Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
erikpukinskis
on May 20, 2010
|
parent
|
context
|
favorite
| on:
DuckDuckGo Searches Are Not Anonymous
What if you use the IP address of the user as a seed for the encryption? Then if someone else used the same key from a different IP they'd get different search terms?
epi0Bauqu
on May 20, 2010
[–]
That embeds the IP in the process and could theoretically be reverse-engineered.
apgwoz
on May 20, 2010
|
parent
[–]
Are there session ids? I assume that HMAC(secret + sessionID + ip + search terms) would be fine.
epi0Bauqu
on May 20, 2010
|
root
|
parent
[–]
No sessions.
apgwoz
on May 21, 2010
|
root
|
parent
[–]
I see you do settings through a cookie or URL params. I'm out of ideas unless you hash the cookie + ip for a session ID fir that purpose.
Consider applying for YC's Spring batch! Applications are open till Feb 11.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: