Inside Safari 3.2's Anti-Phishing Feature
MacWorld is running a piece from MacJournals.com's for-pay publication detailing how the Safari browser's anti-phishing works. The article takes Apple to task for not thinking enough of its users to bother telling them when Safari sends data off to a third party on their behalf. For it seems that Safari uses the same Google-based anti-phishing technology that Firefox has incorporated since version 2.0, but, unlike Mozilla, tells its users nothing about it. "Even when phrased as friendly to Apple as we can manage, the fact remains that after installing Safari 3.2, your computer is by default downloading lots of information from Google and sending information related to sites you visit back to Google — without telling you, without Apple disclosing the methods, and without any privacy statement from Apple."
In Apple's defense, they've never promised to do no evil. Their goal is to instill such unswerving devotion in their customer base that when they actually do some evil, it's here and gone in the news, and nothing has to change.
So far, so good.
The google service is designed to minimize privacy leaks. It downloads a coarse-hashcheck database (so Google learns nothing). And then if something hits, it queries a detailed hash.
So unless you get a match on the coarse-hash database, Google learns NOTHING. And google only learns a hash if it matches, which is not very useful, AND google doesn't store this information unless it is a match with their detailed database.
Test your net with Netalyzr
"The google service is designed to minimize privacy leaks. It downloads a coarse-hashcheck database (so Google learns nothing). And then if something hits, it queries a detailed hash."
The problem is the lack of disclosure.
Remember, the people who designed the Internet (incorrectly) assumed that all computers on the network would be trustworthy, so the rules are pretty loose.
C'mon, Macworld is better than this. Okay, the article is critically reviewing the anti-phishing feature, but the writer seems to have a bone to pick and in order to post an emotionally charged article, takes things one step too far.
The internet was intentionally designed, itself, not to have a centralized authorizing body for each and every PC and server on the planet. It's decentralized on purpose. When a so called journalist writes something like this, I have a problem, because to me it's just pandering to the security freaks. It's a bit off topic, but I also have a problem reading the rest of the article because it makes it hard to trust what the guy has to say. There's probably good facts in the article, and if there's a problem Apple should be criticized, but I can't possibly continue reading when I see something stupid like this.
"All great wisdom is contained in .signature files"
but over on this side of the pond distributing personally-identifiable information to a third party without explicit consent is a criminal offence.
Sorry I'm less than enthusiastic at your privacy laws considering there's a camera on every corner in your country, watching the citizenry.
On the Oregon Cost born and raised, On the beach is where I spent most of my days
A lot of you seem to love Apple
I use Safari because it's well integrated with OS X. Firefox isn't, and Camino (which I use by preference) has a couple of bugs that are supposed to be fixed Real Soon Now that make it lock up behind a proxy and don't let me disable Apple's stupid insecurity dialogs.
I also use Safari and Camino because they don't use XUL the way Firefox does. I don't trust the security model for XUL nor the technique Firefox uses for the XUL installer, XPI. And in fact there's been at least one XPI-related vulnerability (quickly patched, but it shows that the class of problems I'm concerned about are real).
This doesn't mean I love Apple, or that I think the folks on the Camino team are cooler than the ones on the Mozilla team. This just means I'm more interested in the best tool for the job than where it comes from.
I fail to see how this is a big deal. Did you read the article? If so, you would not panic as well.
First of all, everything is transported in hashes. You do not compare the actual URLs that customers visit, only the hashes. Google has no actual links that indicate the banks that you use and the pr0n sites you have browsed. Only hashes.
Also, this is a configurable option. Apple does not force you to use Google. Apple does not force you to use this feature. I think it would be easier if Apple has explained this feature in the release notes to a greater extent and if users had to accept some sort of a license agreement when enabling this feature. Nothing else beyond it.
Read TFA -- or at least TFS, FFS.
This article is about an anti-phishing feature in Safari that compromises your privacy.
Your solution is to switch to Firefox, which has the exact same feature enabled by default.
Aside from sheer Firefox fanboyism, what's your point?
Don't thank God, thank a doctor!