5 ms·
"Privacy Google maintains the Safe Browsing Lookup API, which has a privacy drawback: "The URLs to be looked up are not hashed so the server knows which URLs t
by iMerNibor 11y ago
"Privacy
Google maintains the Safe Browsing Lookup API, which has a privacy drawback: "The URLs to be looked up are not hashed so the server knows which URLs the API users have looked up". The Safe Browsing API v2, on the other hand, has the following privacy advantage: "API users exchange data with the server using hashed URLs so the server never knows the actual URLs queried by the clients". The Firefox and Safari browsers use the latter."
https://en.wikipedia.org/wiki/Google_Safe_Browsing#Privacy https://en.wikipedia.org/wiki/Google_Safe_Browsing#Privacy
- deleted 11y ago[deleted]
- jonchang 11y agoFirefox's safebrowsing feature uses a separate cookie jar, so if you are logged into Google those cookies will never be sent via the safebrowsing API. Also, Firefox hashes the URL and compares the prefix of that hash to a master table downloaded from Google. If the URL matches a prefix in the table, Firefox requests all URLs that begin with that prefix hash. Google is never sent the full hashed URL.
- tedunangst 11y agoHeh. The next paragraph after that quote is: > Safe Browsing also stores a mandatory preferences cookie on the computer[9] which the US National Security Agency allegedly uses to identify individual computers for purposes of exploitation.[10] That may or may not be true, but must one be a radical to be concerned?
- nickodell 11y agoIt's true, but slightly misleading. If you open firefox and browse to a few sites, it will send that cookie. If you then take your computer down to the coffee shop and keep browsing, even if you don't log into anything, it will still send that cookie in the clear. There are other ways that the NSA can figure out a list of IP addresses you've been using, but this is 1) totally silent, and 2) is common to a lot of systems.
- itistoday2 11y ago> "API users exchange data with the server using hashed URLs so the server never knows the actual URLs queried by the clients". Privacy Theater. No real information is lost since all you need to do is have a database of domains and boom, hash easily reversed.
- magicalist 11y agoPlease tell me you didn't just edit that wikipedia article and cite your own comment. Not only is that not a valid wikipedia cite, it's not even right. Only hash prefixes are ever sent to Google, and only if it's already tested locally that the hash prefix includes malicious sites. Humorously this exact same exchange took place in the linked conversation: https://lists.debian.org/debian-devel/2015/07/msg00232.html https://lists.debian.org/debian-devel/2015/07/msg00232.html edit: wow, it was you. https://en.wikipedia.org/w/index.php?title=Google_Safe_Browsing&type=revision&diff=671512026&oldid=670960707 https://en.wikipedia.org/w/index.php?title=Google_Safe_Brows...
- itistoday2 11y ago> wow, it was you. Yes, I did that for two reasons: - I couldn't find a better link for the citation and it seemed like rather important info that should be in the wiki. Maybe someone else would find a better one to replace it with. - I figured linking to an HN discussion would serve as a great citation, even if I was mistaken about something. Looks like HN didn't disappoint. :) EDIT: I've updated the wiki text to remove my previous edits and added a mention about the use of hash prefixes. > Not only is that not a valid wikipedia cite, it's not even right. Only hash prefixes are ever sent to Google, and only if it's already tested locally that the hash prefix includes malicious sites. Humorously this exact same exchange took place in the linked conversation: https://lists.debian.org/debian-devel/2015/07/msg00232.html https://lists.debian.org/debian-devel/2015/07/msg00232.html Thanks for the link and pointing that out, I stand corrected. I'm curious to know how big the prefix is. Depending on its size this either remains privacy theater or not.
- magicalist 11y ago