3 ms·
Did you turn on that 'Block dangerous and deceptive content' feature in Firefox' security tab? It works by consulting Google each time you visit a new website.
by aawc 8y ago
Did you turn on that 'Block dangerous and deceptive content' feature in Firefox' security tab? It works by consulting Google each time you visit a new website. You can imagine the rest.
Patently wrong. Here's how the API works:
The Update API lets your client applications download hashed versions of the Safe Browsing lists for storage in a local database. URLs can then be checked locally. Only if a match is found in the local database does the client need to send a request to the Safe Browsing servers to verify whether the URL is included on the Safe Browsing lists.
From: https://developers.google.com/safe-browsing/v4/update-api https://developers.google.com/safe-browsing/v4/update-api
Source: Safe Browsing engineer on Chrome.
- yjftsjthsd-h 8y agoSo then it semi-randomly sends Google URLs you visit? That's better, but I wouldn't say patently wrong. Statistically usually wrong?
- lixtra 8y ago> So then it semi-randomly sends Google URLs you visit? No, it computes a 4 byte hash of the URL (domain?) and if this matches a local DB entry then it asks google for all malicious URLs with that hash (explained in the link of parent). Depending how many entries there are your browser contacts google fairly frequently and then google using techniques mentioned in the article can link your TLS-Cookie to your IP.
- manicdee 8y agoA four byte hash is unique to two billion sites. The collision space with non-mainstream sites you might visit is going to be tiny. It’s as good as sending the actual URL, and possibly even the full path to the document you requested, if the browser has previously asked Google for another site and Google has seen a pattern of browsing from Site A to Site B in browsers not using this “security” feature.
- lixtra 8y ago> A four byte hash is unique to two billion sites Due to the birthday paradox collisions happen much earlier.
- Engineering-MD 8y agoYes, but that is (by the nature of the paradox) only true for a small subset of sites. It provides a huge amount of information, and for much the same reason, DoB is often used as part of an identifier.
- lixtra 8y agoLet’s assume that it is indeed the hash of the URL as they wrote. There are much more than 2B URLs on the net. Assume google flagged 2M as malicious (a 8MB db). So on average you get a hit for 1 in thousands URLs. For each hit you query google for the malicious sites with the actual hash. It does feel like some information could leak but at the same time there are literally hundreds of possible URLs that map to each hash value. So there is plausible deniability as well. Again, combined with more information this could be exploited. But probably there are easier attack vectors.
- manicdee 8y agoNot the point. You issue quest on hash A then hash B. Google guesses that because of other activity it has seen today, visits to a site marked by hash A followed by visits to site marked hash B means you are following a link from Alex Jones’ blog to a flat earth holocaust denial web site, and thus prepares to serve your IP address ads for tin foil hats and prepper magazines. The chances of your traffic pattern of hash A then hash B colliding with, say, my browsing of the MLP fan club and following a link to cosplay photos from Dragon Con are pretty slim, even though the MLP fan club URL hash collided with the Alex Jones blog hash. Google aren’t just looking at the one thing you viewed, they are following you everywhere.
- flukus 8y ago> That's better Is it? Typically these shady sites would be the ones I'd most like to keep private.
- Avshalom 8y agoany evidence that it doesn't match with the top ~1M websites? because that page says "hashed versions" which kind of implies "not inspect-able". also why does it collect client ID at all and also "should uniquely identify a client implementation, not an individual user" doesn't sound a lot like "can't identify an individual user" ... especially in a home user context.
- UncleMeat 8y agoGiven that the system makes a network request when a hashed match is found, anybody could verify this. Surely the evidence would need to go in the other direction, especially since revealing the offending websites would signal to malicious parties exactly what they need to change.
- corv 8y agoYou’re right, it doesn’t contact Google every time but it does contact Google periodically, something which many users might not be aware of. Ideally Firefox wouldn’t rely on contacting any third parties in their default browser configuration.
- oliwarner 8y agoNo, there's a substantive difference between "contacts Google to run a check on a specific domain" and "contacts Google to update the local database of bad domains". They're not comparable. And a browser that doesn't contact third parties isn't much of a browser.