https://www.bleepingcomputer.com/news/security/duckduckgo-now-blocks-google-sign-in-pop-ups-on-all-sites/ BleepingComputer.com logo * * * [ ] [Login] [Sign up] * * * [ ] [Login] [Sign up] * News + Featured + Latest + Comcast Xfinity accounts hacked in widespread 2FA bypass attacks Comcast Xfinity accounts hacked in widespread 2FA bypass attacks + Corsair keyboard bug makes it type on its own, no malware involved Corsair keyboard bug makes it type on its own, no malware involved + Lastpass: Hackers stole customer vault data in cloud storage breach Lastpass: Hackers stole customer vault data in cloud storage breach + Okta's source code stolen after GitHub repositories hacked Okta's source code stolen after GitHub repositories hacked + This CompTIA, Microsoft, and AWS exam prep bundle is on sale for $45 This CompTIA, Microsoft, and AWS exam prep bundle is on sale for $45 + New info-stealer malware infects software pirates via fake cracks sites New info-stealer malware infects software pirates via fake cracks sites + Put a firewall in your pocket with this Deeper Connect Pico deal Put a firewall in your pocket with this Deeper Connect Pico deal + The Week in Ransomware - December 23rd 2022 - Targeting Microsoft Exchange The Week in Ransomware - December 23rd 2022 - Targeting Microsoft Exchange * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * DuckDuckGo now blocks Google sign-in pop-ups on all sites * * DuckDuckGo now blocks Google sign-in pop-ups on all sites By Bill Toulas * December 22, 2022 * 03:21 PM * 7 Blocked DuckDuckGo apps and extensions are now blocking Google Sign-in pop-ups on all its apps and browser extensions, removing what it perceives as an annoyance and a privacy risk for its users. DuckDuckGo offers a privacy-focused search engine, an email service, mobile apps, and data-protecting browser extensions. A standalone web browser is also in the works, currently in beta and only available for macOS. The company announced today that all its Chrome, Firefox, Brave, and Microsoft Edge apps and browser extensions will now actively block Google sign-in prompts displayed on sites. Google offers this single sign-on option on websites to enable users to quickly sign in to new platforms using their Google account for convenience and unified control. Simply put, instead of having to create new accounts and manage multiple passwords on various sites, users can just sign in with Google when the option is available and skip the hassle. The downside of this practice for users is that the websites and apps users sign into can be tracked by Google. While Google states explicitly, "Data from Sign In With Google is not used for ads or other non-security purposes," DuckDuckGo says their tests show that Google still collects data. "See our testing in the attached image which shows Google is collecting data on sites when signed in with Google. For example, on investing.com, many requests are made to https:// securepubads.g.doubleclick.net/gampad/ads?.," DuckDuckGo told BleepingComputer. "This includes the full page url in the request parameters. In testing, if we're not signed into the website with Google, the DSID cookie sent with these requests has a value of NO_DATA. If we are signed into the website with Google, the DSID cookie sent with these requests has a long hexadecimal value." "You can see this in the attached image - on the left we're signed in with Google, on the right we're not signed in with Google." Cookie siphoning user data (left) and blocked (right)Cookie siphoning user data (left) and blocked (right) (DuckDuckGo) As DuckDuckGo believes these are privacy risks, it has resorted to taking the rather aggressive approach of blocking Google sign-in prompts, never giving users the option to take up the tech giant's offer. BleepingComputer has found that the option is baked into the general protection feature of the browser extension, so when the extension is active, all Google prompts are blocked automatically. The same applies to the DuckDuckGo browser for macOS, where the Google blocking feature is built into "Protection," and there's no option to disable it unless you disable all privacy protections. DuckDuckGo browser on macOS, protection set to on (left) and off (right)DuckDuckGo browser on macOS, protection set to on (left) and off (right) (BleepingComputer) DuckDuckGo's new feature will not cause any issues to those who use Google to sign-in on websites as that method is still available on the affiliated platforms' login pages. However, the annoying pop-up window will not show up. Related Articles: DuckDuckGo now lets all Android users block trackers in their apps Google to roll out Privacy Sandbox on Android 13 starting early 2023 Google will pay $391M to settle Android location tracking lawsuit Massive Twitter data leak investigated by EU privacy watchdog Brave launches FrodoPIR, a privacy-focused database query system * DuckDuckGo * Google * Google Sign-in * Privacy * * * * * Bill Toulas Bill Toulas is a technology writer and infosec news reporter with over a decade of experience working on various online publications. An open source advocate and Linux enthusiast, is currently finding pleasure in following hacks, malware campaigns, and data breach incidents, as well as by exploring the intricate ways through which tech is swiftly transforming our lives. * Previous Article * Next Article Comments * Wim-Katje Photo Wim-Katje - 2 days ago + + And this now makes DuckDuckGo completely useless for me. As a software developer, I depend a lot on Google and many of it's services. My own company even has a Workspace account and I use various Google API's in the projects I develop. I depend heavily on this functionality. So if DuckDuckGo blocks it then I just block DuckDuckGo... Thing is, if people want to have privacy then they should stop sharing private information online. And become more aware of all the trackers that exist. And don't trust DDG that much either, as it has been proven before that even DDG is using trackers themselves, collecting data and who knows what they do with it? They can't disclose that, as that would be bad marketing. ("We promise that no one else will share your private data" is not a good marketing slogan...) While Google is collecting private information, they are also open about it. That's a big difference... * ThomasMann Photo ThomasMann - 2 days ago + + I understand your problem. For a software developer this is not good. But on the other hand.... It was and is people like yourself that have allowed to get corporations like Google, M$ and the like, to amass all that data = power, that they are now using against their customers. All you people are interested in, is your income... Software developers are the major problem when it comes to the horrifying state of powerabuse against users, which means everybody! The surveillance ability of states all governments all over the world would not be possible without your ignorance. And what will be the endresult of this development is still unpredictable, but it will be a desaster... I understand your problem, but duckduckgo understands the REAL problem! The excuses you make are a joke, are simply in it for the money! * Wim-Katje Photo Wim-Katje - 1 day ago + + Well, unfortunately DuckDuckGo used trackers from Microsoft to track user data. Read a previous article at https:// www.bleepingcomputer.com/news/security/ duckduckgo-browser-allows-microsoft-trackers-due-to-search-agreement / to learn more. They claim to be privacy-focused but they're not honest about that. Now you might like DDG because they claim to respect your privacy, but they lied about that! Thing is, people have started to use computers for entertainment and sharing their privacy everywhere. Social media are Gold for companies, as it provides so much information for them. And for DDG, their goal doesn't seem to be concern about privacy, but a concern that others can collect this information. By trying to control the browser market and search engines, DDG is basically able to collect all this data themselves and use this data without disclosing this to the end users. Keep in mind that DDG might even have violated the GDPR laws in Europe. Claiming they don't track anyone yet secretly allowing Microsoft to use trackers? That seems a serious accusation to me. And yes, that too is all about money! Thing is, I'm not ignorant. I'm just not sharing any personal details that I want to keep private. And if more people would just stop sharing private information online then that would solve about 80% of the whole problem. Instead, people just continue what they have always done and fall for the marketing trick of DDG. Because even DDG uses data to gain more power. Don't forget, DDG makes most of it's money from online advertising and to do a better job at that, they will need to collect data from their users, to provide better ads. Thing is, I don't trust Google but they are at least honest about collecting data. They also provide insights in what they know about me. DDG lied to me about not tracking me, and they probably know things about me that they are unwilling to disclose. So I don't trust DDG either. But they also lied to me, and to the public in general, which is why DDG is just as Evil as Google and the rest... * ThomasMann Photo ThomasMann - 1 day ago + + Thank you, that sounds a bit different than the first comment. I myself hve no illusions about DDG, digital security is nothing but wishful thinking. I completly agree with your "I'm just not sharing any personal details that I want to keep private. And if more people would just stop sharing private information online then that would solve about 80% of the whole problem." The advantage that DDG (and "Startpage") has, unless you have different info there too, is that they do not manipulate ranking of search results... * Wim-Katje Photo Wim-Katje - 1 day ago + + "Thank you, that sounds a bit different than the first comment. I myself hve no illusions about DDG, digital security is nothing but wishful thinking. I completly agree with your "I'm just not sharing any personal details that I want to keep private. And if more people would just stop sharing private information online then that would solve about 80% of the whole problem." The advantage that DDG (and "Startpage") has, unless you have different info there too, is that they do not manipulate ranking of search results..." You're welcome. And yes, to me it's a matter of trust. As a developer, I work on projects that handle millions of euros in financial transactions and needs to be very aware of privacy. One of the conditions I have to deal with is that I cannot use any Cloud services or remote APIs. As a developer in Europe, I also have to be very aware of the GDPR and need to be clear and transparent about we deal with the privacy of users. So I know the amount of data that we can collect with our services and sites in minute details. I know the personal details that you can find in the HTTP headers of each request. SSL should encrypt them all, though. But the URL and IP address can still be collected. And a man-in-the-middle approach can defeat the purpose of SSL if the client does not check the SSL certificates. This makes DDG challenging as they operate as a middle-man with their privacy tools. So, DDG desires a lot of trust from us, users. All out private data will go through their servers for anything we do through their apps. And DDG blocks all this data to anyone else who is interested in it. This basically provides DDG a monopoly on this data... Now, when DDG gets caught supporting trackers, I know something fishy is happening. This should be a warning signal for many, showing that even DDG might not be trusted with our data. Because as a developer, I know all sites can and will collect private data for various purposes, but most are open about it. DDG lied... And that means they're not worth my trust. Keep in mind that this is more than just a search engine, as they have their own browser app and extension. * ThomasMann Photo ThomasMann - 2 hours ago + + Thank you, for your answer. Interesting, as I live in a different world. A world in which the idea of security while using the internet is a silly idea. People like myself want to know when all attempts security will be completely useless, maybe with computers in the "wrong" hands... Security breaches seem to me to be at best, a question of time. I watched a "documentary" last night about the beginning of germany's Chaos Computer Club in the 80s, which shows that government secret services from the very beginning of the net, where after those people who threatend to establish a communication platform, that will NOT be under government control. People even were murdered by CIA &Co. Those efforts have of course increased and will NEVER stop. When it comes to browsers, have you heard of one that is usable and will not be able to be broken, if someone finds it necessary in the future? I took a careful look, which of my correspondence through the net I want NOT to be accessable for others. I use a VPN and Tor for that. For the rest I still use Ff.... which lied a lot more than DGG, but at least it makes life very much easier for things that do not matter. Very understandably you write "DDG lied... And that means they're not worth my trust." Agreed, but do you have any idea at many things you simply just have not yet looked thoroughly enough to see, that they also lied? * Wim-Katje Photo Wim-Katje - 2 hours ago + + "Thank you, for your answer. Interesting, as I live in a different world. A world in which the idea of security while using the internet is a silly idea. People like myself want to know when all attempts security will be completely useless, maybe with computers in the "wrong" hands... Security breaches seem to me to be at best, a question of time. I watched a "documentary" last night about the beginning of germany's Chaos Computer Club in the 80s, which shows that government secret services from the very beginning of the net, where after those people who threatend to establish a communication platform, that will NOT be under government control. People even were murdered by CIA &Co. Those efforts have of course increased and will NEVER stop. When it comes to browsers, have you heard of one that is usable and will not be able to be broken, if someone finds it necessary in the future? I took a careful look, which of my correspondence through the net I want NOT to be accessable for others. I use a VPN and Tor for that. For the rest I still use Ff.... which lied a lot more than DGG, but at least it makes life very much easier for things that do not matter. Very understandably you write "DDG lied... And that means they're not worth my trust." Agreed, but do you have any idea at many things you simply just have not yet looked thoroughly enough to see, that they also lied?" I'm old as I was born in 1966 and my father was a Software Engineer. I came in contact with computers in the early days, since I was 8, and was already programming when I was 12. I've seen the early days of the CCC and I know a bit about the history of computers and their origin, from the early looms with punched cards to the German dominion of computer technologies before they decided WWII was a good idea. After Germany lost WWII, the Allied forces basically plundered the German computer technologies to use them for themselves. Because Germany was far ahead on everyone else. After all, the first higher programming language, Plankalkul, was originally created by a German developer and used on German mainframes. As for the Internet... Well, this actually started as a military project (DARPA) and to get more people working on it, the technology was also shared with many universities in the USA to get more developers working on it. At one point, it also became a major part of NASA and then more and more companies and industries started to join the project until it developed into the World Wide Web as we know it since the 1990's. But it's primary use has always had a military aspect, and later State Control. Well, mostly the USA. As for security... Well, it doesn't matter which browser you use. Your security is in danger as soon as you start sending signals to your provider. If you want a bit more security then you should install this in your router or get a local VPN server that will block certain domains and IP addresses. But this should be in your home and you need to get it from some source that you absolutely trust. DuckDuckGo would have been an option, if they had not lied to the public. But as I said, one small lie about such a sensitive topic is enough to distrust them forever. But more importantly, if you want your communications to be secure then you would need a peer-to-peer connection with others and use an encryption method with asynchronous keys. You would send the public key to your friend and your friend sends his public key to you. You then use his public key to send messages to him while he uses your public keys to send messages to you. Because these messages can only be read by someone with a private key, you know that only one person can actually read these messages. You just have to make sure that you have the real public key from your friend as a man-in-the-middle attack works quite well if you don't. Suck communication tool is not difficult to make but the challenge is just validating these keys. With the Web and SSL certificates, this is done through a layer of trustees who digitally sign the key. If the key is valid then the key should be from the proper source mentioned in it. And with SSL, certificates are validated with the domain name through various means, where the person who owns the domain has to prove he's the owner to the trustee. A complex process, yet generally reliable. If you check if the certificate is from the trustee... But the problem is that if you really want something secure, then you might have to write something yourself. It's not too difficult to write peer-to-peer encrypted communications but the question is always whom to trust. And my philosophy is simple: trust no one! But always evaluate the risks you might have and consider if it's worth taking these risks... For me posting here, for example, is also such a risk evaluation. I'm sharing my opinion here, knowing that it can be used against me. I use my name, knowing people might start to look more information about me. I have a profile picture that shows what I look like. And I think this is enough information for others to find my Facebook account, Twitter, Google and my personal website. Probably my LinkedIn account too. Maybe even my Fiverr account and other data. So, how easy would it be for people to find all of this? Well, not too easy, but possible... But then my thoughts are about large schools of fish. You have these schools with thousands of fish swimming close together and a hungry predator swimming in the area. But a fish in such a large group is not easy to notice as an individual so a predator going after one is likely to get one of the thousands of others. If you would swim alone, you would be their sole target and you'd need to hide. But in the school, you can swim in the open, knowing others might alert you of any dangers. The Internet is like this school of fish. There's dangers out there, but the chance of getting picked as target is slim. You need to attract the would-be attacker in some way. So, would anyone be really interested in you and what you do? Well, maybe if you're a celebrity or important politician. Or if you're high up in some military command or are in control over a large organization. But the average person living a normal life with his wife, two kids, a dog and a house with a tree in the garden? Boring. :) Well, unless you're selling meth and have a secret meth lab in your cellar where you make that stuff Walter White made in "Breaking Bad" with it's blue color. Then you'd be a target for the FBI and the Drug cartels... :) Anyways, TL;DR... What I'm saying is that you need to understand security in details to know how to be secure. So if you feel you need better security then you have to learn, not trust any marketing campaigns from companies like DuckDuckGo. Those companies are trying to sell products to you, and are likely to collect any data about you... Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * Twitter Massive Twitter data leak investigated by EU privacy watchdog * WordPress Hackers exploit bug in WordPress gift card plugin with 50K installs Latest Downloads * Malwarebytes Anti-Malware Logo Malwarebytes Anti-Malware Version: 4.5.19 4M+ Downloads * Windows Repair (All In One) Logo Windows Repair (All In One) Version: 4.13.1 2M+ Downloads * Everything Desktop Search Logo Everything Desktop Search Version: 1.4.1.1017 21,867 Downloads * Zemana AntiLogger Free Logo Zemana AntiLogger Free Version: 1.8.2.320 52,215 Downloads * Zemana AntiMalware Logo Zemana AntiMalware Version: NA 304,154 Downloads Follow us: * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2022 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT