Is Firefox lying to users about viruses in downloads?
theindy.us
theindy.us
Even if Firefox did a full virus scan, there would still be false positives and false negatives in the results.
The system designer always has to put their reporting threshold somewhere, and that always means making a decision to bias towards false positives or false negatives. Eliminating false positives means exploding the number of false negatives.
Unfortunately, people like the OP don’t understand this, and yell angry things like “Firefox is lying to me!” Others here suggest FF should inject a bunch of weasel words like maybe and could and might. That’s a seemingly rational thing to do if you believe you’re informing a customer population that understands things like false positives and false negatives, but we have pretty clear evidence that they don’t. So FF makes a conscious informed decision to prefer reporting false positives over false negatives and then allows the user to override if they believe they know enough to do so. Sure, there are some costs to false positives, but they are dwarfed by the cost of false negatives.
The "lie" the author was complaining about was that Firefox is miscommunicating what it did: It warned that a concrete file was containing malware when it actually found a suspicious domain.
Depending on context, that might make a huge difference - e.g., if a user got such a warning for a file they uploaded themselves, they might get the wrong impression that their system is compromised.
As the author noted, simply describing the actual threat would clear this up.
> Sure, there are some costs to false positives, but they are dwarfed by the cost of false negatives.
This strategy has blown up a number of times already. If you present too many false positives, users might lose trust in you and ignore your predictions altogether.
I've upvoted you, since I think your point is good, I'd just add that as a developer, I've found myself on more than one occasion pushing for the type of UX being advocated here, and getting pushback from designers/PMs. Typically, the issue I run into is a desire for the UX to be "simple", sometimes simpler than the system underlying it actually is (or is even capable of being), and so instead of clear and correct messaging, you get simplified and incorrect messaging.
(My current example of this would be ZIP codes. People like to simplify them to a geographic area in their heads, and then think of them as polygons, and then from there, think you can ask "is this lat/lng inside this ZIP?"; ZIP aren't polygons (they're defined as segments of roads) so answering that question requires approximations; those approximations are sometimes wrong.)
Designer: This label is required to say what store the user is at given his location.
Developer: the location sensor is imprecise. We could have 20m of precision or worse. The store location data is also known to be inaccurate and incomplete. We can provide top 10 candidate stores with their probabilities. The “top” one we return could be 95% likely or 35% likely. Your move!
Bad Designer: Too much numbers for my brain. We’ll just show the top result. YOLO!
Better designer: We could only show a result if it’s above a certain threshold. Or we could show top 3. Or maybe we need to talk about changing the requirement.
Better developer: There may be other signals and inputs we could use to help make the results more confident...
If I consulted Google Maps and it told me I'm with 48.25% likelihood at address A, with 39.81% likelihood at address B and with 11.94% at another location, what exactly am I to do with this information?
I think Google Maps actually shows a good design to communicate the uncertanity: They show the uncertanity as a blue circle of varying size. It's visual but (more importantly) gives you as a user the ability to reduce the uncertanity with their own information. E.g., if you know you're at an intersection and the circle covers only one, you now have a precise location.
In general, I'd say, it's important to know which context the information is used.
If your machine gets infected you format all because it is insecure by definition. You might even need to throw out physical machine...
If you get one it downloads ten other and you don't know which one will pass your virus scanner.
It is not fun and games anymore, silly nerds having fun are not doing it. It is actual crime and really bad guys that would kill you without blinkink an eye are doing malware.
If there is one infected file on your domain you consider whole domain compromised.
So it is not like this domain hosts one bad file and it got flagged, it is apparently more often if it "sometimes .. is .. lie".
On the other hand if you don't trust then those should be included.
Question is, does Mozilla trust google enough? Does Mozilla trust some random website where people host pirated content?
That is random article written by some random guy. Seems like he is more technical than average Joe, but he does not have any statistics to show why this behaviour was implemented. It just looks like a nag that he get his pirated downloads flagged by Firefox. It is backed up by bunch of people who also use it on /r/libgen. If they don't like it they can move to IE6.
I trust Mozilla more than some pirated content website or their user.
If you need that content more than you are afraid to be hacked and understand risks involved you are good to go.
People who are not aware of that threat need to be warned. Telling nicely does not work and people will click OK without reading.
Just as I wrote it is not fun and games and magic unicorns from internetz are not giving latest movies/programs for free.
Yes it is censorship, but as I wrote if you understand the risk and know what to do you will find your way to download it without firefox.
It's just a huge annoyance with no considerable benefit.
Having said that, I do agree that browsers shouldn’t implement lots of crazy features but I personally don’t mind if they have some kind of malicious file scanning feature.
Browser.safebrowsing.malware.enabled
Just set it to false IF you consider yourself a poweruser.
IIRC, Chrome does the same thing too. I think it's not much of an issue for Firefox to flag stuffs downloaded from suspected URLs as a malware since it's not uncommon to have one's system infected from those sites' content. Firefox is just trying it's best to prohibit any sort of system infection through itself.
In that case I would change the wording from "contains malware" to "may contain malware".
Also, they're prohibiting nothing. They still give you the option to open the file (which, as explained by the article, opens a whole different, albeit small, can of worms)
Or even more precise: "may contain copyright infringement".
Their (and chrome's) current solution to block malware domains use a client-side bloom filter afaik.
If you'd try to build the same client-side into firefox, you'd have just built another (bad) antivirus software.
Might as well integrate clamav into firefox then.
* Privacy
* Performance
* They would likely have to work with Virus Total to support their infrastructure as I can only imagine how quickly they'd take such a cloud service offline if everyone started using it by default
* And then what happens if / when the cloud service does have an outage? Does that mean people are blocked from downloading things?
* Same question for people on a corporate network who might have Virus Total blocked
* Same question for people on poorer internet connections as now the user has to transfer twice as much data if it's not a hash already stored on Virus Total.
That all said, its a cool idea for a third party browser add-on (if it hasn't already been done?)
_Privacy: They [FF] can act as anonymous proxy.
_Perf: Yes, for new objects, but for known objects, it should be minimal.
_Service outage: Build a system which can allow an override (download at your own peril, while service is out)
_Corp should already have enterprisey systems in place
_New, unknown object: Yes an issue.
As someone else said [GlitchMr], if they can do it ala haveibeenpowned I think it's worth looking into.
I think he's talking about the file contents.
Wait, why am I not using Chrome then in the first place?
The way that their library database works is by linking a book number to a file's md5 sum. On the filesystem they are stored something like `$drive:\$batch\$sum` where `$drive` is a Windows drive letter, `$batch` is the primary key of the document rounded to the nearest 1k, 10k or 100k depending on collection and `$sum` is the `md5sum` of the file data. The archive's file data is shared via torrents, usenet and other means in those batches, and to keep that in sync they have a policy of the primary key and sum of each file being immutable.
So if you do happen to download the literary works of mankind via their torrents, you have to do so with your antivirus turned off and hope nobody has uploaded anything too illegal over the last decade.
But Windows Defender quite rightly still quarantines the file.
It's going to be rarer to find something of that scope, maybe even to the point of you being effectively right.
Here is an example file: https://we.tl/q90gXERGmx
If there's an uncertainty in detection, there are false positives and letting the user decide is the only correct option.
Edit: Nevermind. Re-reading the article - they should indeed allow saving the file in addition to deleting or opening it.
browser.safebrowsing.malware.enabled=false
And if you don't want phishing warnings either: browser.safebrowsing.phishing.enabled=false
Guess it's the same for IE - i've had a few issues with executables that probably don't see many downloads...
...no, i don't use it voluntarily - but sometimes have to at work...
So, spoiler: it's a bit more nuanced than "yes" or "no".
I can understand the reasoning behind this, I've seen it done multiple times to my own projects by the UX guys. I don't really know if it's net-positive strategy or not, but the fact that there is a lie involved at some level is undeniable. At least to those who didn't drink too much Kool-Aid and don't think the average user is too stupid to comprehend the truth, and therefore that it makes no sense to present it to the users.
I may be biased in the other direction, but every time I see a discussion about "dark patterns" in UI I get a feeling that they differ from the "light" ones only in what is the goal of the manipulation, but with methods surprisingly similar on both sides.
As a user, I want to be better safe than sorry - but would perhaps be happier with a finer classification than "no problem/OMG VIRUS!"
In other words, in my opinion, don't cry wolf unless there's an actual wolf, or at least something that could reasonably look like one.
https://web.archive.org/web/20180704124718/https://www.thein...
https://webcache.googleusercontent.com/search?q=cache:https:...