Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Safebrowsing prefs #19

Closed
Gitoffthelawn opened this issue Nov 5, 2015 · 1 comment
Closed

Safebrowsing prefs #19

Gitoffthelawn opened this issue Nov 5, 2015 · 1 comment

Comments

@Gitoffthelawn
Copy link

Currently, this extension will allow the user to toggle browser.safebrowsing.downloads.enabled, and recommends that it be set to false (off).

If I'm understanding the Mozilla documentation (https://wiki.mozilla.org/Security/Application_Reputation) correctly, setting this pref to false will decrease security with no benefit to privacy. From what I can tell (and please correct me if I'm mistaken), setting this pref to false will prevent Firefox from comparing downloads to the internal malware database.

On the other hand, setting browser.safebrowsing.downloads.remote.enabled to false will decrease security while increasing privacy (when it is set to true, Firefox uploads a hash of some of your downloaded files to Google servers to see if they are included in their online database).

If the above understanding is correct, I would recommend encouraging browser.safebrowsing.downloads.enabled to be enabled (the opposite of the current behavior), and add the ability to toggle browser.safebrowsing.downloads.remote.enabled with indicators that a false (off setting) increases security and decreases privacy.

@schomery
Copy link
Owner

schomery commented Apr 6, 2016

Nice catch. From the doc, I have a same understanding too. So lets have browser.safebrowsing.downloads.remote.enabled in the main panel and browser.safebrowsing.downloads.enabled in the advanced panel with recommended value of true

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants