15 ms·
Apple Is Sending URLs to Tencent?
- ripley12 7y ago(edit: the source in question has removed the tweet, so I have too)
- kop316 7y agoI'm getting a "Page doesn't exist" for your link FYI.
- iamspoilt 7y agoI am getting a "Sorry, that page doesn’t exist!" for the twitter link you shared.
- BenTheElder 7y agoLooks like the twitter post you referenced was deleted. That user's only recent post is about super mario maker 2...
- valleyer 7y agoMore details on how this works, for Google at least, here: https://developers.google.com/safe-browsing/v4/update-api#checking-urls https://developers.google.com/safe-browsing/v4/update-api#ch...
- user82738 7y agoThis is only one of the APIs. Full doc at: https://developers.google.com/safe-browsing/v4 https://developers.google.com/safe-browsing/v4
- marcinzm 7y ago> China only. Based on the twitter conversation, it's NOT China only. It's Chinese localization only. Big difference. That means anyone anywhere in the world who set their computer to Chinese has their data sent. Including Europe which is likely a GDPR violation.
- innagadadavida 7y agoThe google servers apparently takes url hash prefix. Does tencent do the same? If so is it still considered a gdpr violation? There is not much info in a url hash prefix.
- rocqua 7y agoSuppose peeps going to HN are suspect. Then anyone who often produces hash prefixes that match HN is suspect. When you start getting sequences, you could possible start matching how people navigate a website. Essentially, a hash-prefix allows you to rule out / semi confirm guesses about browsing behavior.
- deleted 7y ago[deleted]
- amanzi 7y agoThe author of the tweet goes into more depth in a blog post: https://blog.cryptographyengineering.com/2019/10/13/dear-apple-safe-browsing-might-not-be-that-safe/ https://blog.cryptographyengineering.com/2019/10/13/dear-app...
- mulle_nat 7y agoWait, Apple is Sending URLs to Google ?
- slenk 7y agoI think a lot of browsers do for the "Safe Browsing" checks
- phyzome 7y agoFirefox downloads a big blob of unsafe URLs and checks against that, last I saw.
- sanxiyn 7y agoNo, Firefox uses the exactly same Safe Browsing protocol. In fact, the protocol was co-developed by Google and Mozilla.
- phyzome 7y agoInteresting. I do remember people complaining about a large file in Firefox profiles, in the context of multi-user host admins wanting to be able to have it in a centrally managed location rather than replicated to every profile. I recall it being a sizable sqlite DB for Safe Browsing. I wonder what that was about, then.
- teraflop 7y agoThe Safe Browsing API is deliberately designed to avoid leaking the contents of URLs to Google. You can read about how it works here: https://developers.google.com/safe-browsing/v4/update-api https://developers.google.com/safe-browsing/v4/update-api
- xenophonf 7y agoIt's designed to avoid leaking URLs, but I'd be a lot more comfortable if Safe Browsing worked by downloading a list of hashes to my computer and checking locally. That way, data never leaves my device.
- larkeith 7y agoI'm curious if, as @thefalken brought up [0], this is illegal under the GDPR, given that it's a hidden opt out and should apply to EU citizenry with browser language set to Chinese. [0] https://mobile.twitter.com/thefalken/status/1183445477645312002?p=v https://mobile.twitter.com/thefalken/status/1183445477645312...
- alextheparrot 7y agoThe code appears to be used for fraud related purposes, meaning, to my understanding, Apple would likely argue it has a legitimate interest. There’s a lot of legal language around this exception, but fraud is directly called out as a legitimate interest and means that the group controlling the data would not need to obtain user consent. For additional reading, I’d recommend the following post: https://www.gdpreu.org/the-regulation/key-concepts/legitimate-interest/ https://www.gdpreu.org/the-regulation/key-concepts/legitimat...
- the8472 7y agoIs apple the data controller here since it's all happening on the users' device? And does "legitimate interests" extend beyond the data controller's interests? I.e. if it's only about fraud against apple then safe browsing (which is supposed to protect the user from fraud) would not necessarily be a legitimate interest of apple. It might have to be opt-in at least.
- alextheparrot 7y agoGreat questions, which I know I'm not equipped to answer authoritatively - prior comment was just my two-cents on how I'd expect Apple to argue the issue (And even that argument may be a losing one). In opposition to the fraud argument, one could argue they wouldn't reasonable be expected to have their data forwarded to China. The counter-argument to that would likely be along the lines of users who have their localization set to China might have more of an expectation of this. And so the lawyer fees continue to increase in what would be an incredibly interesting case, honestly.
- 7y ago
- yorwba 7y agoThis is really a "damned if you do, damned if you don't" kind of situation. They can either use Tencent's Safe Browsing API as a drop-in replacement for Google's API, relying on k-anonymity to leak as little information as possible. That leaves them open to accusations that they allow Tencent (or, for that matter, Google) to track the browsing history of Safari users. Or they can essentially turn off Safe Browsing in China. (Google's API is collateral damage of the Great Firewall.) That leaves their users unprotected against all kinds of malware and scams. I think they made the right call here by protecting users against the most common threat (most people are not dissidents), while giving advanced users with a different threat model the opportunity to opt out.
- matthewdgreen 7y agoAlternatively, they could purchase the data from Tencent or another company, and operate their own version of the service. That may even be what they’re doing —- but we don’t know, since they launched the service with no details or publicity.
- pmoriarty 7y agoYet another approach is to send the entire list of all malware URLs to each client and let the client do all the processing on their end. This way no data (hashed, anonymized, truncated, or otherwise) would need to be sent to Tencent, Apple, or Google, or anyone else.
- pearjuice 7y agoRemarkable when people become upset when it is explicitly stated your mobile tracking device sends information to third party servers, but deep down we all know the dangers are in what is not explicitly stated.
- awinter-py 7y agoevery form of software phone-home is sleazy we should be linting code to say whether it phones home or not, and what it uploads when it does. plain language privacy policies and ever-changing browser settings are leaving huge gaps. when the US government bought chinese drones they hired a consultant to prove that the drones never call home.
- OJFord 7y ago> we should be linting code to say whether it phones home or not Is that possible? How do you diffentiate it from expected API calls? (Not convinced black/white-listing strings is any different from code review in this case - it'll just be changed on demand if if prevents adding what was tried to be added.)
- awinter-py 7y agoit's theoretically possible. I don't know of any tools that do it (which could be a comment on my research skills rather than the state of the art). in theory you can do dataflow analysis on all external inputs to the program (geo, filesystem, text) and monitor where that goes in the program. For something more complicated like a browser, you might want to do the analysis per component (URL bar in this case). wouldn't be perfect, but it's a starting point. linting is tougher on closed-source software than open-source, but if a company certified a linter output and was found to be lying I'm comfortable with using the law to resolve that.
- UncleMeat 7y agoExcept you'd never have a good enough dataflow analysis to work on arbitrary code without burying people with false positives. Especially in C++ code, where things like function pointers just destroy call graph precision (and therefore taint analysis precision). Linting doesn't even give you this much. All it'd be able to tell you is "where in the program are calls to networking APIs being made" and maybe determining parameters if they are defined in the same function as the call.
- leoh 7y agoLink to code in question https://github.com/Igalia/webkit/blob/9777baa3db09cad7ed5b2ca8ddf5188e7a841aa8/Source/WebKit/UIProcess/Cocoa/SafeBrowsingWarningCocoa.mm#L39 https://github.com/Igalia/webkit/blob/9777baa3db09cad7ed5b2c...
- saagarjha 7y agoWould you mind linking to the upstream repository instead? GitHub doesn’t let you search in forks.
- fireattack 7y agohttps://github.com/WebKit/webkit/blob/master/Source/WebKit/UIProcess/Cocoa/SafeBrowsingWarningCocoa.mm#L40 https://github.com/WebKit/webkit/blob/master/Source/WebKit/U... (For some reason "search in this repo" doesn't work for keyword `malwareDetailsBase` [1], but it's there) [1] https://github.com/WebKit/webkit/search?q=malwareDetailsBase&unscoped_q=malwareDetailsBase https://github.com/WebKit/webkit/search?q=malwareDetailsBase...
- sqs 7y agoURL to same code search on Sourcegraph (which works): https://sourcegraph.com/search?q=repo%3Awebkit%2Fwebkit+malwareDetailsBase https://sourcegraph.com/search?q=repo%3Awebkit%2Fwebkit+malw... (Disclaimer: I am the Sourcegraph CEO.)
- fireattack 7y agoIt shows Search timed out Try narrowing your query, or specifying a longer "timeout:" in your query. right now.
- sqs 7y agoSorry about that. There must’ve been a brief blip during a moment of intense load or a redeploy. Is it working for you now?
- MrSourz 7y agoQq
- saagarjha 7y agoTook a quick look, and this appears to be enabled if [NSLocale.currentLocale.countryCode isEqualToString:@"CN"]: char ____ZN7Backend6Google12SSBUtilities24shouldConsultWithTencentEv_block_invoke_2(void * _block) { rax = [NSLocale currentLocale]; rax = [rax retain]; r14 = [[rax countryCode] retain]; [rax release]; rbx = [r14 isEqualToString:@"CN"] != 0x0 ? 0x1 : 0x0; [r14 release]; rax = rbx; return rax; } Update: the code for Tencent Safe Browsing seems to be very similar to that which talks to Google, down to it being under a "Google" namespace, the API endpoints being named the same, and performing hashing which seems to match the "Update API" here: https://developers.google.com/safe-browsing/v4/update-api https://developers.google.com/safe-browsing/v4/update-api. I think this is just "whatever Google could see before, Tencent can see now, if you're in China". I'm no expert, so I have no idea if that's k-anonymous or whatever if Tencent/Google decide they want to track you, but in either case it's just shifting who's getting your hashes.
- deleted 7y ago[deleted]
- rocqua 7y agoWhat kind of code am I looking at, it seems pretty cool. I this some automatically 'reverse compiled' assembly? In any case, I'd love to know how you generated this. Would be very cool to get something similar out of an executable.
- saagarjha 7y agoIt's "decompilation" of a block invoke for Backend::Google::SSBUtilities::shouldConsultWithTencent() taken by opening /System/Library/PrivateFrameworks/SafariSafeBrowsing.framework/SafariSafeBrowsing in Hopper Disassembler.
- elwell 7y ago> ____ZN7Backend6Google12SSBUtilities24shouldConsultWithTencentEv_block_invoke_2 I'm glad I don't use Objective-C... That's some Java level function naming there. Edit: may have spoke too soon, appears to be possible reverse engineered / decompiled?
- bighi 7y agoIt's better than sending URLs to Google, in my view.
- sgz 7y agoAre those Google/Tencent API requests done only when browsing with Safari, or are they done for any SFSafariViewController? That would imply it’s also inside Brave/Firefox/Chrome...
- zaphirplane 7y agoThe safe browsing seems to work in private mode or am I missing something
- stevespang 7y agoBrave Browser
- w1nst0nsm1th 7y agoIt's no big deal. That just means Safari will find malware on any site critical of Chinese government and they can track through url the id of any critical comment you post on HN and link it to your ip and, thank to statistical analysis, your name and your physical address and your results through your whole scolarity. I'm personaly ok with it. Beside, it is well known the farts of Chairman Mao smelled like flowers and Xi Jiping doesn't look like Winny The Pooh and the Chinese Communist Parti is leading the world toward the enlightment of a new blessed era welcomed by sane people.
- dhdhebsb 7y agoIt literally says it’s going to send links to Google Safe Browsing and Tencent Safe Browsing in the Safari setting page under “Safari and Privacy”
- saagarjha 7y agoThat’s not what it says.
- newshorts 7y agoWhich one of these comments is right? You both can’t be.
- saagarjha 7y ago> Before visiting a website, Safari may send information calculated from the website address to Google Safe Browsing and Tencent Safe Browsing to check if the website is fraudulent. These safe browsing providers may also log your IP address. This is quite different from sending links.
- chenzhekl 7y agoProbably this is the page of Tencent safe browsing: https://urlsec.qq.com/ https://urlsec.qq.com/ I don’t understand why you trust Google so much. It’s as untrustworthy as Tencent for me.
- sekasi 7y agoAgain I feel like I'm reaching out to be educated here.. but if Safari is attempting to validate URLs for safe browsing using the Google API (which it states it will do, quite openly), and Google products is quite clearly blocked in China so it resorts to Tencents API (which it states it will do, quite openly).. why does this seem to provoke anger? I mean this in the most equitable way possible, I'm more trying to understand where Apple has done anything wrong here?
- brians 7y agoWe can’t tell whether non-China data goes to Tencent—intentionally or by some bug or adversarial problem.
- woutr_be 7y agoThe code [1] along, with this explanation [2] does seem to show that it only happens for devices with the country code set to CN. [1]: https://github.com/Igalia/webkit/blob/9777baa3db09cad7ed5b2ca8ddf5188e7a841aa8/Source/WebKit/UIProcess/Cocoa/SafeBrowsingWarningCocoa.mm#L39 https://github.com/Igalia/webkit/blob/9777baa3db09cad7ed5b2c... [2]: https://news.ycombinator.com/item?id=21242628 https://news.ycombinator.com/item?id=21242628
- thawaway1837 7y agoWhy is this more controversial than Apple sending URLs to Google?
- wtmt 7y agoApple has done a lot for privacy in its products and its public statements. But I believe that if it has to have a better impact and be trusted, it needs someone dedicated to privacy who will (ensure that it will) publish details of its products, apps and activities in an honest form in an accessible place (and updated more often than a once-a-year OS upgrade cycle). This kind of commitment to more transparency will help the company be trusted and also held up to questions. Said trust is already eroding with recent events. Apple shouldn’t be complacent and stick to its old ways. Sadly, Apple also has a history of brushing things away or ignoring uncomfortable questions.
- ycombonator 7y agoTim Apple better have an explanation for this one.
- deleted 7y ago[deleted]
- Jyaif 7y agoIt should be noted that Apple could very well proxy those requests to Google and Tencent to protect their customers' ip address, or even implement safe browsing on their own all together. The fact that they don't means that either they trust Google and Tencent, or that they don't care about privacy.
- taobility 7y agoI think the audience in HN are crazy now. Why would you prefer Google than Tencent for same purpose of API? Should all Chinese scare that iPhone would send back all logs to California? Should they scare Tesla sent back all their driving data to US? If you don't trust anything from China, would you destroy any electronics Made In China, including your smartphones, laptop, TV etc, or even some food?
- aussieguy1234 7y agoThis is where they need to sacrifice some computer security for physical security. By turning this off, a few people who don't follow good security practices might get malware. But no one will be sent to prison or "disappeared".