7 ms·
Well, sending some user files to Ukrainian server is a bug. But sending hashes of your downloads to Google [1][2] is a feature, right? 1. https://support.mozi
by johnnydoebk 11y ago
Well, sending some user files to Ukrainian server is a bug.
But sending hashes of your downloads to Google [1][2] is a feature, right?
1. https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
2. https://bugzilla.mozilla.org/show_bug.cgi?id=1138721 https://bugzilla.mozilla.org/show_bug.cgi?id=1138721
- kiproping 11y agoHow can I disable this.
- mdibaiee 11y agohttps://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work#w_how-do-i-use-the-phishing-and-malware-protection-features https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
- chippy 11y agoIs this the list? https://dxr.mozilla.org/mozilla-central/source/toolkit/components/downloads/ApplicationReputation.cpp#391 https://dxr.mozilla.org/mozilla-central/source/toolkit/compo... Just executables, identified by file extension and if you are on Windows, .zip files as well.
- sp332 11y agoThe first page says: "There are two times when Firefox will communicate with Mozilla’s partners while using Phishing and Malware Protection. The first is during the regular updates to the lists of reporting phishing and malware sites. No information about you or the sites you visit is communicated during list updates. The second is in the event that you encounter a reported phishing or malware site. Before blocking the site, Firefox will request a double-check to ensure that the reported site has not been removed from the list since your last update." That seems pretty reasonable. But the second one looks like it checks every executable file you download. Why isn't that mentioned on the FAQ?
- rockdoe 11y agoIt is? Same FAQ page you listed: "When you download an application file, Firefox will verify the signature. If it is signed, Firefox then compares the signature with a list of known safe publishers. For files that are not identified by the lists as “safe” (allowed) or as “malware” (blocked), Firefox asks Google’s Safe Browsing service if the software is safe by sending it some of the download’s metadata."