Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Privacy Businesses Google The Internet Your Rights Online

Firefox 3 Antiphishing Sends Your URLs To Google 296

iritant writes "As we were discussing, Gran Paradiso — the latest version of Firefox — is nearing release. Gran Paradiso includes a form of malware protection that checks every URL against a known list of sites. It does so by sending each URL to Google. In other words, if people enable this feature, they get some malware protection, and Google gets a wealth of information about which sites are popular (or, for that matter, which sites should be checked for malware). Fair deal? Not to worry — the feature is disabled by default."
This discussion has been archived. No new comments can be posted.

Firefox 3 Antiphishing Sends Your URLs To Google

Comments Filter:
  • by lecithin ( 745575 ) on Tuesday September 25, 2007 @01:35PM (#20746655)
    Does anybody remember Google Web Accelerator? This also came out with the 'selling point' that it would help the customer:

    http://slashdot.org/article.pl?sid=05/05/04/2223238&tid=217 [slashdot.org]

    Google has your mail. They have your searches. Now they are going for your browsing history.

    Add it all together and you have a lot of business intelligence. Time to target consumers and influence opinions?

    Smart yes, but still quite scary.

    What information are they going to collect next? What are they doing with all the information that they are already collecting?
    • by cephalien ( 529516 ) on Tuesday September 25, 2007 @01:39PM (#20746707)
      This isn't news. ANY anti-phishing tool that checks to see if a page is a phishing site is going to have to send it SOMEWHERE... or did you think that they were just going to be able to magically download a tiny file on your computer that would just 'know' all the phishing sites?

      They all do this, which is why I don't use them. Some common sense will tell you if a site is phishing. If you try to go to a bank website and get http://bank-0-am3rika.tv/l0g0n [bank-0-am3rika.tv], then you might want to reconsider putting in your username and password.

      Silly sensationalism. nothing more.
      • by TorKlingberg ( 599697 ) on Tuesday September 25, 2007 @01:48PM (#20746841)
        How about http://www.bankofarnerica.com/ [bankofarnerica.com]?
      • Re: (Score:2, Insightful)

        by Seumas ( 6865 )
        Or a solution could just require downloading a database on a regular basis and then comparing the uRL to that database locally on your own machine.

        Aside from the privacy issue, I simply wouldn't want to double the web traffic on my system.
      • ANY anti-phishing tool that checks to see if a page is a phishing site is going to have to send it SOMEWHERE... or did you think that they were just going to be able to magically download a tiny file on your computer that would just 'know' all the phishing sites?

        Um, downloading a definition file isn't exactly magic. Anti-virus companies have been doing it for years. So yes, actually, I would have expect that every few days my browser runs off and gets the latest phishing definition file (maybe every ti
        • Re: (Score:3, Interesting)

          by FuzzyDaddy ( 584528 )
          So yes, actually, I would have expect that every few days

          Given that the phishing site goes up when the spam goes out, you'd want information much fresher than that. I imagine a phishing site's only good for a few hours after you send out the "bait". I occasionally check out phishing sites I get in my spam, and it seems that a lifetime of a few hours is typical. I think the banks/etc. are getting faster at getting them taken down.

          • Even a centralized database is going to suffer from the time problem. Either way, the site has to be discovered, and an entry created. If the lifetime of a phishing site is measured only in hours, it is not likely that it will get into the database before it goes offline.
            • If a comment on slashdot can post in a few seconds, surely an online database can update phishing websites that quickly. Site discovery is easy, from one of the hundred million spam emails with links to the site.
    • by cromar ( 1103585 ) on Tuesday September 25, 2007 @01:42PM (#20746751)
      Also, they can already collect some of (if not a lot of) your browsing history by checking the IP making requests to Google Adwords, if I'm not mistaken.
  • Well.. (Score:2, Insightful)

    by El Lobo ( 994537 )
    Considering that Google is one of the major sponsors of FF, I'm not amazed. Sending the addresses to Yahoo, or MSN, well THAT would be newz.
    • Re: (Score:3, Interesting)

      Considering that Google is one of the major sponsors of FF, I'm not amazed. Sending the addresses to Yahoo, or MSN, well THAT would be newz.

      Like every other feature I think you should be given the option of choosing where you get taken to, if anywhere. For example if I have my own anti-phishing web site then I should be able to choose that.

      I support Google for many things, but I am getting more insecure about their privacy issues.
  • by tgatliff ( 311583 ) on Tuesday September 25, 2007 @01:37PM (#20746683)
    My thought would be if a master list exists for someone to put up a master site that does not keep up with the information, and put a patch into Firefox to have it pull from this site...

    There is no secret to why Mozilla Firefox wants this feature. I suspect Google has agreed to pay then for the feature to be in Firefox, as I would think this data would be quite lucrative....
  • Not new. (Score:5, Informative)

    by garbletext ( 669861 ) on Tuesday September 25, 2007 @01:37PM (#20746687)
    This is a non-story. The ability to ask google about phishing has existed since 2.0, and was disabled then as well. Not that telling google every site you visit is a good thing.
    • Re:Not new. (Score:4, Insightful)

      by griffjon ( 14945 ) <GriffJon@NoSPAM.gmail.com> on Tuesday September 25, 2007 @01:47PM (#20746827) Homepage Journal
      Is this any worse than IE7, which sends the same to M$? At least Google servers are likely to respond in a more chipper fashion than M$'s, which at times have been noticeably slow, such that I turned AntiPhishing off for some newbies I'd activated it for
    • No kidding (Score:4, Informative)

      by Kelson ( 129150 ) * on Tuesday September 25, 2007 @03:22PM (#20748045) Homepage Journal

      The article is about as informative as one of those "Your computer is broadcasting an IP Address!" banners.

      For the record:

      • As you point out, Firefox 2 already does this, and it's disabled by default.
      • IE7 does the same thing with servers at Microsoft. Disabled by default, but strongly encourages you to turn it on.
      • Opera 9 does the same thing with servers at Opera. Enabled by default, IIRC, but can be turned off.
      • Isn't Safari 3 supposed to get similar anti-phishing capabilities?
    • Re:Not new. (Score:4, Informative)

      by Anonymous Coward on Tuesday September 25, 2007 @05:22PM (#20749509)
      Firefox 2 indeed has such a setting.
      [ ] Tell me if the site I'm visiting is a suspected forgery
            (*) Check using a downloaded list of suspected sites
            ( ) Check by asking [Google] about each site I visit

      And heck, when I try to enable Check by asking Google... a window asking me to accept or reject the terms of service comes up! It says exactly this:
      "If you choose to check with Google about each site you visit, Google will receive the URLs of pages you visit for evaluation. When you click to accept, reject, or close the warning message that Phishing Protection gives you about a suspicious page, Google will log your action and the URL of the page. Google will receive standard log information, including a cookie, as part of this process. Google will not associate the information that Phishing Protection logs with other personal information about you. However, it is possible that a URL sent to Google may itself contain personal information. Please see the Google Privacy Policy for more information."
      With two choices, accept or reject the terms of service, or I can cancel and it leaves it on my previous setting.

      I wonder if Firefox 3 does the same, eh?
  • by nweaver ( 113078 ) on Tuesday September 25, 2007 @01:40PM (#20746719) Homepage
    A "blacklist" of phishing sites needs to be stored somewhere, and you need to be able to do queries against it.

    It changes too fast, and is too large, for it to be stored locally.

    So SOMEBODY needs to provide a database interface to it, and unless you are willing to tolerate the voodoo cryptography and serious performance penalty to do privacy-preserving searches, how else is this supposed to be done?
    • by Schraegstrichpunkt ( 931443 ) on Tuesday September 25, 2007 @01:56PM (#20746949) Homepage
      You could do it by providing a bloom filter the browser, and then when there is a match, the browser could download a certain subset of the blacklist to verify that the match is not a false positive.
      • by nweaver ( 113078 )
        Good idea. You'd have to stick to just the top level name and/or IP, but that would work.

        I like it.

    • by tknd ( 979052 )

      You can also say that the internet "changes too fast" and is "too large, for it to be stored locally" yet we don't have a single service provider solution for the internet as a whole. Rather it is a network or a collection of systems.

      One alternative is to try the peer approach. It works exactly as it does in real life. You often find people asking friends about recommendations and experiences with various things like restaurants. The same concept can be applied to websites but done internally by the sof

    • by RonnyJ ( 651856 )
      Well, you could hash the URL into a non-unique identifier, and send that identifier to Google.

      Google could then look that up in their database, then return known phishing URLs hashed with another method. The browser could then check to see if the URL also matches with the second hash returned.
      • by nweaver ( 113078 )
        Thats what the Bloom filter suggestion was, but the bloom filter is better because its a small amount of data you store locally, and then only do you send a query to google.
  • Why the concern? (Score:4, Insightful)

    by Aranykai ( 1053846 ) <slgonser@g m a il.com> on Tuesday September 25, 2007 @01:43PM (#20746757)
    Why is everyone so concerned about a company having their URL history? I mean, they already have your searches(google), your email(gmail) and your documents(google docs), what does it matter?

    What will this mean? Probably that google will continue to improve their search engines, their advertising programs and other services, and they will all stay free.

    Damn, go smoke some more pot, your not paranoid enough.
    • Why is everyone so concerned about a company having their URL history? I mean, they already have your searches(google), your email(gmail) and your documents(google docs), what does it matter?


      Why is everyone so concerned about criminal activities online? they already deal with drugs, arms, extortion, waste recycling...
    • Why is everyone so concerned about a company having their URL history?


      Because they do evil.
    • Re: (Score:2, Funny)

      by bulldog060 ( 992160 )
      i think the biggest concern is coming up from 2 groups, 1st group is obviously the people that think it is all a big plot to control them, and the 2nd would be people that put alot of effort into hiding there pr0n/online dating habits from their spouses or authorities starting to get nervous about another way for them to get caught
      • i think the biggest concern is coming up from 2 groups, 1st group is obviously the people that think it is all a big plot to control them, and the 2nd would be people that put alot of effort into hiding there pr0n/online dating habits from their spouses or authorities starting to get nervous about another way for them to get caught

        Or how about the US Government deciding to execute a gigantic dragnet and grab everyone who has read Al-Jazeera and posted something somewhere that says that "we deserved to get

        • Or how about the US Government deciding to execute a gigantic dragnet and grab everyone who has read Al-Jazeera and posted something somewhere that says that "we deserved to get bombed" - which I've seen on this site here many times.


          See #1. Or refer to "paranoid nutcases."
    • Why is everyone so concerned about a company having their URL history? I mean, they already have your searches(Google), your email(gmail) and your documents(google docs), what does it matter?

      coming soon to a web browser near you it's GSoul. Why sing away your should to just anybody. Choose the best. Choose Google*!

      *offer void where prohibited. Google promises not to do anything it considers evil with your soul. Google reserves the right to eat your soul. In the states of Utah and Nevada Google may also take
    • by chill ( 34294 )
      It gives Google the ability to determine exactly which "escorts" listed on Craigslist I perused before settling on the cute little Latina who promised multiple language lessons. :-)

      Give me your URL history, combine it with your online purchase and reading history and a decent psychologist (or psych AI) can probably tell you what color shirt you are wearing today.

      The government understands this theory. It is why you can certain FOI requests get denied and others allowed. Not that the information you are re
    • The concern. (Score:5, Insightful)

      by Kadin2048 ( 468275 ) * <slashdot@kadin.xoxy@net> on Tuesday September 25, 2007 @02:35PM (#20747453) Homepage Journal

      Why is everyone so concerned about a company having their URL history? I mean, they already have your searches(google), your email(gmail) and your documents(google docs), what does it matter?
      Because it's another thing the authorities can subpoena -- or just take, without all that messy paperwork -- and comb through to find things to go after you with.

      The way the laws are these days, even if you're Mother Teresa, you're probably doing something illegal, even if you don't think of it as illegal or even realize it. (Ever downloaded VLC or Handbrake? Bought discount smokes? Played a little online poker? Bought something without paying your state's sales tax?) Sure, the FBI normally has bigger fish to fry than you and me, but there's no reason that'll always be the case. The tools that are used for terrorism now will be used for narcotics tomorrow, and copyright enforcement the day after that, and eventually it'll trickle down until it's being used against something you're doing. And information compiled in databases has a tendency to stick around (at least, when it's not being misplaced or stolen). Your browsing habits today could come back to seriously haunt you in a decade or two.

      And it's not just the government that you have to worry about, or Google's official policy as a corporation. You also have to consider how much the people who actually deal with this data are paid. How much would it cost to get one of them to give someone malicious access to the database? A whole lot less than the database would be worth, I suspect. Even if you're not doing anything illegal (which, again, I doubt; most people break a half-dozen laws before they get to work in the morning), you're a rare person if there's not something going on in your life that you'd prefer to keep private. Medical conditions, sexual preferences ... it all sounds like good opportunities for extortion to me.

      There aren't really any analogues in the pre-computer world to the size and scope of databases like Google's, in terms of both the breadth and depth of information it could contain on individuals. This is not something that we have much societal experience with, and the limited track record we do have is decidedly mixed. It's not especially paranoid to want to take a "wait and see" approach.
    • Well, this will probably just get me labeled as a "tin-foil hatter" but here goes.
      The main point of maintaining my privacy, in regard to what I read, is simply the fact that I have no way to know what may later be deemed "undesirable". Do I think that "they" are out to get me? No. But I have read enough history to realize that, if we are ever unlucky enough to have a government, or persons within our government who were interested in suppressing a particular group or point of view, that they will quickl
    • by Ogive17 ( 691899 )
      Replace 'Google' with 'government' and you'd be crying 'foul.'
  • Already there (Score:5, Informative)

    by Todd Knarr ( 15451 ) on Tuesday September 25, 2007 @01:44PM (#20746781) Homepage

    It's already in the version of Firefox I'm using, 2.0.0.6 downloaded directly from Mozilla's web site. In fact you've got the choice to enable it or leave it disabled, and if you enable it you've got the choice between downloading a list and doing the check internally or checking each URL interactively with a service (currently Google's the only one in the list, but more could easily be added).

    • Re: (Score:3, Interesting)

      by ivan256 ( 17499 )
      If you're going to do it interactively, why not use a hash of the URL (or the domain name/port) instead of sending the URL itself? Then even with live checking, google would only know which sites you went to if they were a match in their list of bad guys.
      • Re:Already there (Score:5, Interesting)

        by Todd Knarr ( 15451 ) on Tuesday September 25, 2007 @02:06PM (#20747075) Homepage

        Because http://thief.com/login.html [thief.com] and http://thief.com/Login.html [thief.com] both hash to radically different values, but both have in the plaintext a characteristic fingerprint of a phishing attempt. A service that gets the plaintext can trivially identify both, but a service that only gets a hash would be fooled by the second if it only had seen the first before.

        • Bah. SlashDot mangled the URLs, there's supposed to be a "www.bankofamerica.com@" in front of the "thief.com".

  • Oh my GOD! (Score:5, Funny)

    by gowen ( 141411 ) <gwowen@gmail.com> on Tuesday September 25, 2007 @01:45PM (#20746785) Homepage Journal
    Google are going to find out what websites are popular. That's information that they simply couldn't otherwise find out unless they ... oooh ... operated the world's most popular search engine.

    Everybody panic!
    • Re: (Score:3, Insightful)

      You laugh, but there is a difference between knowing which topics people search for and consequently which one they go to when presented with a list of sites related to that topic, and knowing the sites people go to directly and how often they do it.
  • by revery ( 456516 ) <charles@c[ ].net ['ac2' in gap]> on Tuesday September 25, 2007 @01:45PM (#20746793) Homepage
    Breaking news: Cheese gives you cancer!!

    Oh wait, no it doesn't... You might still get cancer though...
  • by Ungrounded Lightning ( 62228 ) on Tuesday September 25, 2007 @01:46PM (#20746809) Journal
    Fair deal? Not to worry -- the feature is disabled by default."

    But does the "enable" interface inform the user that Google gets their browsing history as a side-effect of providing the blacklist?
    • by ronanbear ( 924575 ) on Tuesday September 25, 2007 @02:01PM (#20747029)
      Actually, it does explain it pretty well on FF2. If they changed that it would be news.
      • by xlv ( 125699 ) on Tuesday September 25, 2007 @03:39PM (#20748281)

        Actually, it does explain it pretty well on FF2. If they changed that it would be news.


        FYI, here's the text in the popup for Firefox 2.0.0.7:

        If you choose to check with Google about each site you visit, Google will receive the URLs [google.com] of pages you visit for evaluation. When you click to accept, reject, or close the warning message that Phishing Protection gives you about a suspicious page, Google will log your action and the URL of the page. Google will receive standard log information [google.com], including a cookie, as part of this process. Google will not associate the information that Phishing Protection logs with other personal information about you. However, it is possible that a URL sent to Google may itself contain personal information. Please see the Google Privacy Policy [google.com] for more information.

  • Hash (Score:2, Insightful)

    by Arthur B. ( 806360 )
    Why not send a hash with a salt ? It makes it fast to check if the url is in the malware blacklist but if Google wants to know the list of websites you visited, they have considerably more work to do. You could also send fake hashes along each request.
    • Salt won't help you. (Score:5, Informative)

      by SanityInAnarchy ( 655584 ) <ninja@slaphack.com> on Tuesday September 25, 2007 @02:08PM (#20747101) Journal
      Salt helps for things like passwords, where two users with the same password will have it appear differently in the password file.

      It makes no sense here. It would prevent a third-party from intercepting your browsing history -- but then, they can do that anyway, by simply being your ISP.

      But if Google has the list of malware sites, obviously they know that foo.com resolves to a particular hash (with a particular salt). The only way this could possibly work is if Google stored a separate list for each user, each with its own salt, which would still require you trusting Google to be doing this and not to be keeping a mapping of hash+salt -> website.

      There is no way hashes can solve this problem. The only solution is to either be smart, so you don't need a blacklist, or to download the entire blacklist periodically, which is an option, but not everyone likes it.
  • Why does this need to be included by default? Am I the only one who finds the anti-phishing stuff to be annoying? Fine, some people want it, make a plugin or an extension, but stop adding tangential stuff to the codebase! Adding a piece of "functionality" to a web browser that does a name check on every website you load is bound to add a huge chunk of overhead.

    Am I the only one who remembers The Kitchen Sink [mozilla.org]? Adding stuff like this into a pure vanilla install is ridiculous. I don't care if they want to make
    • Re:Oh joy. (Score:4, Insightful)

      by moore.dustin ( 942289 ) on Tuesday September 25, 2007 @02:35PM (#20747455) Homepage
      The people who have no idea about about extensions and plugins(the average user), are the people who want the anti-fishing features. Being the more advanced user, it is far easier for you to turn it off than it is for the average user to seek, install, and maintain(update) a plugin.

      I would agree that it is annoying for me as well though - I do not need the help of the browser to ward off phishing, especially at the cost of a performance hit. That said, Firefox is not a pet project of the geek world anymore. FF is aggressively seeking the mind and market share of the everyday user, so they must produce a product those users want. Outside of security, what is the real benefit of abandoning IE6 and more importantly IE7? Pages rendering correctly/standard compliance is not an issue with the average user, not in the least. So that only really leaves security, interface/usability, and I suppose can throw in the great extension selection as a motivator to switch as well. This is a move in the direction of better security to offer its users who value it.
  • wait aint this the same google that pays people per firefox download (thats conveniently bundled with google toolbar which sends every url to google)...
  • I thought only MS could be evil. Well, Google, too. Now, you are telling me that open sourcers are evil, too? Now, how many of you that use WordPress...wait, firefox...dug into the code to find that out? Hands? Anyone? Anyone? Bueller? Nah, didn't think so. But, I bet a number of you upgraded. Doesn't matter, closed or open, you're argument about security is bogus unless you crawl through the code, otherwise, it might as well be closed.
    • Fact is, I don't have to, because a LOT of people already have -- the people responsible for developing and shipping Firefox, for example.

      "May as well be closed"? Maybe, if no one outside the development team looks at it. But the difference is between a diverse development team, everyone paid by a different group, some not paid at all for their Firefox work, and a single, homogeneous team, working for one company, who may not even care what spyware goes in.

      By the way, if you'd bothered to check, this featur
  • Get a clue (Score:2, Insightful)

    by Anonymous Coward
    Edit > Preferences > Security > Tell me if the site I'm visiting... >

    [X] Check using a downloaded of suspected sites
    [ ] Check by asking [Google, .. oh no other one in this dropdown] about each site I visit.

    Also saves your bandwidth.
  • by lowy ( 91366 ) on Tuesday September 25, 2007 @01:57PM (#20746961) Homepage
    It seems to me that the users who most need anti-phishing protection are the ones least likely to change their defaults.
  • Because the people who put it in FF are acting like idiots by assuming average users are dumb and won't learn a couple of simple instructions. Hence, the idiots (i.e. many people in IT) don't even bother to suggest proper URL usage and instead concoct convoluted and invasive crap based on what a central authority considers socially acceptable for web browsing (and don't tell me the blacklist won't be expanded beyond suspected phishers-- you know it will).

    The best thing they could do, IMO, is to render every
    • First, realize the feature is disabled by default, and can be enabled without sending your browsing history to Google. Also, it's fairly likely it will let you visit those sites, it'll just prompt you first.

      Because the people who put it in FF are acting like idiots by assuming average users are dumb and won't learn a couple of simple instructions.

      Actually, they are, intelligently, realizing that your average IT department doesn't have the resources to educate users properly, and some of those users are fu

      • by Burz ( 138833 )
        Having it disabled by default is one saving grace, I will admit.

        But we are certain to hear techies ramble on to their acquaintances about clicking that checkbox in preferences, instead of telling them to keep looking at the domain (the latter being the only way to truly safeguard yourself in the longrun anyway).

        Any IT dept who pushes this is stupid, because they are leaking internal employee activities to an external site.

        and some of those users are fundamentally un-educatable.

        Then you are part of the problem, and given your level of knowledge implied by your p

  • Did I miss the memo? (Score:5, Informative)

    by LMacG ( 118321 ) on Tuesday September 25, 2007 @02:04PM (#20747053) Journal
    Is this tin foil hat day or what? This isn't a new feature in FF3, it's already in FF2.

    Wait, maybe it's sending server dumps and some developer said "if you don't like it, fork it." That must be it.

    Do we get a "this is a non-story" correction to this post too?
  • ...accessing the list through TOR?
  • This blog post from a few years back explains how/why one might run a system like this: http://blogs.msdn.com/ie/archive/2005/08/31/458663.aspx [msdn.com] (blogs.msdn.com)
  • This feature is available in FF 2, and is disabled by default, and as has to modes of enablement, only one of which sends data to Google? So now people shouldn't even be allowed to choose to send their data to Google? Does kdawson and iritant not use Firefox and see this feature here for ages now?
  • This is something that is OK if you choose to add it, to put it in the actual firefox deliverable is not OK, even if it is off default.

    Plus as people are pointing out, why the #!()%/)#(/%(#/! is it sending info *to* google? You should retrieve an updated list of those sites to *your* computer where it is checked. Imagine what they could do with this technology in let's say... China? Yes, not so much fun anymore is it? How about the feds?

    How come the Firefox developers came to agree to this in the first plac
  • Just do a Google search for "Ad-Aware" or "Spybot" and check out how many of the sponsored links are actually links to scam or malware programs masquerading as these spyware cleaners.

    Until Google stops doing business with outright criminals, I'm not going to trust them to tell me who is a criminal and who is legitimate.
  • Wow, just wow... (Score:4, Insightful)

    by GarfBond ( 565331 ) on Tuesday September 25, 2007 @03:11PM (#20747893)
    This is a *really* bad submission. It's wrong on so many fronts.
    1. As others have pointed out, there's nothing innately wrong with using Google for antiphishing. They have a large userbase, and can easily detect a mass of users flocking to a really sketchy site. Would it be a huge deal if they plugged into PhishTank [phishtank.com]?
    2. The submission does reflect this, but the feature isn't on by default. Instead, Firefox appears to use a static master black list that it redownloads periodically.
    3. I can't trigger it now, but I'm pretty sure that you're asked to confirm when you select Google that you're aware of the URL sending and other various privacy implications. The user will not be uninformed when they make this choice
    4. The feature is already present in Firefox 2. It is not new to Firefox 3. It's been well publicized before, and there haven't been any major problems since.
    This is a pretty stupid low to go for some anti-Google hits.
  • by Torodung ( 31985 ) on Tuesday September 25, 2007 @03:47PM (#20748423) Journal
    I am legitimately not trying to troll here.

    Could Slashdot editors please have a group discussion about accuracy and integrity in journalism? First it was the WordPress piece, that was rightly amended, and now there's this. Both deal with a fear that "someone" is spying on us. Anyone who deals with computer security deals with that fear on a regular basis, but those fears should not be expressed in the journalism: Facts should.

    As many have mentioned, this feature can be found in the Firefox 2.0.0.7 security tab under "Tell me if the site I'm visiting is a suspected forgery." The summary is flat-out misleading, and contains links to a general page about all Firefox 3 features (which does not mention Google in the slightest), and the entire discussion about Firefox 2 memory leaks, not the relevant posts the author seems to reference.

    There literally is no "FA" to "R" in the first place, and the summary is inaccurate, not only in its facts, but because it is summarizing nothing.

    This editorial behavior gives Slashdot a bad name, and moves it a step towards the irrelevancy of The National Inquirer. I've been bringing buckets of salt to take with this site in the past weeks, and would like to see these trends reversed.

    Please discuss it.

    (I've shut off the Karma bonus on this post, it should fly on its own merits. I'm not posting "AC," because if I'm out of line here, I'm willing to pay the price for it.)

    --
    Toro
  • Well... (Score:4, Insightful)

    by Jugalator ( 259273 ) on Tuesday September 25, 2007 @06:27PM (#20750111) Journal
    It's kinda hard to verify URL's if you don't compare them to a massive database.

    Is anyone surprised? How is it evil? The evil would only come from the data being misused. Obviously they NEED the data, or rather, the dudes running the database need it. That's not the evil part.
  • by Animats ( 122034 ) on Tuesday September 25, 2007 @07:22PM (#20750575) Homepage

    It's not really enough to just check the URL against some phishing database. The phishing sites now use unique URLs for each phish going out. Some even use unique subdomains. An example is http://onlinesession-949076872.natwest.com.nigy3r.cn.

    We've been struggling with this for SiteTruth [sitetruth.com], which, among other things, uses PhishTank's data. Originally, we used PhishTank's online query API, but that required an exact match on the URL, which was useless. Now we download their entire database every few hours and blacklist the entire base domain (what you buy from a domain registrar) if there's a verified, active phishing site anywhere in the domain.

    That seems reasonable enough. But there's collateral damage. So, most days, we have AOL, Microsoft Live, and Yahoo blacklisted. That's because those major sites have "open redirectors" - URLs which will redirect to any specified site. For example,

    • http://r.aol.com/cgi/redir?http://mgw1.haoyisheng.com/icons/asp.html
      A convenient, easy to use redirection script popular with phishers. Provides a URL that appears to be on AOL, but isn't. Interestingly, AOL treats as spam any email that uses their own redirector URL. [aol.co.uk] So it's only useful for attacking non-AOL users.
    • http://login.live.com/logout.srf?ct=1179231565
      &rver=4.0.1532.0&lc=1033&id=64855
      &ru=http:%2F%2Fby117w.bay117.mail.live.com%2Fmail%2Flogout.aspx%3Fredirect%3Dtrue
      %26logouturl%3Dhttp:%2F%2F62.49.9.117:443/HB.onlineserv.cgi/

      The "logout" page for Microsoft Live can be abused, with some effort, to make it appear as if some hostile site is on Microsoft Live. This looks like Microsoft tried "security through obscurity" and failed.
    • http://rds.yahoo.com/_ylt=A0Je5VTi9_RDDbAA3TJXNyoA;
      _ylu=X3oDMTE2ZXYybGFuBGNvbG8DdwRsA1dTMQRwb3MDMQRzZWMDc3IEdnRpZANpMDIxXzQ3/SIG=15j5u6auo/
      EXP=1140214114/**http://hticketing.com/www.bankofamerica.com/sslencrypt218bit/online_banking/

      A Yahoo redirector URL intended to create the illusion of a Bank of America site. It may be possible to exploit this as a cross site scripting attack. [xssed.com]

    These were all active phishing sites an hour or two ago.

    Yes, arguably the intelligent user should be able to visually parse the URLs above and realize that they're not really on the sites indicated. Or notice that a redirection took place. But most users don't notice that. Neither do many anti-phishing tools, especially if the attacker combines both techniques described above.

    Phishing has reached the point that if you have an open redirector or proxy on your web site, someone will use it to borrow your reputation for their scam. Open redirectors are now like open mail relays - a nice Internet feature that had to be shut down because of exploits.

    So fix those open redirectors, people, or expect to be listed as a phishing-friendly site.

Don't get suckered in by the comments -- they can be terribly misleading. Debug only code. -- Dave Storer

Working...