惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
T
The Blog of Author Tim Ferriss
Stack Overflow Blog
Stack Overflow Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
Attack and Defense Labs
Attack and Defense Labs
Project Zero
Project Zero
C
Cybersecurity and Infrastructure Security Agency CISA
N
Netflix TechBlog - Medium
P
Privacy International News Feed
爱范儿
爱范儿
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
MongoDB | Blog
MongoDB | Blog
Spread Privacy
Spread Privacy
G
Google Developers Blog
Cyberwarzone
Cyberwarzone
L
LINUX DO - 热门话题
C
Cisco Blogs
T
Tor Project blog
NISL@THU
NISL@THU
I
InfoQ
P
Privacy & Cybersecurity Law Blog
Simon Willison's Weblog
Simon Willison's Weblog
D
DataBreaches.Net
有赞技术团队
有赞技术团队
S
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
月光博客
月光博客
T
The Exploit Database - CXSecurity.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
GRAHAM CLULEY
Cisco Talos Blog
Cisco Talos Blog
Recent Announcements
Recent Announcements
The Cloudflare Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Threatpost
B
Blog
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security
美团技术团队
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Scott Helme
Scott Helme
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
The Register - Security
The Register - Security

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Hister: The Most Privacy-Respecting Search Engine
Adam Tauber · 2026-05-07 · via DEV Community

Privacy and web search are in constant tension. Every time you type a query into a search engine you are handing over something valuable: a window into what you are thinking. Most people accept this trade-off without much thought. This post breaks down the real privacy risks at every layer of the search stack and explains exactly where Hister fits in.

We will take a look at different privacy issues related to online search services, metasearch engines and opening search results. Then examining Hister's solutions to these problems.

Privacy problems with web search

Online search services

Popular search engines like Google, Bing, and their derivatives are advertising businesses. Your search queries are the raw material. They are stored, profiled, cross-referenced with your browsing history, location, and demographics, and used to model your behaviour far beyond any single search session.

The deeper structural issue is unverifiability. Even a search engine advertises it as privacy respecting, it cannot be audited. You cannot confirm whether queries are truly deleted, whether there is no logging, whether their system isn't compromised, whether your IP address is separated from your query log, or whether anonymised data is actually anonymised. You are asked to trust a black box operated by an organisation whose commercial interests are usually directly served by retaining as much data about you as possible.

Self-hosted metasearch engines

Self-hosted metasearch engines like SearXNG (I'm the original author of Searx btw) and similar projects are a meaningful step forward. By routing your queries through your own server, they decouple significant amount of metadata from the query as seen by Google or Bing. That is a real and valuable guarantee.

But the guarantee has a hard ceiling: metasearch engines are permanently dependent on external search providers. Every query still leaves your infrastructure and travels (potentially both) to Google, Bing, or other providers. Those providers see a query, a timestamp, and an IP address (even if it is your server's IP rather than your personal IP). If the upstream provider correlates queries from the same source IP over time, or if your metasearch instance is the only one making requests from that IP, the anonymisation shrinks considerably.

Another important disadvantage is that metasearch engines can provide no protection against data leakage through the search queries. The search terms are always forwarded to the external providers even if the search query contains sensitive data.

Visiting search results

This privacy surface is rarely discussed when talking about search engine privacy, but it is significant.

When you click a search result you visit a website that does not know you arrived from a private search engine. That website may load dozens of third-party trackers, advertising networks, analytics platforms, social widgets each of which observes your visit and can correlate it with your identity across the web. Many of these trackers operate at the network layer and cannot be blocked at the browser level without breaking the page.

Beyond passive tracking, pages can be tempered, can contain malicious scripts, credential-harvesting forms, or drive-by exploits. Before you visit a page you have no way to inspect it. The act of visiting is, in itself, an exposure.

How Hister addresses each layer

A fully local, self-contained index

Hister indexes content you choose to index: pages you visit via the browser extension, URLs you crawl explicitly, or local files on your machine. The index lives entirely on your own hardware. There is no remote server, no third-party cloud storage, no sync service. A query never leaves your infrastructure.

This eliminates the entire trust problem that applies to online services. There is nothing to verify because there is no external party involved. Your query log is a file on your machine that you control completely.

No external search provider calls

Unlike metasearch engines, Hister does not call Google, Bing, or any other search provider at query time. The search runs entirely against the local index. There is no outbound network request triggered by a search query, not even to a self-hosted upstream.

This solves the biggest privacy issue of metasearch engines. Your queries produce zero external network traffic.

Offline previews as a tracker firewall

Hister's most distinctive privacy feature is its offline preview. When a page is indexed, its readable content is stored locally. When you open a result in preview mode, you read the locally stored content.

This means you can read a result, follow an idea, and return to the page days later without the remote server ever knowing you visited. Trackers embedded in the page never execute. Third-party scripts never load. You are completely invisible to the origin and to every analytics or advertising service the site uses.

This is a qualitatively different protection from anything a browser extension or DNS-level blocker can offer, because the page content simply never reaches the network.

Hister's honest limitations

No tool offers unlimited capability, and Hister is no exception.

Index coverage. Hister can only search what it has indexed. A conventional search engine has crawled hundreds of billions of pages; Hister has crawled whatever you have pointed it at. For exploratory searches on topics you have never researched before, the local index may come up empty.

Indexing exposes you. Building the index requires visiting pages. When the browser extension records a page you visit, or when you run hister index against a URL, a network request goes to the origin server. The privacy protections apply after indexing, not during it. If you index a hostile page, that page can observe the visit. Hister mitigates this with support for a Chromedp backend and configurable headers and cookies, but the fundamental exposure during indexing cannot be eliminated entirely.

Where does Hister stand?

Online search Metasearch Hister
Query leaves your machine Yes Yes (via proxy) No
Dependent on external index Yes Yes No
Tracking when reading results Yes Yes No (offline preview)
Index coverage Comprehensive Comprehensive Limited to what you index
Verifiable privacy No Partial Yes, free software, self-hosted

Hister is not the right tool for every search. It is the right tool when privacy is non-negotiable, when you need to be certain, not just hopeful, that your searches stay private.

If that matters to you, try the demo or follow the quickstart guide to run your own instance in minutes.