DuckDuckGo: The Good, the Bad, and the Missing Audit

After reading old news, audit reports, and community discussions, here's a more complete picture of DuckDuckGo than the usual headlines.

8 min read

So I already did one pass on this before, the basic stuff, Bing dependence, the 2022 Microsoft tracker thing, the API situation. This time I went back and actually read through old news, audit reports, and old Reddit threads instead of just the summary, and there is more here than I thought, some of it worse, some of it actually not fair to DDG at all.

The Founder: No Hidden Skeletons

Let’s start with the founder, because normally this is where things get weird, and this one really does not. Gabriel Weinberg sold a social network called The Names Database for about 10 million dollars back in 2006, before DuckDuckGo even existed. He started DDG basically as a side project in his basement in 2008 because he was annoyed with his own Google results, not because he had some big privacy mission from day one. He said in interviews that privacy became the focus only after early users on Hacker News and Reddit kept asking about it. No fraud, no lawsuit, no hidden scandal that I could find. People online like to hint there’s something bad in his past, and I just couldn’t find it. The real controversies are all about product choices he made while running DDG, not who he was before.

Trackers, Audits, and Corporate Responses

Now the actual messy part. The 2022 Microsoft tracker thing is the one most people already know, a security researcher finds that DDG’s browser blocks Google and Facebook trackers but lets some Microsoft ones through, DDG admits it’s a contract limit tied to the Bing deal, and later fixes it. What I didn’t look at closely last time was how Weinberg first answered this on Twitter, and honestly it’s a bit telling. He didn’t just say, yes that’s a gap, we’re fixing it. First he talked a lot about everything the browser DOES block, other trackers, cookies, all that, before finally landing on the actual fix. Downplay first, fix later. Not a crime, just a very normal corporate response, and it’s part of why people didn’t fully trust it again even after the fix.

Then there’s one I hadn’t looked at before, the 2024 browser audit. In October 2024, independent researchers found a technical problem where some websites using older or weaker web code could still allow a kind of cross tracking through the DDG browser. It got fixed after going public, same pattern as before, but it’s a different event from 2022, a lot of people mix these two stories into one and they are actually two separate things two years apart.

Separately, DDG did pay for a real outside audit of their VPN product, done by a company called Securitum, in October 2024. I’ll give them real credit here, they published the whole result instead of just a summary. Fifteen problems found in total, zero critical, two high risk, four medium, nine low. Six of those got fixed, including all the high and medium ones, and the low risk ones they said they’d just accept since the impact was small. That’s actually a good look for a company that chose to publish results that make them look a bit imperfect, most companies hide this or never pay for the audit at all.

Piracy Misunderstandings and Backlash

The one I think is actually the most interesting, and mostly forgotten now, is the pirate site thing from April 2022. People noticed that searching directly for The Pirate Bay or youtube-dl on DDG using the site: search command wasn’t showing results, and the internet jumped straight to “DDG is secretly blocking piracy sites now, so much for being different from Google.” Weinberg pushed back hard, said it was a bug in how the site: command worked, not an actual removal, and that searching those sites by name directly still worked fine. TechRadar tested it themselves with a clean browser and a VPN and found no problem finding pirate sites through normal search. So this looks like a bug that people read as a conspiracy, which happens a lot with search engines honestly, one weird result and suddenly there’s a whole story built around it.

The Russia disinformation ranking thing from March 2022 is the one that caused the biggest real backlash on ideas, and I think it’s worth separating what actually happened from how people reacted. Weinberg tweeted that DDG would down-rank sites linked to what he called Russian disinformation, after the invasion of Ukraine started. The reaction was fast and pretty harsh, one psychology professor’s reply went semi viral accusing him of turning DDG into, quote, “another tentacle for some Ministry of Truth.” Some corners of the internet, especially around alternative health and anti mainstream media circles, still bring up this exact tweet years later as proof that DDG “sold out.” DDG’s own defense was that spam and malware ranking already existed, and this was just another ranking signal, not removing viewpoints. Whether you believe that is genuinely a personal call, I’m not saying there’s one clean right answer here, but it’s worth knowing this one tweet is still treated like proof in certain privacy skeptic circles years after it happened.

A few other smaller things kept showing up in more recent criticism pieces too, worth a quick mention even without a big story attached: some auto suggest feature reportedly leaked search data without encryption before getting patched, and general worry about how much DDG’s own servers see, since a proxy setup means DDG itself sees everything even when its partners don’t.

The Real Gap: Where Is The Search Engine Audit?

But then I went looking for one more thing, and this turned out to be the actual biggest gap in the whole story. Is there an independent audit of the search engine itself, not the VPN, the real core product. Short answer, not really, and this seems to be a known complaint in privacy circles for years now, I found a Reddit thread from 2020 asking almost this exact question, “I found no audit reports or such, to prove their no logging claims,” and as far as I can tell that’s still true today.

The VPN got that Securitum audit I mentioned, source code, infrastructure, the no log policy, live systems, all checked, full report published. Genuinely good. But the search product, the thing DDG is actually famous for, has nothing like that. No independent audit of the search proxy setup, the Microsoft partnership pipeline, how identifiers actually get removed, backend logging, or a real end to end check on the specific claim that Microsoft can’t build a history from what it gets.

There is some academic research on DDG, just not on this exact thing. Papers on ad tracking found that privacy focused search engines including DDG and Startpage still expose users to some tracking risk when clicking ads, mostly because of how online ad systems work in general, not because DDG lied specifically. Other papers look at result bias, personalization, and location based results, which is about outputs, not backend privacy. None of it actually opens the proxy pipeline and checks it directly.

Compare this to how other privacy tools handle it. Signal publishes its protocol details and gets reviewed by cryptography academics constantly. Tor publishes protocol papers and the design can be checked by outside researchers. VPN companies increasingly treat outside audits as a basic requirement now, DDG’s own VPN included. DDG’s search product, the actual main thing they’re known for, mostly just has documentation and a privacy policy that says trust us, which, for a company whose whole pitch is trust, is a real gap.

To be clear this doesn’t mean the claims are false. It means the strongest proof for “Microsoft can’t build a profile from your searches” right now comes from DDG explaining their own setup, not from someone outside the company actually checking it. Those are two different levels of confidence.

What DuckDuckGo Needs to Answer

So here’s what I’d actually want DDG to answer, and I mean specific things, not a PR paragraph.

Will you get an independent audit of the actual search proxy pipeline, same as you did for the VPN, and if not, why has this specifically been left out for years while the VPN got one.

What exact headers, cookies, or other data survive the proxy on the way to Bing’s backend, in technical detail, not the outcome language currently sitting in the privacy policy.

Does Microsoft keep any short term logs on their end for abuse detection or infrastructure reasons, and if yes, for how long, and is that something that can be checked independently or is it purely based on a contract.

Can the way you strip identifiers be checked or repeated by an outside researcher, the way Signal’s protocol can be, or is the public only ever going to know this through your own documents.

For Duck.ai, when a chat gets sent to a third party model provider like OpenAI or Anthropic, what exact metadata travels with that request, and has this pipeline been checked independently the same way the VPN was, or is it running on the same trust us model the search proxy currently has.

And honestly, given how central the Microsoft relationship is to the whole product, would DDG ever try to reduce that dependence, or is the Bing partnership permanent enough now that “independent search engine” was never really the right way to describe this, more like an independent privacy layer sitting on top of someone else’s infrastructure.

The Bottom Line

Stacking all this together, the real pattern here isn’t “DDG is secretly evil” and it also isn’t “DDG is perfect and everyone’s overreacting.” It’s a mid size company running a genuinely different setup than Google, with real outside audits that sometimes find real problems, sometimes handling those problems badly at first, sitting inside a business built on Microsoft’s infrastructure whether they like saying that clearly or not. The founder has no hidden skeletons. The product has had real documented failures. And a good part of the internet’s specific anger about it, the pirate site thing especially, turned out to be people finding a bug and turning it into a conspiracy, which might honestly be the most human part of this whole story.