Recommended Posts

This past week private search engine DuckDuckGo recorded their best week ever for traffic. The website, which does not record user?s clicks, provides a service for those who wish to browse the Internet away from the prying eyes of the government or Google...

http://thebackbencher.co.uk/duckduckgo-receives-record-traffic-following-prism-scandal/

People switching need to watch / listen to the latest episode of Security Now. (http://twit.tv/show/security-now/408)

The data collection isn't being made at Google's facilities. Using another search engine is pointless.

But google is directly involved as a 'supporting PRISM' along with Microsoft, where duckduckgo isn't. don't mean that what you are searching won't be logged, but its less likely and showing that people won't stand for such direct secret involvement.

This guy in the video is a quack too.. he's rambling about things he barely grasps. Near the end when he says hes' 'uncomfortable' with 128bit encryption I nearly lost it. Check out around 1h31 to contradict yourself. Its definitely being made at googles facilities, however its not being made 'in' google itself and they aren't affiliated and they can't talk about it either.

This guy in the video is a quack too.. he's rambling about things he barely grasps.

You don't know much about Steve Gibson, do you?

I thought too years ago he was a quack...until I started listening to him on a regular basis. You don't need to listen to all 400+ podcasts to realize he knows his stuff.

But google is directly involved as a 'supporting PRISM' along with Microsoft, where duckduckgo isn't. don't mean that what you are searching won't be logged, but its less likely and showing that people won't stand for such direct secret involvement.

 

Google and MS are not involved with PRISM.  They have issued statements to that effect as well as many other companies.  They do have to respond to legal requests tho...as would any company.

Near the end when he says hes' 'uncomfortable' with 128bit encryption I nearly lost it.

Why? 128-bit encryption isn't what it used to be. MS themselves has stopped issuing certificates with less than 1024 bits almost a year ago. How strong encryption is doesn't remain fixed across time.

Google and MS are not involved with PRISM.  They have issued statements to that effect as well as many other companies.  They do have to respond to legal requests tho...as would any company.

They have 'fell victim to' I guess is a better way to word it, with digital taps on their upload servers. 

Why? 128-bit encryption isn't what it used to be. MS themselves has stopped issuing certificates with less than 1024 bits almost a year ago. How strong encryption is doesn't remain fixed across time.

Its blown open publicly last I knew. I'd be more than uncomfortable with it.. I'm referring to SSL/RC4 encryption, not AES or DES or any other non-common web security layer. Hell I read a few articles on how 256-bit can be severely weakened by predicting possible outcomes and prioritizing the method in brute-forcing it, example would be reducing 2356 years computer processing to around 25 on the same hardware. Theres NO encryption that is secure and there never will be. Its only a time-thing, you hope what you encrypted stays that way until its no longer relevant.

You don't know much about Steve Gibson, do you?

I thought too years ago he was a quack...until I started listening to him on a regular basis. You don't need to listen to all 400+ podcasts to realize he knows his stuff.

 

Likes

They have no direct access to their servers.  Whatever data is requested, they legally have to give.  But they provide the data.

 

Theres taps on all the upstreams of the major US data centers. Thats their order, and Snowden made this very obvious with his leaks including their timeline of involvement. Other than those huge data centers of microsoft, google, yahoo, apple, etc, its Tier1 providers, so basically where all the ISPs in the USA get their internet to sell... From a standpoint in the USA you might as well shut off your internet if you are choosing which evil to make your request at, you aren't going to anonymously make it without going through something like TOR. From outside the USA where Tier1 providers are not tapped - duckduckgo may be a wiser choice depending on how you hit their servers. Huge however tho, .com and .net addresses are part of VeriSign which is a US company, and so, they are USA redirected, so your request traffic, IP, times etc bounces off the NSA somewhere when you visit one regardless of where in the world you are.

DuckDuckGo has never given me good results, and if it gets popular you can bet they'll be getting their own fair share of NSL "requests", and like Google/Microsoft/Apple/Yahoo/etc. they'll probably lose if they try fighting them.

DuckDuckGo has never given me good results, and if it gets popular you can bet they'll be getting their own fair share of NSL "requests", and like Google/Microsoft/Apple/Yahoo/etc. they'll probably lose if they try fighting them.

 

They don't record user data so there would be nothing to give the authorities.

You don't know much about Steve Gibson, do you?

I thought too years ago he was a quack...until I started listening to him on a regular basis. You don't need to listen to all 400+ podcasts to realize he knows his stuff.

 

I know he wrote spinrite, software that saved my ass as well as continuing to save the ass of many of my friends, all for less than $100.

He knows what hes doing obviously, but hes one of those guys who can't summarize his knowledge into a digestible form. I found it hard to listen past 15 minutes of his 91 minute podcast, I can only imagine how he rambles in the other 400+ of them.

 Huge however tho, .com and .net addresses are part of VeriSign which is a US company, and so, they are USA redirected, so your request traffic, IP, times etc bounces off the NSA somewhere when you visit one regardless of where in the world you are.

 

What are you on about? That's not how things work at all!

He knows what hes doing obviously, but hes one of those guys who can't summarize his knowledge into a digestible form. I found it hard to listen past 15 minutes of his 91 minute podcast, I can only imagine how he rambles in the other 400+ of them.

 

Well, ok, I'll grant you most people have a short attention span, and neither him or Leo pretend this is a podcast for the masses.

 

Which is really a shame, as typically the people who keep propagating the most outrageous claims on forums such as this one are those who would benefit the most from listening to what he has to say, as he's thorough in his research and won't say anything he can't back up.

Well, ok, I'll grant you most people have a short attention span, and neither him or Leo pretend this is a podcast for the masses.

 

Which is really a shame, as typically the people who keep propagating the most outrageous claims on forums such as this one are those who would benefit the most from listening to what he has to say, as he's thorough in his research and won't say anything he can't back up.

Why don't you make a summary for the rest of us who suffer from ADD, or point out at what time he actually talks about PRISM.

This topic is now closed to further replies.
  • Posts

    • I've been on Deezer for over a decade, but glad that Tidal joined them in fighting AI slop. Can't stand such takes as Spotify's: "Spotify's CEO recently pushed back against listeners who call AI music "slop," urging people to stop using the term and instead embrace the creative potential of AI music."
    • “Could” … in the IS the healthcare is run by insurance companies that make indecent profits denying basic treatments to people that are paying money for nothing. Besides, where are all the Trump epigones who were stating that the tariffs were going to paid by foreign companies and not the US citizens? …
    • Microsoft Teams gets smarter at spotting sneaky meeting bots by Usama Jawad Microsoft Teams is set to receive a couple of new features soon, including a dedicated Recap app and a rather controversial location tracking functionality. The Redmond tech giant has also explained how it has made online communication and collaboration a lot more performant this year. Now, the company has detailed more secure bot admission mechanisms, as first reported by us in March 2026, and now available in Teams. As the use of AI has expanded across enterprise environments, Microsoft has begun allowing users to integrate bots into their meetings for various tasks, such as note-taking. While this has a tangible productivity benefit for users, Microsoft has highlighted how misconfiguration has allowed bots to join meetings that they shouldn't. This has created security and privacy risks, which Microsoft is now combating using a new Teams admin policy that allows organizers to control how external bots access meetings. Admins can leverage a policy called Manage external bots and their access to meetings. The default configuration is "When detected, require approval before joining", which places detected bots in a lobby before they are explicitly admitted into the meeting. The other option disables the experience. Microsoft has also requested admins to only allow organizers and co-organizers to manage access to a meeting, so that other people don't randomly allow bots into meetings. Teams will now be able to leverage infrastructure signals to intelligently detect and distinguish between bots and humans. Microsoft will soon also trial a registration experience for independent software vendors (ISVs) to build a system that registers a bot with Microsoft, so it is marked as a "known" bot. Teams will also categorize bots as trusted and suspected threats so that organizers can quickly identify which bots they want to allow into a meeting. Additional safeguards to block accidental admission of a bot into a meeting include: No one-click Admit option for identified bots Confirmation prompts when admitting participants that include bots Warnings when organizers choose Admit all, and bots are included Microsoft has begun rolling out this experience, and it will be retiring the current CAPTCHA verification implementation. In the future, the company plans to roll out new capabilities like allow-lists, organization-wide policies, admin reports, audit logs, and more granular controls.
    • With the current hardware prices Microsoft should lift the restriction. Then if you have the correct TPM then allow you to use X feature, if you don't have the correct TPM then don't but still actually let you run windows. 11. With a disclaimer during install that X features would be unavailable.
    • It's good for recycling of course. But commence inflation of a second hand RAM bubble and price gouging on DDR 4 inventory in 3... 2... 1...
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      538
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!