Privacy

DDG has a tracker blocking carve-out linked to Microsoft contract

Comment

Pole lifting rubber duck with hook in its head
Image Credits: Andy Roberts (opens in a new window) / Getty Images

DuckDuckGo, the self-styled “internet privacy company” — which, for years, has built a brand around a claim of non-tracking web search and, more recently, launched its own ‘private’ browser with built-in tracker blocking — has found itself in hot water after a researcher found hidden limits on its tracking protection that create a carve-out for certain advertising data requests by its search syndication partner, Microsoft.

Late yesterday, the researcher in question, Zach Edwards, tweeted the findings of his audit — saying he had found DDG’s mobile browsers do not block advertising requests made by Microsoft scripts on non-Microsoft web properties. (NB: This is a separate matter to what happens if you actually click on an ad when using DDG — as its privacy policy clearly discloses all privacy bets are off at that point.)

Edwards tested browser data flows on a Facebook-owned site, Workplace.com, and found that while DDG informed users it had blocked Google and Facebook trackers, it did not prevent Microsoft from receiving data flows linked to their browsing on the non-Microsoft website.

Edwards had some Twitter back and forth with DDG’s founder and CEO Gabe Weinberg, who initially appeared to be attempting to play down the finding by emphasizing all the stuff he said DDG’s browser does block (e.g., third-party tracking cookies, including those from Microsoft).

Weinberg was also especially keen to make it clear the data flows issue is not related to DuckDuckGo search.

However the limitation on DDG’s browser’s tracker blocking does amount to an exemption from protection against certain advertising data transfers to Microsoft subsidiaries (Bing, LinkedIn) — which could be used for cross-site tracking of web users for ad targeting purposes. Or, in other words, to undermine DDG browser users’ privacy.

In Twitter back and forth, Weinberg confirmed Edwards’ audit was correct — “fessing up to a contactual agreement that he said limited DDG’s ability to block trackers in this scenario by writing that DDG’s ‘search syndication agreement’ with Microsoft, which owns and operates the Bing search engine and index, prevents us from stopping Microsoft-owned scripts from loading.”

He added that DDG was “working to change that.”

https://twitter.com/yegg/status/1529054493605756934

Asked via Twitter whether DDG’s contract included a clause that prevents it from publicly complaining about the limitations imposed upon it by Microsoft, a tech giant with a growing adtech business, Weinberg told us: “Our syndication contract has broad confidentiality requirements, and the specific requirement documents themselves are additionally explicitly marked confidential.”

Discussing his findings and DDG’s response with TechCrunch, Edwards described himself as “pretty shocked” by Weinberg’s public response to his audit — and for having what he summed up as “no public solutions for the problems created through the secret partnership between DuckDuckgo and Microsoft.”

“I have significant concerns … about DDG’s public claims, especially the ones they make on their iOS/Android app install websites, promising tracking protections,” Edwards added. “If you compare the language within the app details, to the information shared by the DuckDuckGo CEO yesterday, you can’t help but wonder why they are so openly lying in one location of the internet, and not lying in another area of the internet, and seemingly attempting to throw their top advertising partner Microsoft under some sort of bus — essentially DDG’s CEO made numerous comments about how he was trying and hoping to get out of their current contract with Microsoft — this was a shocking admission to see publicly and something that I hope regulators take a serious look at.”

The issue has blown up on Hacker News over the day — where Weinberg (aka yegg) has been doing more firefighting in the comments, reiterating that DDG’s hands are tied by its contract with Microsoft and further claiming it has continued to press for changes to “this limited restriction.”

“This is just about non-DuckDuckGo and non-Microsoft sites in our browsers, where our search syndication agreement currently prevents us from stopping Microsoft-owned scripts from loading, though we can still apply our browser’s protections post-load (like 3rd party cookie blocking and others mentioned above, and do). We’ve also been tirelessly working behind the scenes to change this limited restriction,” Weinberg wrote on the site.

“I also understand this is confusing because it is a search syndication contract that is preventing us from doing a non-search thing. That’s because our product is a bundle of multiple privacy protections, and this is a distribution requirement imposed on us as part of the search syndication agreement. Our syndication agreement also has broad confidentially provisions and the requirement documents themselves are explicitly marked confidential,” he added.

While DDG’s browser clearly does not block all scripts — and no tracker blocker is going to be 100% effective as tracking techniques are ever evolving — this carve-out for Microsoft scripts looks different on merit of it being a specific exemption attached to a contractual agreement that’s linked to a commercial deal which allows DDG to use Microsoft’s search index in its core product — none of which was (seemingly) public knowledge prior to Edwards’ audit.

In further public remarks on the issue, Weinberg implied that DDG is trying to balance a goal of giving browser users a very easy tracker blocker experience (i.e., to maximize accessibility), with beefing up protections that might further enhance user privacy but with a potential cost to the experience (e.g., broken webpages).

However the lack of a disclosure by DDG to browser users of the Microsoft-related restriction to its protections is particularly concerning — especially in light of the stark contrast with its privacy-focused marketing which tells users they will “escape website tracking” (which clearly isn’t happening in the specific Microsoft-related instances identified by Edwards). So DDG risks misleading users and undermining its own reputation as a pro-privacy business.

In a more recent response posted in response to Hacker News comments, Weinberg appears to have accepted the need for DDG to make fuller disclosure, writing: “We will work diligently today to find a way to say something in our app store descriptions in terms of a better disclosure — will likely have something up by the end of the day.”

“I understand the concern here that we are working to address in a variety of ways but to be clear no app will provide 100% protection for a variety of reasons, and the scripts in question here do currently have significant protection on them in our browser,” he added. 

We reached out to Weinberg with questions. He sent us this statement:

We have always been extremely careful to never promise anonymity when browsing, because that frankly isn’t possible given how quickly trackers change how they work to evade protections and the tools we currently offer. When most other browsers on the market talk about tracking protection they are usually referring to 3rd-party cookie protection and fingerprinting protection, and our browsers for iOS, Android, and our new Mac beta, impose these restrictions on third-party tracking scripts, including those from Microsoft. We’re talking here about an above-and-beyond protection that most browsers don’t even attempt to do — that is, blocking third-party tracking scripts before they even load on 3rd party websites. Because this can cause websites to break, we cannot do this as much as we want to in any case. Our goal, however, has always been to provide the most privacy we can in one download, by default without any complicated settings, so we took this on.

We also put questions to Microsoft about the limitation it imposes on search syndication partners but at the time of writing the tech giant had not responded.

Privacy trade-offs are never great but one conclusion looks inescapable here: Antitrust regulators need to closely examine the search syndication market — given it’s essentially comprised of two gatekeeping adtech giants, Google and Microsoft, which are fully empowered to enforce (unfair) terms on anyone else wanting to offer a competitive search product, or, indeed in certain cases, an alternative web browser.

European regulators have recently agreed a new ex ante competition regime that’s aimed at the most powerful intermediating platforms — which the Digital Markets Act refers to as internet “gatekeepers.” The DMA is clearly applicable to search engines but it remains to be seen whether the Commission will spot the opportunity to use the incoming regulation to crack open the search market by enforcing fair usage terms around search syndication on the only two indexes that count.

How Europe has expanded its bid to disrupt Big Tech

More TechCrunch

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

4 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?