back
69 comments
My previous comment didn't get so much attention, perhaps this will...

https://hulbee.com/?query=perl%20-e%20'print%20%22%3CIMG%20S...

Edit: I had an example of displaying the IP address back to the user from my server, but it went over capacity in a few short minutes, so I took it down and removed the link. I am sure everyone gets the point, specially with a lot of the other examples provided by other HN users below.

Here is a screen shot for future reference: http://imgur.com/PkAGhqn

nice find, however the perl command is unnecessary.

    <IMG SRC=http://kt-media.knowtechie.netdna-cdn.com/wp-content/uploads/2014/12/hacker1.jpg>
works as well. the server isn't executing perl, it's just not escaping client input allowing you to add html tags to the result page.

edit: i should say - it's absurd that anyone can launch a website with this kind of vulnerability in 2015. every html rendering framework i've ever used/read about automatically sanitizes user input when generating the html. the only accidental way i can imagine someone doing this is building html from string concatenations...

edit2: for a simple challenge, try to embed other tags. like A or SCRIPT

They "fixed" it. Well, there's still another.

https://hulbee.com/?query=%3C%2Fscript%3E%3Cimg%20src%3Dsdf%...

It runs on Chrome and bypasses the filter.

Edit: for context, the parent found an XSS issue. It was patched within a few hours. The patch was incomplete, and this one still worked. So, not only do they get it wrong for launch. When presented with an exploit they don't even patch the full vulnerability. I'll trust my data with someone who understands security, thank you very much.

Red herring. Serious bugs have been found in lots of respect worthy software and service efforts. It just needs to be fixed. You are holding a toddler up to the standards of a pre-teen (which is the highest I'd put Google).

The question here is whether this is a respect worthy effort at privacy protection.

EDIT: Flaws or holes have been found in Tor. Does that mean we reject the Tor effort outright? If anything, the holes found in Tor are more serious and fundamental, because they raise doubts about Tor's approach and whether their goal can ever be achieved. An HTML injection hole in Hulbee is simply an issue of incomplete execution of their vision, which may or may not be forgivable depending on the technical and non-technical circumstances (which none of us here know yet).

I admire their efforts, but serious efforts need to start with the fundamentals.
I would argue the Tor example is not a valid comparison. Tor is a very complex system. It has a vast attack surface for holes, especially if you ignore boundaries like assuming there is a globally omniscient adversary.

Contrastingly, websites sanitizing inputs has been done for quite some time; it is hardly new, difficult, or complex. It's fundamental. I would guess most people's answer is that this is not a sufficient effort to protect privacy or security.

whether this is a respect worthy effort at privacy protection

If they've launched with an HTML injection vulnerability, their security infrastructure is not sufficient to protect your privacy. Game over.

XSS injection is possible too:

https://hulbee.com/?query=%3CIMG%20SRC%3D..%2FImages%2Flogo-...

<IMG SRC=../Images/logo-hulbee.png onload=alert('hello')>

So much for your privacy I guess. That most likely isn't the only thing wrong with their infrastructure if they missed that.
This is not a bug, you are just uninformed: a platform that allows anybody to use anybodys machine for anything is the final business model in web 2.0. Everybody in the startup world is getting crazy about this.

BTW google is doing it, Mickysoft and Apple is doing it - only difference is that they try to maintain exclusive customer access to these features, but it does not work out always.

hulbee entering the scene as an unrestricted distributed code execution platform freely available for anybody will change everything!

Is is not a bug, it is a feature (image search, that does not work too well).

When you place an IMG tag, it tries to find some results by that image (similar to Google's seach by image->URL). Try using an invalid reference or IFRAME SRC.

Edit: I stand corrected. They do embed poorly-filtered request text into the results page.

This is false.

There's no reason I should be able to embed the following onto someone else's page:

    https://hulbee.com/?query=%3Ca%20href%3D%22%23%22%20obfuscate%3D%22238942932djwdj928%22%20onClick%3D%22alert('pwnd')%3B%22%3Eclick%20here%20for%20results%3C%2Fa%3E&region=browser&uiLanguage=browser
You lost my interest when I saw an ad manager in your HTML source: adannonce.com. I'll stick with DuckDuckGo thanks. You can't be privacy focused when you're already giving away data to a 3rd party.

I see a "Clear my activity" link, why would it keep my activity at all? https://hulbee.com/Utils/ClearSettings?returnUrl=%2F%3Fquery...

Surly you could have afforded a better certificate than a C+ graded GoDaddy one? Sure, its 2048 bit SSL, but that is quite the SSL chain for being privacy focused.

https://www.ssllabs.com/ssltest/analyze.html?d=hulbee.com -vs- https://www.ssllabs.com/ssltest/analyze.html?d=duckduckgo.co...

Offering advertising on a privacy focused search engine? Could work, but when you're marketing to privacy focused individuals, you've just lost them.

In the end, I'm from Canada, my connection routes through New York (like most North American connections). My privacy is still being abused by greater forces whom likely have at least one of the private keys for one of the many certificates that make up that GoDaddy certificate, so I'll likely just stick with Google, or perhaps even DuckDuckGo.

> You lost my interest when I saw an ad manager in your HTML source: adannonce.com

Are you aware that adannonce.com belongs to Hulbee? Loading ads from adannonce.com should not bother you more than loading ads from hulbee.com . And the fact that it contains ads is no secret.

Please do your research before crying wolf in future.

Thanks for the info, care to dive into my other concerns?
> Surly you could have afforded a better certificate than a C+ graded GoDaddy one

It really doesn't matter what the CA cert is (I mean the CA infrastructure itself is kind of weak coughdiginotarcough) - what should matter more is configuring the server and the key size of the certificate.

I should note it's not hard to get an A+ on the test - I run a small source code hosting service and I have an A+ result from ssllabs.

gitlab has an A-/A and github has an A/A+ (yes - they are 2 different scores based on different servers.

Is this an A/B test?

See for yourself: https://hulbee.com/imprint | https://swisscows.ch/imprint

These sites `appear` to be exactly the same, I wonder what the difference is other than the design, branding and domain.

I've been using https://swisscows.ch for almost 6 months now. and was sharing it with my friends and family. Even made it the default on a lot of devices from friends and family. No negative feedback so far! I also shared it with you: https://news.ycombinator.com/item?id=9628904

So far there are only one two things that make me go back to google.com in rare occassions. On google "<search-term>" strictly gives me results with that term, that's appears not working similarly on hulbee/swisscows. If only I could sort search results by date and `strip results older than x` I would have no more reason to "google". What I really like about swisscows is the image and music search.

One questions bugs me: How does it work? I mean the results have the same and sometimes even higher quality than google. BIG +: No self-/government-/geo-censored results like on google/bing, I can find so called "illegal URLs" (links that don't appear on the big sites like DMCAed links and results for certain stopwords)

#bug: There is a bug on Firefox on Android in the image search. Clicking results opens a modal window with the resulting image below the viewable region. Screenshot: http://i.imgur.com/KClGfUO.png

> Safe. Smart. Innovative.

The minute any business describes itself as "innovative", I assume they write everything in PL/SQL.

Pretty much.

I've once done an informal "research", comparing some of the worst software sweatshops that I know against companies such as SpaceX. The metric used was the number of references to "innovation" and "innovative".

The results were very interesting. Highly recommended.

I don't get it. Because truly innovative companies don't write SQL? Is this some kind of ORM or NoSQL snobbery?
No. It's just that the word "innovative" spoken by a company is the dead canary that tells you the company is so full of bullshit that the methane vapours are creating a fire hazard.
No, it's like TeMPOraL said. I could've said ABAP4, but (thankfully) not a lot of people are aware of it.
I've always thought that when a company tells you that their product has some quality like safety or quality, instead of showing it to you with their product, it's likely that that's the extent of that quality in their product: the declaration.
Judging by the top comment I think they lost on the 'safe' bit, probably on the 'smart' bit too. They may still win on 'innovative'.
A -meta- search engine.

"In partnership with Bing" "Powered by Yandex" etc etc

Looks like it gives almost the same results as DuckDuckGo -- which is to be expected given DDG also uses Bing and Yandex. I like it a lot less, though, with the animations and ad on the side of the screen.
Do you have a link for 'bing'? I found the yandex in the translations only (yet)
how tall is mt everest?

https://hulbee.com/?query=how%20tall%20is%20mt%20everest%3F&...

vs.

https://encrypted.google.com/search?hl=en&q=how%20tall%20is%...

Hulbee can correlate the words "mt everest" to "Nepal," but it can't give me the actual answer. That's weak for a engine that claims to be "the first intelligent answer engine because it is based on semantic information recognition and offers users intuitive help in their search for answers."

I wonder if it would be possible for a nonprofit organization to fund such a "hybrid search engine" with wikipedia scale donations.

If so that would be better than trusting all of these small companies to not sell you out a week before IPO.

Of course it is possible. But the forces that work against it are incredibly powerful.

Consider this: If before Wikipedia existed someone proposed to create an online encyclopedia that anyone in the world could anonymously edit, that it be funded by donations and that it become the encyclopedia that most people refer to, nearly 100% of us would have rolled on the floor and laughed out loud.

It might not even be possible if Google, Bing, Yandex had TOS that required the use of their ads networks (negating the point of it being funded by donations).
I'd love DDG to be that organization, although not sure if it's already too late as they are for-profit and got series A funding around 2011
also try https://hulbee.ch/ (they are a swiss company, after all) for entertainment.

  hulbee.ch uses an invalid security certificate. The 
  certificate is only valid for the following names: 
  *.hulbee.com, hulbee.com
I'm too bad of a typist to use this. Intending to search for xcworkspace I typed wcworkspace. Google gracefully corrects me. Hulbee stares at the blank wall of no results. I want to like it, but if you want to replace my entrenched tools you've got to start by matching their basic functionality.
Is there a search engine which returns only https results? Meaning all of the results are https sites.
I dont know that but you can force HTTPS Everywhere to only allow HTTPS connections.
HTTPS Everywhere only forces HTTPS when it's possible.

Force-TLS and HTTP Nowhere does what you describe.

It's 2015, and this is a search engine. Why is there no autocomplete? You guys should check out https://www.constructor.io
This looks advertisement supported?

It appears that a visual advertisement for Coke appears in the left frame, no matter what the search term is.

Franky, I'm a fan of how those advertisements are tied into the site. Not flashy or obstructive, classy, embedded into the tile grid. No garbage tracking scripts loading, no plugins, just a simple colour image (from the same domain!!). If all ads were like that, I'd throw away my uMatrix and Adblock.
Advertisement-supported and privacy focused need not be mutually exclusive.
Eh... if I compare this http://puu.sh/jqh03/af70af5769.jpg and this http://puu.sh/jqh3V/56749ce4cc.png , I think I'll stay with DDG.
You make it seem as if the reason for your DDG preference is self evident. What is the big difference to you? Is it that the first result's info box is so far to the right?
Alerta alerta, it's censoring more than Google, try searching for a pussy!
sighs, looks at old Powerset swag from 2008, sighs again
The animation with the mosaic is just terrible - a visual distraction and slowness no search engine needs.