<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another look at SafeBrowsing warnings</title>
	<atom:link href="http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/</link>
	<description>The odd parity bit</description>
	<lastBuildDate>Sat, 17 Oct 2009 05:26:38 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: David</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-43515</link>
		<dc:creator>David</dc:creator>
		<pubDate>Sun, 28 Dec 2008 10:09:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-43515</guid>
		<description>I got the same thing with safebrowsing trying to get my pin - is this a genuine attempt to get my pin or is it just that a bunch of data is being transferred and the few digits that make up my pin are sometimes transmitted just by coincidence?</description>
		<content:encoded><![CDATA[<p>I got the same thing with safebrowsing trying to get my pin &#8211; is this a genuine attempt to get my pin or is it just that a bunch of data is being transferred and the few digits that make up my pin are sometimes transmitted just by coincidence?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gres</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-42412</link>
		<dc:creator>Gres</dc:creator>
		<pubDate>Thu, 23 Oct 2008 03:55:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-42412</guid>
		<description>I&#039;ve seen the same security message from ZoneAlarm only safebrowsing is trying to get my pin.  What is going on with this?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve seen the same security message from ZoneAlarm only safebrowsing is trying to get my pin.  What is going on with this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gene</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-41557</link>
		<dc:creator>Gene</dc:creator>
		<pubDate>Sat, 13 Sep 2008 13:12:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-41557</guid>
		<description>I have Trend Micro as my security program and it has stopped countless tries from safebrowsing ...... trying to get my private data ie phone number and bank account number</description>
		<content:encoded><![CDATA[<p>I have Trend Micro as my security program and it has stopped countless tries from safebrowsing &#8230;&#8230; trying to get my private data ie phone number and bank account number</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-38423</link>
		<dc:creator>George</dc:creator>
		<pubDate>Tue, 08 Jul 2008 06:24:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-38423</guid>
		<description>This is a big problem for smaller sites, but not a problem for bigger sites - AOL and other companies have a lot of malware on their sites but their sites are not &quot;suspicious&quot;, while smaller sites with just couple &quot;problems&quot; are getting blacklisted - compare links below - first one is blacklistes, the other one is not and compare number of problems:
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://txdnl.com/
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://aol.com/
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://freewebs.com/</description>
		<content:encoded><![CDATA[<p>This is a big problem for smaller sites, but not a problem for bigger sites &#8211; AOL and other companies have a lot of malware on their sites but their sites are not &#8220;suspicious&#8221;, while smaller sites with just couple &#8220;problems&#8221; are getting blacklisted &#8211; compare links below &#8211; first one is blacklistes, the other one is not and compare number of problems:<br />
<a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://txdnl.com/" rel="nofollow">http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://txdnl.com/</a><br />
<a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://aol.com/" rel="nofollow">http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://aol.com/</a><br />
<a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://freewebs.com/" rel="nofollow">http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=http://freewebs.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Z</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-36343</link>
		<dc:creator>Z</dc:creator>
		<pubDate>Mon, 19 May 2008 14:48:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-36343</guid>
		<description>Tried the firefox page in FF3RC1 and didn&#039;t get any warning.</description>
		<content:encoded><![CDATA[<p>Tried the firefox page in FF3RC1 and didn&#8217;t get any warning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gijs</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-35826</link>
		<dc:creator>Gijs</dc:creator>
		<pubDate>Sun, 11 May 2008 20:25:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-35826</guid>
		<description>Are those pages localized? Those dates could mean either &quot;May 1st&quot; or &quot;January 5th&quot; to me.</description>
		<content:encoded><![CDATA[<p>Are those pages localized? Those dates could mean either &#8220;May 1st&#8221; or &#8220;January 5th&#8221; to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Dolske</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-35585</link>
		<dc:creator>Justin Dolske</dc:creator>
		<pubDate>Wed, 07 May 2008 21:08:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-35585</guid>
		<description>jwatt:

I think, but am not sure, that &quot;this site has not hosted malicious software&quot; is making a distinction between targeting users and just providing bandwidth for distributing malware? It is confusing, though.

The linked URLs just go to the report pages for those sites, not the actual site.

I&#039;ve seen mixed results on how often blocked sites are scanned. But I think the important point for the moment is that by making this data available, it&#039;s now possible to critique the method.

Chris:

I&#039;m not now sure exactly what &quot;without user consent&quot; means. I&#039;d assume it&#039;s a mix of pages trying to exploit known security vulnerabilities, and distributing software that dishonestly includes malware (eg, a screensaver that includes trojan).

I don&#039;t think listing the exact exploits and advisories is all that useful for users. If the site is actively distributing malware, then it&#039;s risky to visit, end of story. I would expect that sites using known malware are also highly likely to include unknown attacks.</description>
		<content:encoded><![CDATA[<p>jwatt:</p>
<p>I think, but am not sure, that &#8220;this site has not hosted malicious software&#8221; is making a distinction between targeting users and just providing bandwidth for distributing malware? It is confusing, though.</p>
<p>The linked URLs just go to the report pages for those sites, not the actual site.</p>
<p>I&#8217;ve seen mixed results on how often blocked sites are scanned. But I think the important point for the moment is that by making this data available, it&#8217;s now possible to critique the method.</p>
<p>Chris:</p>
<p>I&#8217;m not now sure exactly what &#8220;without user consent&#8221; means. I&#8217;d assume it&#8217;s a mix of pages trying to exploit known security vulnerabilities, and distributing software that dishonestly includes malware (eg, a screensaver that includes trojan).</p>
<p>I don&#8217;t think listing the exact exploits and advisories is all that useful for users. If the site is actively distributing malware, then it&#8217;s risky to visit, end of story. I would expect that sites using known malware are also highly likely to include unknown attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Hubick</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-35567</link>
		<dc:creator>Chris Hubick</dc:creator>
		<pubDate>Wed, 07 May 2008 19:28:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-35567</guid>
		<description>How does &quot;malicious software&quot; get &quot;downloaded and installed without user consent&quot;?

Does this really mean &quot;this web site attempts to exploit security vulnerabilities to download and install malicious software without user consent&quot;?

I mean, no site should be able to do that, so I&#039;m lost.

As for the level of detail, IMO, it tells me almost nothing - I want to know what exploits the page attempts with links to corresponding security advisories, etc.  So, my preference would be a summary at the top for &quot;normal&quot; users, and then a big divider, and give even more detail below.</description>
		<content:encoded><![CDATA[<p>How does &#8220;malicious software&#8221; get &#8220;downloaded and installed without user consent&#8221;?</p>
<p>Does this really mean &#8220;this web site attempts to exploit security vulnerabilities to download and install malicious software without user consent&#8221;?</p>
<p>I mean, no site should be able to do that, so I&#8217;m lost.</p>
<p>As for the level of detail, IMO, it tells me almost nothing &#8211; I want to know what exploits the page attempts with links to corresponding security advisories, etc.  So, my preference would be a summary at the top for &#8220;normal&#8221; users, and then a big divider, and give even more detail below.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Olly</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-35551</link>
		<dc:creator>Olly</dc:creator>
		<pubDate>Wed, 07 May 2008 10:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-35551</guid>
		<description>I&#039;ve hit the big red warning in FF3b5 and upon clicking through found that Google&#039;s already marked the site as &quot;safe&quot;. How often does FF update it&#039;s blacklist?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve hit the big red warning in FF3b5 and upon clicking through found that Google&#8217;s already marked the site as &#8220;safe&#8221;. How often does FF update it&#8217;s blacklist?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Watt</title>
		<link>http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/comment-page-1/#comment-35546</link>
		<dc:creator>Jonathan Watt</dc:creator>
		<pubDate>Wed, 07 May 2008 08:19:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2008/05/06/another-look-at-safebrowsing-warnings/#comment-35546</guid>
		<description>So it says:

&gt; Of the 151 pages we tested on the site over the past 90 days, 108
&gt; page(s) resulted in malicious software being downloaded...

Then just a bit further down it says:

&gt; Has this site hosted malware?
&gt;     No, this site has not hosted malicous software over the past 90
&gt;     days.

Huh??? That&#039;s confusing.

Also, it says this is for bettasearch.com, but actually it&#039;s for www.bettasearch.com. That www. can make a big difference, so they should fix that.

And why on earth are the URLs to the malicious sites actually hyperlinked? (Unless they go to safebrowsing.clients.google.com of course.)

I visited the site myself just now, and the page is currently saying:

&gt; Of the 1 pages we tested on the site over the past 90 days, 0 page(s)
&gt; resulted in malicious software being downloaded and installed without
&gt; user consent. The last time Google visited this site was on
&gt; 03/26/2008, and suspicious content was never found on this site
&gt; within the past 90 days.

So why is it still being blocked? Is 1 page test really enough? I suspect the site is still hosting malicious software (being bet_t_asearch.com and all), but if a user sees that only one page was tested, and it wasn&#039;t found to have malicious software on it, they&#039;re going to loose confidence in the protection and think it&#039;s buggy and just a pain. They&#039;re also likely to click through to the page.</description>
		<content:encoded><![CDATA[<p>So it says:</p>
<p>&gt; Of the 151 pages we tested on the site over the past 90 days, 108<br />
&gt; page(s) resulted in malicious software being downloaded&#8230;</p>
<p>Then just a bit further down it says:</p>
<p>&gt; Has this site hosted malware?<br />
&gt;     No, this site has not hosted malicous software over the past 90<br />
&gt;     days.</p>
<p>Huh??? That&#8217;s confusing.</p>
<p>Also, it says this is for bettasearch.com, but actually it&#8217;s for <a href="http://www.bettasearch.com" rel="nofollow">http://www.bettasearch.com</a>. That www. can make a big difference, so they should fix that.</p>
<p>And why on earth are the URLs to the malicious sites actually hyperlinked? (Unless they go to safebrowsing.clients.google.com of course.)</p>
<p>I visited the site myself just now, and the page is currently saying:</p>
<p>&gt; Of the 1 pages we tested on the site over the past 90 days, 0 page(s)<br />
&gt; resulted in malicious software being downloaded and installed without<br />
&gt; user consent. The last time Google visited this site was on<br />
&gt; 03/26/2008, and suspicious content was never found on this site<br />
&gt; within the past 90 days.</p>
<p>So why is it still being blocked? Is 1 page test really enough? I suspect the site is still hosting malicious software (being bet_t_asearch.com and all), but if a user sees that only one page was tested, and it wasn&#8217;t found to have malicious software on it, they&#8217;re going to loose confidence in the protection and think it&#8217;s buggy and just a pain. They&#8217;re also likely to click through to the page.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
