4 ms·
Firefox isn’t necessarily scanning the files for viruses, they’re often just using databases that list domains suspected of hosting malware. IIRC, Chrome does
by sus_007 8y ago
Firefox isn’t necessarily scanning the files for viruses, they’re often just using databases that list domains suspected of hosting malware.
IIRC, Chrome does the same thing too. I think it's not much of an issue for Firefox to flag stuffs downloaded from suspected URLs as a malware since it's not uncommon to have one's system infected from those sites' content. Firefox is just trying it's best to prohibit any sort of system infection through itself.
- yjftsjthsd-h 8y agoThen (as the article suggests) Firefox should actually tell the user that it is the site that is untrusted and not the file, and allow the user to save it so that they can actually scan it themselves.
- klez 8y ago> Firefox is just trying it's best to prohibit any sort of system infection through itself. In that case I would change the wording from "contains malware" to "may contain malware". Also, they're prohibiting nothing. They still give you the option to open the file (which, as explained by the article, opens a whole different, albeit small, can of worms)
- Viliam1234 8y ago> In that case I would change the wording from "contains malware" to "may contain malware". Or even more precise: "may contain copyright infringement".
- mc32 8y agoI wonder why they can’t integrate some service like VirusTotal into their downloader. Sure, for heretofore new objects it’ll take longer, but they have a long list of many many file hashes and their reputation dB .
- chmod775 8y agoBecause I don't want Firefox to send what I download to some (third party) company. Or anywhere for that matter. Their (and chrome's) current solution to block malware domains use a client-side bloom filter afaik. If you'd try to build the same client-side into firefox, you'd have just built another (bad) antivirus software. Might as well integrate clamav into firefox then.
- mc32 8y agoCan’t they just compare hashes and for those where they have to do a scan, serve as an anonymous intermediary/proxy?
- GlitchMr 8y agoPerhaps similarly to Pwned Passwords API, except for files: https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/ https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
- laumars 8y agoThere are quite a few reasons I can think of: * Privacy * Performance * They would likely have to work with Virus Total to support their infrastructure as I can only imagine how quickly they'd take such a cloud service offline if everyone started using it by default * And then what happens if / when the cloud service does have an outage? Does that mean people are blocked from downloading things? * Same question for people on a corporate network who might have Virus Total blocked * Same question for people on poorer internet connections as now the user has to transfer twice as much data if it's not a hash already stored on Virus Total. That all said, its a cool idea for a third party browser add-on (if it hasn't already been done?)
- mc32 8y agoThose are good things to think about, but I'll give them a stab: _Privacy: They [FF] can act as anonymous proxy. _Perf: Yes, for new objects, but for known objects, it should be minimal. _Service outage: Build a system which can allow an override (download at your own peril, while service is out) _Corp should already have enterprisey systems in place _New, unknown object: Yes an issue. As someone else said [GlitchMr], if they can do it ala haveibeenpowned I think it's worth looking into.
- gruez 8y agocue the inevitable "Firefox is leaking every file you downloaded!"
- Jdam 8y agoOh, if Chrome does it, it’s totally fine for Firefox to do it, too!! Wait, why am I not using Chrome then in the first place?