Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Block malware from downloaded files

Hi, Google. Would you just look at what I downloaded!



I'm also a bit worried about the privacy implications of this. Especially given that the feature is hidden, and the only two ways to turn it off involve going into about:config, which most people don't even know exists. I wouldn't even know it was doing this if I hadn't read the changelog.

Reading the changelog, it also mentions having local and remote blacklists, but how FF chooses which one to use wasn't clear to me. Local blacklists are not as scary to me for obvious reasons. Being able to use this without the remote blacklist would be nice.

I would really love some additional info on this feature from Mozilla, as well as a more user-friendly way of disabling it.


> and the only two ways to turn it off involve going into about:config, which most people don't even know exists.

There's a third way according to the feature's development documentation [0]: uncheck "Options"/"Preferences" -> "Security" -> "Block reported attack sites".

[0]: https://wiki.mozilla.org/Security/Features/Application_Reput...


It's in the documentation: https://wiki.mozilla.org/Security/Features/Application_Reput...

1) Check local blacklist 2) Check local whitelist 3) If no hits on either, check remote service


It seems like the last few updates of Firefox are each hiding yet one more important setting... I think that is what will finally drive me away from Firefox (I've used it since the beginning even if chrome was much faster for a while) ... time to browser shop.


There's no "seems" about it. Useful functionality has been obscured or removed from Firefox time and time and time and time again since Firefox 4 and their rush to imitate Chrome. It isn't a new problem at this point; it has been happening for years now, and people have been angered by it for years now, too.

It's a shame that your comment has been voted down, as well. The more that the Firefox community goes out of its way to deny that users are unhappy, or even to censor them like in this case, the harder it will be for Mozilla to remain relevant.

Firefox is pretty much Mozilla's only semi-successful offering at this point, and even its market share has been steadily dropping (it's probably well under 20% by now). If this slide continues, nobody will have any reason to listen to Mozilla. Their influence over the web, already waning, will unfortunately become non-existent.


They might be "hiding" the setting by not including it in the main settings page, but there is no other (mainstream) browser with anything close to the equivalent of the flexibility of about:config.


Though judging by the logic espoused in the tab-close-button bug step one is to move it to about:config and then step two is removing it all together for not being discoverable enough.


Well that's a GUI thing, so it's still available via CSS. Annoying to get to, but configurable.


yes, but they also change about:config "Preference Names" possibly to confuse users so that they stop messing with settings? for example the preference name for the number of lines scrolled when using the mousewheel used to be "mousewheel.withnokey.numlines", I believe it is now "mousewheel.acceleration.factor" ... I didn't keep track of all the changes, but I am sure that there is many others.


Which settings are needed to make firefox preserve my privacy (if there are more things )?


A switch on/off in the preferences is needed (because privacy choices must be easy for everyone) and I'd choose "off", but I think this bit from Google may ease the mind of someone here.

> It’s important to note that any time Safe Browsing sends data back to Google, such as information about a suspected phishing page or malicious file, the information is only used to flag malicious activity and is never used anywhere else at Google.


> and is never used anywhere else at Google.*

* Unless the NSA has asked us to share it with them.

Edit: This is a serious concern. Google's promise not to use this data is completely meaningless in today's world.


There's already a switch in the preferences.


> the information is only used to flag malicious activity and is never used anywhere else at Google.

But does it say the information is anonymized and promptly deleted, and nothing is logged?


It says the following from a post on the Chromium blog from January 2012

"After two weeks, any associated information, such as your IP address, is stripped, and only the URL itself is retained." ( From: http://blog.chromium.org/2012/01/all-about-safe-browsing.htm... )

As a Firefox user, I really think it's poor form on the part of Mozilla to not provide any additional information or re-assurances on their website about the data captured and recorded by Google. Mozilla's slogan on their homepage is "Commited to your privacy and an open web". Being committed to privacy means being open and explicit about the data captured through their browser services, no matter how innocuous the data might seem. It also means presenting that information clearly and making it easy to find. People can then make informed choices about whether they want to use such services.

This is the sort of thing I would have expected them to have said:

"When you download a file from a web page, Firefox checks that the file does not contain a virus or malware before you save it. To check the file is safe to download, Firefox contacts Google to use a service they provide called Safe Browsing. Google checks if the file is harmful or safe, and sends this information back to Firefox (this normally happens in a few seconds). If the file is safe, Firefox will start the download. If the file is harmful, Firefox will block the download and display a warning message.

When Firefox uses the Safe Browsing feature, it needs to send Google information about your download. Google records the following information from Firefox: your IP address, the name of the file you are downloading, the address of the website, and [insert any other data recorded here]. [Also insert a re-assurance that Google does not keep a record of all your downloads against your Google account or against your IP address - assuming this is the case. Also explain how Google uses that info. and how long it's kept for etc.]

[Then finally explain how to switch off this feature if you don't want to use Google's Safe Browsing feature.]"


https://wiki.mozilla.org/Security/Features/Application_Reput...

* 47% improvement in malware detection with the current implementation

* 87% improvement in malware detection possible when the feature is complete

I can see why that trade-off was made.


> I can see why that trade-off was made.

But why not allow users to make their own choice and disable the privacy compromise easily?


They already do? There's a switch in the preferences.


Seems like Mozilla is not following Brendan Eich's plan to differentiate "heavily" on privacy.


https://developers.google.com/safe-browsing/firefox3_privacy... suggests it's not that simple.

They used to use a bloom filter with a regular download list, which would allow local checks without revealing every URL, but it looks like that changed at least for Chrome: https://code.google.com/p/chromium/issues/detail?id=71832


Thanks for pointing that out, I went and did set the url to a blank string as mentionned in their documentation.

(safebrowsing.appRepURL for the curious)


Google's malware scanning service also generates false positives and provides no contact info for submitting an appeal. A little too automated for my liking.


Yeah, really--Mozilla what are you doing? I thought you cared about privacy. :(


This really irks me, where's the best place for us to complain to Mozilla about this?


I don't think that there is a good place to do that, unfortunately.

You could file a bug, but it'll be pretty much lost among the thousands upon thousands of other ones that already exist and haven't been dealt with.

You could comment here or in some other discussion forum, but those in the Firefox community will probably just vote you down, and continue to pretend that there isn't a problem.

You could write an article, but again, that probably won't help much, unfortunately.

The best thing to do may be to find an alternative browser, or use older browsers that aren't broken in this manner.

I just don't think that those working on Firefox these days truly care to listen to what the remaining Firefox users have to say. Time and time again lots of users have loudly expressed extreme displeasure with monumental mistakes like Australis and the removal of useful functionality, only to be totally ignored by the Firefox developers. I don't see why this situation should be any different.



NOT what you downloaded.

but every page. as that service is run for every url. at least it was on aurora.

also, expect network pre-fetch links soon since google also likes that. so they can know what you visited even if you don't click it.


Isn't it checked against a local blocklist?


It's also checked against a remote one unless you either disable the feature entirely or set "browser.safebrowsing.appRepURL" in about:config to an empty string.


The quoted docs actually say that the remote lookup feature isn't even in Firefox 31.


removed google for everything under about:config 'safebrowsing.'




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: