Slashdot Mirror


Firefox 3 Antiphishing Sends Your URLs To Google

iritant writes "As we were discussing, Gran Paradiso — the latest version of Firefox — is nearing release. Gran Paradiso includes a form of malware protection that checks every URL against a known list of sites. It does so by sending each URL to Google. In other words, if people enable this feature, they get some malware protection, and Google gets a wealth of information about which sites are popular (or, for that matter, which sites should be checked for malware). Fair deal? Not to worry — the feature is disabled by default."

13 of 296 comments (clear)

  1. Not new. by garbletext · · Score: 5, Informative

    This is a non-story. The ability to ask google about phishing has existed since 2.0, and was disabled then as well. Not that telling google every site you visit is a good thing.

  2. Re:And Google does it again! by cephalien · · Score: 5, Insightful

    This isn't news. ANY anti-phishing tool that checks to see if a page is a phishing site is going to have to send it SOMEWHERE... or did you think that they were just going to be able to magically download a tiny file on your computer that would just 'know' all the phishing sites?

    They all do this, which is why I don't use them. Some common sense will tell you if a site is phishing. If you try to go to a bank website and get http://bank-0-am3rika.tv/l0g0n, then you might want to reconsider putting in your username and password.

    Silly sensationalism. nothing more.

    --
    If firefighters fight fire, and crimefighters fight crime, what do freedom fighters fight? - George Carlin
  3. Re:Does a master list exist? by 42forty-two42 · · Score: 5, Informative

    By default firefox does not send URLs to google. It downloads a static list from google periodically, and checks against that.

  4. Uhh, how ELSE are you going to do this? by nweaver · · Score: 5, Insightful

    A "blacklist" of phishing sites needs to be stored somewhere, and you need to be able to do queries against it.

    It changes too fast, and is too large, for it to be stored locally.

    So SOMEBODY needs to provide a database interface to it, and unless you are willing to tolerate the voodoo cryptography and serious performance penalty to do privacy-preserving searches, how else is this supposed to be done?

    --
    Test your net with Netalyzr
  5. Oh my GOD! by gowen · · Score: 5, Funny

    Google are going to find out what websites are popular. That's information that they simply couldn't otherwise find out unless they ... oooh ... operated the world's most popular search engine.

    Everybody panic!

    --
    Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
  6. the unarticle... by revery · · Score: 5, Funny

    Breaking news: Cheese gives you cancer!!

    Oh wait, no it doesn't... You might still get cancer though...

  7. Clueless users don't change defaults by lowy · · Score: 5, Insightful

    It seems to me that the users who most need anti-phishing protection are the ones least likely to change their defaults.

  8. Fixed that for you. by Kadin2048 · · Score: 5, Insightful

    I bet we wouldn't have half the problems we do now if people just stopped automatically trusting everything they see.

    --
    "Ladies and gentlemen, my killbot features Lotus Notes and a machine gun. It is the finest available."
    1. Re:Fixed that for you. by XenoPhage · · Score: 5, Funny

      I bet we wouldn't have half the problems we do now if we just stopped having people.

      --
      XenoPhage
      Technological Musings
    2. Re:Fixed that for you. by QuickFox · · Score: 5, Insightful

      I bet we wouldn't have half the problems we do now if we were just.

      --
      Terrorists can't threaten a country's freedom and democracy. Only lawmakers and voters can do that.
  9. Re:And Google does it again! by LMacG · · Score: 5, Informative

    Ah, you mean the way it already works, then? Good idea!

    --
    Slightly disreputable, albeit gregarious
  10. Re:And Google does it again! by Zaatxe · · Score: 5, Interesting

    Here in Brazil, Petrobras gasoline stations have the brand BR over a green and yellow pair of stripes. And then somebody had the idea of branding their gasoline stations 13R, using a font almost impossible to tell the differrence between BR and 13R. And of course this 13R stations sell very low quality fuel...

    But you don't need to believe me, you can believe your own eyes. This is the 13R station and This is a real BR station.

    --
    So say we all
  11. Re:Does a master list exist? by elyk · · Score: 5, Interesting

    In firefox 2.0, if you look in preferences > security, there are two options for antiphishing. One is the "use a downloaded list" option, and the other is the "check by asking google for each site I visit". But the word google is a dropdown box - it appears that there will eventually be more choices, but they haven't made deals with (or been offered money from, depending on how cynical you are) other providers yet.

    --
    MS-DOS: Most Severe Denial of Service
    Free Online Backup