4 ms·
The full details are in https://www.google.com/chrome/privacy/whitepaper.html#malware https://www.google.com/chrome/privacy/whitepaper.html#malwar... , but the
by pkasting 8y ago
The full details are in https://www.google.com/chrome/privacy/whitepaper.html#malware https://www.google.com/chrome/privacy/whitepaper.html#malwar... , but the short summary is:
A hash prefix list gets downloaded locally; Chrome checks locally against the prefix list. If a URL hits, Chrome will send the hash prefix (not the full hash and not the URL) to the server, the server will send back all full hashes that match that prefix, and then the client will complete the check locally.
In theory, if the server had a small number of matching full hashes, it could guess about what URL a client might be hitting, but in practice the system is designed as much as possible to avoid ever leaking data about what you're visiting to Google servers.