Apple redirects Google Safe Browsing traffic through proxy servers in iOS 14.5
the8-bit.com
the8-bit.com
Apple's products are only private if you want privacy from their commercial competitors. If you want privacy from Apple or the US federal government to which they provide tons of user data (without warrants(!) or due process), you're in for a constant uphill battle.
Using everyday devices should not be creating hardware-serial-linked permanent records that the state can download at any time; to me that's stuff of a true dystopia.
Apple has not yet integrated this viewpoint, and seem to regard privacy as only important against companies that aren't Apple. Device backups (full message history and attachments), as well as Photos stored in iCloud, are not end to end encrypted permitting Apple (and by extension the state) to read and access all of it without your involvement.
It's a bummer they're extending this attitude to browser-related traffic too. There seems to be a new trend inside of Apple that they're still figuring out here (see also: the addition of ContentFilterExclusionList in 11.0, and then its quick removal in 11.2).
Did you know that if you entirely block access to all Apple hosts, you can't even add a Gmail account to an iPhone?
Push notifications can't be implemented otherwise... so you'll have to trust Apple for that one.
Mozilla Push Service is the Mozilla equivalent for example. Push notifications are an expected feature of every device nowadays, routed through a server owned by the OS/browser provider by design.
Also, locally running apps can trigger their own notifications.
On a fresh install you have Software Update, News, Safari, iTunes Store, App Store, Stocks, etc. which are all going to be a part of polling for available push notifications. When a new device update releases you will get a notification about it, even without an Apple ID signed in.
Yes, locally running apps can trigger time-based notifications but all network-based notifications should be handled by Apple's push services as iOS doesn't allow long-term persistent background tasks due to battery drain and it doesn't make sense for every app to have its own individual polling occurring at random times.
>A new study has found that a stationary iPhone sends data 50 times less frequently to Google's servers than a stationary Android phone.
That's according to a 55-page report titled 'Google Data Collection', carried out by Professor Douglas C Schmidt, professor of computer science at Vanderbilt University.
The study comes as Google faces criticism and now a lawsuit over the revelation that turning off Location History does stop it tracking iPhone and Android users' location.
https://www.zdnet.com/article/want-google-to-track-you-less-...
>According to a research paper published by Vanderbilt University's Professor Douglas Schmidt Aug. 15, Google’s Android phones are sucking information from your private life at a much higher rate than Apple’s iPhones — almost 10 times more, on average.
https://www.tomsguide.com/us/android-privacy-vs-iphone,news-...
In what ways do you think your point is relevant to this article?
There's a growing list.
You and I want true e2e everything. We have our encryption keys backed up safely. We make ourselves enter our passwords regularly enough that we can't forget them. We willing and capable of taking full responsibility for protecting our data. You and I are not like most people. They don't want to be bothered with "all that nerd stuff". They just want all their photos to magically show up on all their devices, and to have a support person they can call to let them in when they've forgotten their password for the second time this year. That doesn't mean those people are less intelligent, or ignorant, or any of that. It means they have different priorities than you and I do, and their priorities are absolutely reasonable and appropriate for most people. They look at us and say "WTF, those guys don't work for the CIA. Why are they so obsessed with protecting their recipe collection and text messages, at the risk of losing all their data if they forget a password?" And frankly, that's a completely OK and normal mindset.
Apple's privacy stance is the correct one for the market they're trying to sell to. I personally think your and my privacy stance is better, but most people would reasonably say it's impractical given the threat model we actually face. I'm OK with that because I like doing these things for myself as a hobby, but I don't think Apple has made a bad or unjustified decision. They just different priorities than we do.
This is a false dichotomy.
Apple had invested significantly in doing a form of key escrow with trusted other devices and other users, possibly involving secret sharing with trusted friends-and-family, that would permit users to have end-to-end encrypted data that could still be recovered without Apple having keys.
The FBI nixed the plan, and Apple obeyed.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Apple employs tons of world class cryptography experts, and has designed several end-to-end cryptosystems, and is perhaps the foremost leading expert organization on what comprises good UX "for the rest of us". This is a solvable problem, and the "they can't do e2e because" excuses that people throw up (such as the one you provided) fall down when we see that they had a system ready to go that was ended on the initiative of those who would prefer surveillance.
Even Google figured out a way to do e2e device backups for Android in a privacy-preserving way. Apple is at least as competent as they are at designing cryptosystems, possibly more so.
The technical issue can be solved, but not as long as Apple doesn't want to upset the FBI.
what??
If you're doing the blocking yourself on your own network then sure whatever, you don't really care whether google stuff breaks, but you probably also have safebrowsing disabled, or know how to whitelist the safebrowsing endpoint yourself if you need it, so the whitelist argument isn't relevant in that context.
If that was the case, here was the original comment.
> Apple servers are whitelisted in adblocking and firewall APIs
What exactly did you disagree with?
However people can disobey our laws and so if they aren't popular enough they're worthless. The UK used to have laws controlling the ownership of dogs. Each dog required a license, licenses were taxed and you could be refused a license. But that law was very unpopular, and so it was abolished - not because licensing dog ownership wasn't a good idea, but because even if it was a great idea it was too unpopular to succeed.
I am pretty sure whitelisting servers don't follow the laws of Thermodynamics or nature.
Without the human invention of entropy, we'd have no clue why our perpetual motion machines aren't working.
For the mechanics those laws describe, they're great too. Pretty sure there would be constant unwanted explosions everywhere if energy could keep transforming in any way where it's conserved. I like that my table doesn't decide to be a bomb at random
Trust does not compartmentalize.
This is a fair assumption to challenge. Lots of developers co-mingling their traffic with an ad company doesn't mean everyone has to whitelist their servers. It's an impediment. But Apple has navigated those.
(from personal experience, we used a service in a project once to fetch stock market data. It was a good faith agreement, we had to maintain our own tallies of how often a stock price was fetched, tell them, and we'd be charged accordingly. This made sense because from them we just got a 20 mbit inbound pipeline of stock updates, which we fed into a Gemfire (which is now apparently called "VMware Tanzu™ GemFire®") cluster and exposed to end-users via a simple REST API. (It was a bank, of course we couldn't change firewall rules to allow websockets or whatever was available at the time).
How is this about "data mining"? If they have built their own safe browsing service they'd be in the exact same position to do data mining!
I'm sure Apple doesn't need to build APIs to do data mining on their own users. It would be very un-apple to create an API like this and allow non-apple devices to use it. So where is the benefit on data mining?
Privacy (in a consumer and marketing sense) is a major market advantage. I think that Apple has determined that keeping data away from 3rd parties is a good way to capitalize on that market edge vs. giving up the edge and engaging in the same consumer exploitation as their competitors.
I agree, this seems like the simplest and most straight-forward explanation to me.
If they wanted to claim privacy advantage, they could offer these lists for rsyncable download, like antivirus of more civilized eras used to do.
How does Apple building its own service smell like "data mining"? You can build your own service and not be a data miner.
It's free. https://developers.google.com/safe-browsing/v4/pricing
Emphasis 'all'. There may be meetings, but it's still free.
Whether it is or isn't (at the moment) data mining I won't debate.
My concern is sending that much of my behavioural information through a point controlled by one party.
In aggregate, that's not insignificant traffic, so you wouldn't want to use your own resources to process it without a worthwhile reason.
this doesn't really pass the smell test of "is there something fishy going on around here?"
https://www.zdnet.com/article/firefox-to-ship-network-partit...
But evil servers don't.
Example: gravatar.com gives an expiration time of 5 minutes.
curl -q -i --output - https://www.gravatar.com/avatar/70d9b050bfe39350c234d710fadf... | grep -a xpires
expires: Fri, 12 Feb 2021 11:54:40 GMT
https://caniuse.com/referrer-policy
Hoping the defaults for sending such metadata will change eventually
Not the same thing as hiding your IP and the domain name, but we're getting closer to full privacy, slowly. The problem with proxying is that it would only work with a small list of third-party asset hosts, and it would break the ability for CDNs to work unless it was a distributed proxy... that sounds like more headache than its worth except maybe as a new type of browser extension, something similar to a content filter but instead loads cached or proxied copies.
But at that point it's worth considering VPN or compression proxy services for content compression as Chrome and Opera Mini might do, and MITM everything the browser loads so nobody gets your IP except Apple. I imagine folks might pay for an Apple VPN service, I'm just not sure Apple wants any headaches that might go along with it yet. :)
Why not just remove referrer header for all 3rd party requests? Or remove it in Private browsing mode. VPNs nice, im using one, but other VPN companies are not, such a cutthroat business :) And you can not self-host VPN, it defeats the hide my IP feature.
Google violates privacy, yes but so does Apple.
Real privacy on phones means removing google play services from your phone, using fdroid, not using any proprietary apps and self hosting services instead of relying on gsuite or ms365.
Not the fake privacy shit that Apple does, where they move the power from Google to themselves.
You do, of course, pay for this privacy with significantly reduced convenience.
Signal has received financing from the CIA so my trust level isn't high (even though I use it).
My point is that privacy is an illusion on any connected system and particularly a smartphone.
You can make less privacy damaging choices but IMHO there's no panacea.
More like Signal once received funding from a fund that included funding from an organization that was once run by the CIA.
Still, I agree with your overall point. To be truly private, you need to disconnect. Other than that, you need to consider each trade off. Historically, this was difficult because companies barely disclosed what they did. Since GDPR and CCPA, a lot of the veil has been lifted.
People use Google & Facebook because they are dependent on their services but some of them know they are unethical (for e.g the recent WhatsApp scandal shows that at least some people are kinda aware).
Apple on the other hand lies and does propaganda about their fake Privacy and people (even on HN) think they are the solution, and that's far more dangerous I think.
Many people think real Privacy solutions are not worth supporting because they have Safari, IOS & Icloud. Well guess what, ICloud is not even (end2end) encrypted, employees have been listening to your Siri conversation, HomeKit doorbells are doing nonconsenting facial recognition on you & your friends, Apple tracks every app you lunch & when (and no that's not necessary for security, you could just download a blacklist instead of sending Apple your history), and no, Apple does not audit or read any line of code of the apps on the store.
It's killing me that my friends think it's okay to install Facebook, Instagram & Snapchat or whatever on their phone because "No but it's okay, I have an IPhone so Apple has checked the app and everything". For them, Apple is magically going to protect them whatever they do.
That's where you see their lies & propaganda really worked.
Apple is like a polluting gas car that sells & market itself as a green clean ecological electrical car so that people can use without conscience issues
Apple is not absolute, ironclad privacy. Don't rely on them for covert ops missions. But they ARE providing a very reasonable model of doing business that requires no special skills on the part of the user and does not engage in the unrelenting surveillance that other companies bake into every corner of their products.
Is it "privacy"? I'm not sure. But it is definitely "not surveillance". And that's a very reasonable place to start.
They shame third party apps you have given background location permission for using your location in the background (eg. gps dog collar app) while never alerting you when the first party Apple apps do the same "Apple maps / friend finder / Siri / etc. used your location in the background"
That's fine -- your privacy will go way up -- but I don't think that's the solution very many people are looking for.
It still shares the same amount of information, it's just being shared with Apple instead of Google. If it was a privacy problem before, it remains so.
They have a "law enforcement portal" they can log in to in order to request the data.
In this particular case with Safe Browsing APIs, there wasn't a 'surface area' in the way that you mean, to begin with. The article, and commenters, are incorrectly making it appear that way.
As long as you have a 'smart' phone, it will talk to servers. Messages, email, contact sync, online backups, tools to give you trace possibilitiies if your phone is stolen ... everything needs some kind of server. And if you use an iPhone, a lot of those will be located at apple. If you use an android phone, those servers will be located at google (and possibly also at the hardware vendor eg samsung etc)
Aside from the whole 'company A can be trusted more then company B' thing which is in my opinion a personal matter, this specific item where apple will route the traffic to a 3rd party through apple to hide the ip etc of their customers is a good thing.
Probably gave it away?
> "their values when it comes to repairability and labor force"
Apple obviously doesn't have any positive values about labour force and repairability, but both of those have about 0% to do with privacy, so they aren't relevant in this case I'd think.
It’s just the classic “Apple’s bad, therefore they are absolutely doing anything nefarious I could come up with”.
adssettings.google.com
This is purely a move to further lock users in while being touted as being privacy friendly through persistent PR.
I'm the only person using my IP address, ergo it's personally identifiable. Seems pretty clear cut to me?
IP addresses are only when identifiable metadata is linked with it. I can only guess that you are being deliberately obtuse on this - I had momentarily forgotten that I was on HN so my comments weren't welcome sadly.
Google’s implementation of k-anonymity in Safe Browsing does not account for their own ability to correlate multiple queries and narrow down which specific website corresponds with the hash.
Apple compromised over 30,000 of their customers in such a fashion in 2019, as documented in their own transparency report.
The F in FISA stands for foreign, but at least one person who worked on the program has told us that it is used to obtain the data of Americans without warrants as well.
A journalist requested their data from Apple, Google, and Facebook a few years ago[1],
> The zip file I eventually received from Apple was tiny, only 9 megabytes, compared to 243 MB from Google and 881 MB from Facebook. And there's not much there, because Apple says the information is primarily kept on your device, not its servers. The one sentence highlight: a list of my downloads, purchases and repairs, but not my search histories through the Siri personal assistant or the Safari browser.
Also curious how, if as you say Google is so transparent with this information, they abruptly stopped updating all of their iOS apps on December 8th, the day that Apple required them to publish the data that their apps collect[2,3].
1: https://www.usatoday.com/story/tech/talkingtech/2018/05/04/a...
2: https://twitter.com/Thomasbcn/status/1356645088697454596
3: https://www.macrumors.com/2021/01/05/google-hasnt-updated-io...
Signal actually uses a similar approach to anonymize queries to GIPHY from users of its app. https://signal.org/blog/giphy-experiment/
Apple’s business model is not based on exfiltration of personal data, in fact their business of selling hardware is only boosted by adding privacy features.
That is a very binary view. Yes, it is still a privacy problem; but now the privacy problem is with a company that is not abusing personal data on a massive scale.
EDIT:
Come-on HN. Google has nothing to do with how trustworthy Apple is. You can distrust both. This whole "for privacy" push from Apple is clearly more about hurting others than protecting users. I'm surprised HN'ers are buying into this marketing ploy.
I love what 14.5 is doing to shake up the privacy invading practices of the large internet co's.
>I love what 14.5 is doing to shake up the privacy invading practices of the large internet co's.
Sure, but just don't believe it is for your privacy's sake.
So no, they shouldn't get a pass on everything they do in the name of privacy just because they aren't an ad company. Although in this case the proxy server is reasonable I think.
Don't read the marketing materials, read the actual financials.
The problem starts they focus on services revenue. The old days Steve Jobs would built Services to sell more products. Now Apple are building services only to extract more profits and revenue.
And as the web include Apple ID for login, more users will forever be lock into Apple ecosystem even on the web. You no longer have users or customers direct relationship. Everything goes through Apple. And in the name of good and privacy Apple is standing in between every business and their customers. All while acting badly in the case against Epic when things dont go their way.
Source: https://www.theverge.com/2020/2/3/21121492/google-hardware-m....
Both extremes exist here, just like everywhere else. Anti-Apple articles/posts/discussions also get a ton of upvotes and frequently end up on the front page, and the discussions are filled with comments of people swearing off Apple forever.
Apple is a polarizing company in the tech world and that is just as true on HN as anywhere else.
How is that clear?
I don't have rosy feelings about Apple. But their primary business is designed around making the iPhone environment pleasant and unscary. While Google's is about optimally monetizing information about me.
I trust Apple and Google just the same... to both do their best to follow their business interests. It just happens that one happens to align more with my interests than the other.
If you think Apple and Google handle privacy essentially the same aside from superficial marketing, I think that means you don't understand what either of them want.
"So, these behemoths have now started to eat each other to satisfy their never ending appetite for money and control. What next? Remaining ones colluding together to prevent entrance of new competitors?"
"With mobile and social media platforms having finished their market expansion, and their product categories having settled, privacy-respecting open source alternatives catch up in functionality and usability. Anti-trust and regulation to enforce privacy and interoperability ensure these new entrants get a chance in the market, and consumers have a real chance to escape the clutches of the behemoths"
Tall order? Sure - but all progress starts with a dream.
so, yeah, inertia is certainly a factor, but the staggering level of tech incompetence among the masses is also a likely factor.
It is also not a matter of "catching up in functionality and usability". It will never catch up. Proprietary networks can build on top of free ones, but not viceversa. Also, every pseudo-feature introduced by a proprietary network soon becomes mission-critical (e.g. people will say free network X is not "up to the task" because one cannot easily send animated cat pictures with it, in the same way IRC suddenly became "not up to the task").
In summary, it is absurd to wait until free networks "catch up". They will never "catch up", for some users definition of "functionality and usability", and network effects will take care of the rest of users. The only way this works is if users are willing to actually prioritize free-ness and to actually trade off some features to gain it. Boycott closed networks, even.
But that will never happen.
You talking about Google killing its Jabber compliance?
Linux dominating mobile should not be about Android using the Linux kernel underneath the scenes...
I think that Linux phones are going to be very useful very quickly given huge interest of the community and openness of the platform.
Whenever a solution to a technical problem is "recompile components of the OS", this means the answer to the same problem in a "non-linux"/non-free system would be "piss and moan and bend over and take it up the tail pipe". aka: no solution whatsoever. The developer's way or the highway.
The point is: once your problem is complicated enough that your only resort is to edit the software, free software _at least_ gives you the chance to do that. It's no wonder people actually suggest doing it. Proprietary software does not. It's no wonder people _don't_ suggest doing it.
If it was supposed to be a complain, better rephrase it.
The kicker being that such problems are so rare as to be functionally nonexistent, and even in such cases, usually contacting the vendor can at least give you some options. A few anecdotes from my own experiences:
1) Windows\MacOS have never simply refused to use a network card, for no apparent reason.
2) MacOS has never destroyed it's own bootloader because it was Tuesday and it was bored: Windows did it once, but it was repaired automatically by the recovery partition.
3) Windows\MacOS have never refused to play audio after resuming from standby until rebooted.
> The point is: once your problem is complicated enough that your only resort is to edit the software, free software _at least_ gives you the chance to do that
But conversely, I don't have to edit software I paid for that's built on a reliable, if imperfect, OS. A reboot fixes almost anything wrong with Windows, and sure, I'd appreciate it if it could be like linux and stretch it's uptime into years, but also, a reboot takes less time than a run for coffee.
That a solution technically exists is less important than the accessibility of the solution.
No, it's not, and I really want to emphasize that. If the alternative is _no solution_ then the accessibility of the solution is a rather moot point. That is the point I was trying to make.
What you want to say is that it does not matter if free software makes it _possible_ to solve your problems, because (you claim) you don't have these problems with proprietary software, or (you claim) you have a simpler solution available for those that is only applicable to the proprietary software.
I am not going to enter that particular discussion. I just wanted to point out how it is absurd to simply claim that "as long as people keep recommending recompiling stuff open source won't work" when actually A) people recommend it _because you can actually do it_ , unlike alternatives B) being able to recompile stuff is actually a major if not the main strength of free software, so it is a strange argument to point it as a negative.
And my reply to that is, in the context of mainstreaming Linux to the wider computer using audience, that's ridiculous. You might as well tell every person who owns a car to never pay for repairs again, because you can, via the proper hardware, reprogram the ECM. That "solution" applies only to an interested subculture of (awesome) people who hack shit.
To say to my aunt Doris that Ubuntu can be better for her to use than Windows and then require her to learn a fair bit of bash script and C# to complete that journey is ridiculous.
No one, absolutely no one is saying that (specially the part about "never pay for repairs again" -- another common nonsense).
What I am saying is that between a otherwise-identical non-reprogrammable ECM and a reprogrammable ECM, the objectively better choice is the reprogrammable ECM. Because even if you don't know how to do it, you at least have the choice to let someone else do it. It doesn't matter if you personally do or don't understand how to reprogram ECMs. The choice is still clear.
> my aunt Doris that Ubuntu can be better for her to use than Windows and then require her to learn a fair bit of bash script and C# to complete that journey is ridiculous.
Your aunt Doris doesn't have to learn C#. But she _has_ the option to, she has the option to follow the instructions from someone she apparently read on the Internet (what motivated this discussion, I thought), AND she has the option to convince/hire someone to do it for her. When your aunt Doris hits the same issue with Windows, .... she's stuck! Better luck with Apple!
I suggest that if you have any interest whatsoever in free software, spend some time to understand this aspect, because it can and does reframe the discussion. If you remove the free part from "free software", what remains is basically just software; the same as any other piece of software, a rotting bug-laden piece of shit. Why deny this feature?
Must have been one hell of a hangover from that Mardi Gras ball.
https://time.com/76655/google-apple-settle-wage-fixing-lawsu...
For one, the user can change the default search spot.
Second, selling it doesn't have any difference that having it just be Google (without money changing hands)
Third, why did some upcoming challenger overbid Google for that spot and they were rejected?
https://time.com/76655/google-apple-settle-wage-fixing-lawsu...
Google has been paying Apple $8-12 billion per year to be the default iOS search engine. In more realistic terms, it's payment for Apple not to create their own search engine.
https://support.apple.com/en-us/HT210675
>For users with China mainland set as their region in Settings > General > Language and Region, Safari may also use Tencent Safe Browsing to do this check.
Are these checks proxified as well?
Actually sounds pretty good. In Australia it is 730 days.
> Actually sounds pretty good. In Australia it is 730 days.
No, it doesn't. China requires the content of user activities to be saved, so your chat history is literally being sent to the local police in real time for scanning. The result is stuff like this: https://www.youtube.com/watch?v=MiMLVYK4hEc (Chinese police casually asserting their dominance by locking some poor guy in a tiger chair for badmouthing them on a private WeChat chat). A few years back someone found an analyzed an unsecured Mongo DB that was storing these messages: https://www.bleepingcomputer.com/news/security/open-mongodb-...
IIRC, Australia only has metadata retention requirements.
>China requires the content of user activities to be saved,
Do you have a source for this? I find it hard to find information on this, I assume it's because I don't speak Chinese.
The copy I linked is clearly a re-upload of a re-upload, it was just the first copy I found.
How do we know anything is real at all? I don't have a specific chain of custody for the video, but I judge that it's likely true because the practices shown are consistent with other reports (e.g. https://www.youtube.com/watch?v=M8PgCUap1Vg, https://www.hrw.org/report/2015/05/13/tiger-chairs-and-cell-...). It gets other details right, like the anti-motorcycle crackdown. Also, the low-level Chinese police that would create a video like that very likely do not understand how bad the optics of it are when seen by foreigners.
> Do you have a source for this? I find it hard to find information on this, I assume it's because I don't speak Chinese.
https://en.wikipedia.org/wiki/WeChat#State_surveillance_and_.... It wasn't hard to find.
This says nothing about the amount of days. Neither do the sources.
>Its parent company is obliged to share data with the Chinese government under the China Internet Security Law and National Intelligence Law.
Can be said about the US as well, companies can be forced to share their data with the government.
edit: Thanks for the HRW report, I'll have a read
Is the amount of days really the most important aspect of this?
> Can be said about the US as well, companies can be forced to share their data with the government.
While the US is definitely not perfect, that's a false equivalency. One can only draw superficial parallels between the US and China on this topic. The key difference is actually in the area of political culture. For instance: both the US and China make a big deal about the "rule of law," but they're actually talking about very different things. The the US, it means the law is applied consistently and even constrains the government. In China, the government is in a very real sense above the law, and the phrase merely means that they demand you comply with their rule through the laws they make.
No, but if people cannot get such a simple thing right, and find citations for that, I also don't trust they got the rest right. No one has linked me anything that says "all messages from everyone need to be stored for whatever amount of days".
If you are going to paint China as the bad guys, at least do it over stuff that can be supported by facts, or if it is supported by fact make sure you can show them if someone asks.
After a five year court case, the Federal Court decided in 2017 that the average citizen isn't allowed to access all data that may be about them, despite being allowed to do so under the Privacy Act. If that sounds ambiguous... It's because it is.
Without an ability to say with is metadata and what is not, everything may be getting stored, and some companies will be overly conservative in how much data they are storing.
Not to say that this is worse than the Chinese implementation which is far more explicit in its demands for privacy invasion, just that the Australian case is... Worse than it sounds.
That is false. Google produces the hashes and can easily reverse them.
Google Safe Browsing exists because people are shit heads. Apple proxy servers exist because Google is a shit head.
> According to Apple, before visiting a website, Safari may send hashed prefixes of the URL (Apple terms it “information calculated from the website address”) to Google Safe Browsing to check if there’s a match.
Does anyone have links to algorithms for such "hashed prefixes of an URL"?
"A 32-bit hash prefix like "ba7816bf" would represent the first eight characters of a 256-bit, 64-character SHA256 digest of a full URL.
Before it loads a requested website, Safari, like other browsers that implement a safe browsing lookup system, will hash the URL of the website to be visited and compare its hash prefix to the received hash segments of malicious sites."
https://news.ycombinator.com/item?id=21254166
https://www.theregister.com/2019/10/14/apple_china_tencent/
https://developers.google.com/safe-browsing/v4/urls-hashing#...
Is this done for 'privacy'?
Pretty thinly veiled attempt, because they could easily create hashes for every url their crawlers come across, and do some statistical wizardry to try to find out which of the 1000 urls with that prefix you visited. Right?
Can anyone explain how this works? It isn't making sense to me. If the hash is unique enough to match in a database identifying malicious websites (without false positives), isn't it also unique enough to identify the website the user is trying to visit? At least to anyone with the hashing algorithm? Doesn't it have to be, in order to work at it's intended effect, to match a list of malicious websites?
If it might be, you send that hash prefix to Google, who respond with a list of full hashes with that prefix, and then you can go through that list (locally) and determine whether the computed hash is in the malicious set or not (without false positives).
The important point is that the full hash is never sent over the wire from the end user: only a prefix (typically four ASCII-encoded hex bytes) is ever transmitted.
This is one item I would not block, we already have huge issues with this list providing false positives. Giving Google even less data to make adjustments make this worse.
> Since Apple uses a hashed prefix, Google cannot learn which website the user is trying to visit. Up until iOS 14.5, Google could also see the IP address of where that request is coming from.
> And setting up a proxy server to filter Google Safe Browsing traffic just so Google cannot users’ browsing activity will be a welcome move for a lot of users.
IIRC the safe browsing was designed to avoid disclosing user traffic: https://developers.google.com/safe-browsing/v4/update-api
> The Update API is designed for clients that require high frequency, low-latency verdicts. Several web browsers and software platforms use this API to protect large sets of users.
> If you are concerned about the privacy of the queried URLs or the latency induced by a network request, use the Update API.