Firefox 3 Antiphishing Sends Your URLs To Google
iritant writes "As we were discussing, Gran Paradiso — the latest version of Firefox — is nearing release. Gran Paradiso includes a form of malware protection that checks every URL against a known list of sites. It does so by sending each URL to Google. In other words, if people enable this feature, they get some malware protection, and Google gets a wealth of information about which sites are popular (or, for that matter, which sites should be checked for malware). Fair deal? Not to worry — the feature is disabled by default."
This isn't news. ANY anti-phishing tool that checks to see if a page is a phishing site is going to have to send it SOMEWHERE... or did you think that they were just going to be able to magically download a tiny file on your computer that would just 'know' all the phishing sites?
They all do this, which is why I don't use them. Some common sense will tell you if a site is phishing. If you try to go to a bank website and get http://bank-0-am3rika.tv/l0g0n, then you might want to reconsider putting in your username and password.
Silly sensationalism. nothing more.
If firefighters fight fire, and crimefighters fight crime, what do freedom fighters fight? - George Carlin
A "blacklist" of phishing sites needs to be stored somewhere, and you need to be able to do queries against it.
It changes too fast, and is too large, for it to be stored locally.
So SOMEBODY needs to provide a database interface to it, and unless you are willing to tolerate the voodoo cryptography and serious performance penalty to do privacy-preserving searches, how else is this supposed to be done?
Test your net with Netalyzr
It seems to me that the users who most need anti-phishing protection are the ones least likely to change their defaults.
I bet we wouldn't have half the problems we do now if people just stopped automatically trusting everything they see.
"Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."