3 ms·
are you referring to this? https://news.ycombinator.com/item?id=9779440 https://news.ycombinator.com/item?id=9779440 this is the first I've heard of this, coul
by lingben 11y ago
are you referring to this?
https://news.ycombinator.com/item?id=9779440 https://news.ycombinator.com/item?id=9779440
this is the first I've heard of this, could you be more specific?
- brador 11y agoThis: https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work#w_how-does-phishing-and-malware-protection-work-in-firefox https://support.mozilla.org/en-US/kb/how-does-phishing-and-m... It sends a hash of the file to Google with your IP/print. Worded like it's anonymous and one way, it's not. The hash is unique to the file, if your file-hash database is large enough (like Googles) you can cross reference to get the details of the original file. From this hash, you can then see the exact file the person is downloading. Great if you want to make a list of who is downloading an unallowed file, like say, a list of missing Chinese citizens or anything from wleaks.
- lern_too_spel 11y agoNothing on that page mentions a hash. There is absolutely nothing misleading in the page you linked.
- brador 11y agoThe metadata sent to Google includes a hash of the file. That's what the metadata part means.
- lern_too_spel 11y agoNo, the metadata means the URL (not hashed). The protocol is linked from the page you posted. It's clear as day, and the only person who would be misled is somebody who didn't read the page at all and claimed it said things it doesn't say.
- lingben 11y agopretty sure you're misunderstanding how firefox handles that, it downloads to local and checks against it, not the other way around
- brador 11y agoOnly if it's signed by a known good publisher. Is that file you downloaded from Github signed by a known good publisher? Nope, then it's getting sent to Google for logging. Oh, it was a list of detained journalists? Well, no more gov contract work for you and you'll never know why.