They constantly measure DomRect using javascript, which is a unique hardware-based metric that can be used to track individual users.
Imagine the cost of running duck.ai. What exactly is the revenue that it brings in?
Of course, if it were some honeypot, using DomRects to track users (and DomRect is not protected by Tor Browser or Mullvad Browser etc), well then it doesn't really matter if it's not bringing in much revenue since it's value is in being a honeypot.
Yes, DomRect can be used legitimately in coding without tracking users... but why does ddg need to use this when they know that it CAN be used to track users and users have no way to audit the servers?
It's really interesting they measure DomRect and not Canvas when privacy-aware users often block canvas fingerprinting but don't block DomRect.
It's sus
