me that you actually care that much about this issue.


Having spoken to Gabriel offline, because I was building my own search engine, he cares quite a bit about this issue. A ton of us in tech clain to care about privacy, but very few of us put their balls (and actions) where their beliefs are. DuckDuckGo's privacy policy has been in place for quite some time. And, it's only been recently that he's advertised it.


Anyone who really cares can - and will - use HTTPS.

EDIT: It appears that at least one person disagrees with me. So, a quick question: Which takes more effort for the end user, switching to a new search engine or switching to https?


In the last few weeks, I've talked to a lot of people that care. And in general people do care: http://blogs.wsj.com/digits/2010/12/21/web-surfers-troubled-...

I can tell you that normal people who care also don't know about HTTPS or how to use it. I'm all for Google making it easier to do so, or otherwise stop this personal information from leaking. See http://news.ycombinator.com/item?id=2122431 for some ideas.

Also, FWIW, HTTPS alone doesn't solve the issue completely, as HTTPS->HTTPS traffic still leaks.


Actually, with Google Instant, the search terms aren't in the URL anymore - does it still leak?



Not if you use Opera.


Not sure why this hasn't been said yet (maybe I missed it), but dukgo.com already has this figured out.

https://duckduckgo.com/fabric

It knows that fabric means something in textiles, geology, etc, and that it has multiple meanings in computing. To get Python, just click 'more meanings'

EDIT: I guess my point was already made, so in order to contribute something to the conversation, I'll add this: if there's anything wrong with your search result, you can just click the feedback button in the corner, explain what it is ('not showing official site for x', etc) and it gets fixed really fast.


> Not sure why this hasn't been said yet (maybe I missed it), but dukgo.com already has this figured out.

Or better yet, search for "fabric python" and be done with it, no need for Google storing all your searches at the expense of you typing a few more characters once in a while.


Or just search for "fabric" without personalization/being-logged-in and you probably get the Python-related fabric in the top 10.

It was result number 7 for me.


The same word is likely to mean different things to different people. DDG doesn't have the infrastructure to handle this, Google has (with Search History). What you get with DDG is generic Bing results, lightly filered and in a different UI.


I would prefer the web to be better classified and less "guessing". For my queries google has been guessing wrong most of the time and putting results of things i didnt search for in the top results page.

With the bangs and the zero-click duck aproaches what I think is a really good solution, for 'fabric' you get : http://duckduckgo.com/?q=fabric Which has in the zero click info all the meanings (including the python library), and if you would want python related results just do: http://duckduckgo.com/?q=python+fabric And it works beautifully...

I guess is a matter of how you are used to search


I agree, when I search for "fabric" I want to see the same results (more or less) on whichever computer I'm on - logged in to Google or not.

If I want information on the fabric python library I just search for "python fabric" - works on DuckDuckGo as noted above and also works just fine on Google.


"I want to see the same results (more or less) on whichever computer I'm on"

Even if only to stay aware of where your sites (and those of clients) are going to be positioned when customers search for them.


Is the whole privacy on search thing really a big issue?

Yes it is, if you're a political activist. Both Yahoo and Google have a proven history spying on people on behalf of government.


"spying on people" is a really unfair way to describe what happens when you voluntarily share your information with a third party who is in turn subpoenaed.

You should be taking issue with the governments demanding the records rather than expecting these companies to break the law on your behalf.


Few spies self-identify as someone who hurts innocent people. They think of themselves as supporting their family while helping their government or something.

Don't focus on what nouns different parts of the spying apparatus choose to label themselves with, or what other functions they serve. Instead, consider their effects in the context of being a spying apparatus.


But how is it spying if you use the service voluntarily, they tell you exactly that they collect and often (always?) let you opt out of the collection.

That's a really diluted standard for "spying".


Well, consider spies in WW2, specifically the "loose lips sink ships" variety.

The spies that saying warns of were not crawling around in vents with night vision goggles, they were your friends, neighbors, and coworkers who would relay semi-public information to a processing center that used the info towards harmful ends.

I see this situation as a direct analogue. We communicate naturally with a supposedly disinterested or trustworthy party, who then collects that information and distributes it to others, without our best interests in mind.


Do Google and Yahoo actually have a policy of only turning over information to governments when subpoenaed, or otherwise legally compelled, and promise not to voluntarily turn over such information in the absence of a court order? I can't find any solid statements on that from either company.


Where do you draw the line? what governments is google allowed to hand over information to vs which ones it can deny?


The simple answer is wherever they have operations. I don't think it is unreasonable to say that if you are going to run ops within a country you implicitly have to follow the law of the land.

That being said, thinking they shouldn't be in a particular country which obligates them to do these things is a much more sound position than just saying they shouldn't follow the law in a few particular cases.

Ultimately, if you know they are operating in a country with a government which likes to do these sorts of things, caveat utilitor. (At least, try not to look so surprised when the police come knocking.)


wherever they have operations

And because of that I choose to use a 1-man search engine, without loss of quality, while gaining everything last bit of privacy.

And because of this, his stunt of a billboard ad is actually truthful.


Whether you place your trust in a multibillion dollar company, a one man shop, or just use an anonymizing proxy, the issues are the same.

The billboard is just noise and you are technically sophisticated enough to know better.


>Both Yahoo and Google have a proven history spying on people on behalf of government.

[citation needed]


And ye shall receive:

"An Indian man is facing five years in jail for making an "offensive" comment [against Sonya Ghandi] after Google handed his personal data to local police."

http://www.v3.co.uk/vnunet/news/2217063/google-handing-user-...

Yahoo taken to task over China

http://www.boycottyahoo.com/yahoo_taken_to_task_over_china.h...


Distortion. That's not Google spying on people. The guy use Orkut, a social network website, surely there's his account information there.

The personal data that is handed over is email address of the account. It's probably a privacy violation if it's really that hard to find out someone's email address once you know his social network account, but it's not spying on people.


Google OWNS Orkut, in fact, it says so on the 2nd line:

Google's Orkut social networking site

Here is the same story on TechCrunch showing how Google provided more than just an email address:

The owner of the email id Rahul Vaid was traced, using information supplied by Google, to Chakarpur in Gurgaon city of Haryana.

http://techcrunch.com/2008/05/18/hit-pause-on-the-evil-butto...


Yes, Google own Orkut.

That makes it even less sensible to call Google "spying" on people when one signup for Google's social network.


Ok, maybe, if it worked. But Google results have been tanking in quality. So now I vote for privacy. DuckDuckGo gives me quality results without being creepy.


I, for one, want Google to be all Orwellian on me because it will mean better search results.

Will it necessarily mean better search results or will it mean that you will be subjected to personalized spam produced by those who game Google's system? I think history shows that there will be at least a little of the latter.


I think it's a red herring, but enough people take it seriously for this to be brilliant PR on the part of Gabriel.


i don't think it's an outlier state of mind at all ... in fact at this stage the majority of people in the US aren't concerned about search privacy.

but, y'know, DuckDuckGo doesn't have to get the majority of people. with their incredibly low costs, if they can get their search market share to even 1%, they can be hugely profitable. and there are at least that many people who care.


How does ddg make money, anyway?


The search results to amazon are affiliate links. I'mbassuming they have other methods to get revenue as well.


Are they just aggregating search results from various websites and putting it all together into one package?


Judging from their homepage, I'd guess they sell bowties for ducks.



So you seriously want to give up your privacy (and ours as well) to save you typing one freaking word (python)? That's lazy to the point of being offensive.


[deleted]


That's being a bit pedantic, he's just using it as a colorful way of saying that he doesn't mind them keeping track of what he's done, and he backs it up with a really good reason.


For anyone wondering, this comment has changed. After being told by ericd he was being a pedantic ass and downvoted he edited the comment. This isn't what it originally said.


And now it's deleted, such a jerk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: