3 ms·
But these features don't send your browsing history anywhere. The Firefox safe browsing service downloads a list of bad URLs in form of hashed prefixes from the
by jonchang 10y ago
But these features don't send your browsing history anywhere. The Firefox safe browsing service downloads a list of bad URLs in form of hashed prefixes from the Google service. Then every page you visit is compared against the downloaded list (offline). If there's a match, Firefox sends the hashed prefix up to Google and downloads a list of all full URLs that match that hashed prefix. There's another offline comparison and if the web page you are visiting still matches, then the page is blocked and the phishing/malware warning is shown. At no point is an actual URL sent to Google or anyone else.
https://developers.google.com/safe-browsing/v4/update-api https://developers.google.com/safe-browsing/v4/update-api
- jlgaddis 10y agoHonest questions: How could they say "This file is not commonly downloaded" without knowing how often it is downloaded? If they know how often files are downloaded, where are they receiving that information from?
- niftich 10y agoMicrosoft introduced a similar feature in 2010. In that scheme, "file identifier" and the signature, if the application is signed, is sent to a cloud service [1][2][3]. Therefore they can track attempts for downloads, without having to know the URL itself. [1] https://blogs.msdn.microsoft.com/ie/2010/10/13/stranger-danger-introducing-smartscreen-application-reputation/ https://blogs.msdn.microsoft.com/ie/2010/10/13/stranger-dang... [2] https://blogs.msdn.microsoft.com/ieinternals/2011/03/22/everything-you-need-to-know-about-authenticode-code-signing/ https://blogs.msdn.microsoft.com/ieinternals/2011/03/22/ever... [3] https://blogs.msdn.microsoft.com/ie/2011/03/22/smartscreen-application-reputation-building-reputation/ https://blogs.msdn.microsoft.com/ie/2011/03/22/smartscreen-a...
- kobayashi 10y agoDo you happen to know how this compares to Web of Trust's operations?
- awqrre 10y agoSo if they want to know if you visit a specific site, all they need to do is add it to the list (a hash prefix is probably often enough to be very specific)... Wikileaks was added and removed from the list lately... I will just leave this feature off. Also, I don't follow Firefox' code close enough and the behavior might change at any time.