Enhancing Download Protection in Firefox
blog.mozilla.org
blog.mozilla.org
> it is possible that you have been tricked into downloading a malicious file from a phishing site which has not yet been identified as such by the Google Safe Browsing service.
Does this mean that sites that have some kind of personalized downloads or downloads that are created on the fly (like generated PDFs for example, or watermarked content) will always create a warning for the user on download?
As a personal anecdote, my website has been blacklisted multiple times by safebrowsing, downloads have been blocked as "XXX is malicious", multiple AV products have found "malware" in a program that's never even been released before, etc. I have to email 10-20 different anti-virus companies with samples every release and then deal with the ones who want it in a different format or submitted through a web portal instead.
Then we have the problem that contacting any human about safebrowsing false positives is nigh impossible. Take a look at the report right now - https://www.google.com/transparencyreport/safebrowsing/diagn... - "Some pages on this website send visitors to dangerous websites. Some pages on this website install malware on visitors' computers." yet it says "Current status: Not dangerous". And Webmaster tools can't seem to find anything specific: http://i.imgur.com/HzT8xfC.png
I'm not sure if the "Windows 10 Media Creation Tool" also has this problem since it doesn't recognize Sandisk flash drives as being flash drives (presumably Sandisk's fault). If anyone's run it on a computer with Trend Micro I'd be curious to hear.
Do you have actual evidence of this happening? I get no warnings for my own stuff, even though I'm sure it's pretty uncommon :-)
> For example, if you are looking to download a new version of Firefox or a popular software package such as VLC and get this warning
Am I reading to much in to this, or are they doing something clever to only apply this "uncommon downloads" thing for popular search terms?
(This would avoid penalising small producers to)
Internet Explorer continuously blocks them and scares the users away from them.
Neither Firefox nor Chrome trigger a warning on them and seem to recognize them as harmless.
http://www.winprivacy.de/english-home/
https://github.com/10se1ucgo/DisableWinTracking
Now if only they could be incorporated into the standard anti-virus tools...
From the open source one:
"Note: Windows Defender may report the EXE as a trojan (Win32/Pocyx.C!cl), and may therefore prevent you from extracting the EXE to anywhere on your computer. Set up an exclusion in Settings > Update & Security > Windows Defender > Exclusions by adding the folder you intend to extract the EXE to."
Riiiiiiiiiiiiight.
There is somewhat of a logical inconsistency in trying to avoid spyware on Windows 10 that is hopefully explained by lack of knowledge. The purpose of my post is to inform. Not everyone is aware.
http://www.networkworld.com/article/2956574/microsoft-subnet...
One of the sites I frequent has all their torrents marked by safe browsing as malware (mistakenly AFAIK), so ideally I'd like to whitelist that one site without opting out of the feature entirely.
How could they say "This file is not commonly downloaded" without knowing how often it is downloaded?
If they know how often files are downloaded, where are they receiving that information from?
[1] https://blogs.msdn.microsoft.com/ie/2010/10/13/stranger-dang...
[2] https://blogs.msdn.microsoft.com/ieinternals/2011/03/22/ever...
[3] https://blogs.msdn.microsoft.com/ie/2011/03/22/smartscreen-a...
https://wiki.mozilla.org/Security/Features/Application_Reput...
Local database with whitelists and blacklists, file signature inspection, and remote lookup for files with unknown, unsigned binaries in them.
Signature based systems are still useless. And you send more data to google!
(Yes, yes they probably download lists and don't directly send the hash. The lists are most likely still sharded enough to get an idea, as it is with the regular safe browsing crap)
As a minor plus, if you've already disabled the existing blocking options in previous versions of Firefox, then these new ones are automatically disabled.