• Phishing scam for hotel bookings

    From The Todal@the_todal@icloud.com to uk.legal.moderated on Sun Sep 20 10:22:18 2026
    From Newsgroup: uk.legal.moderated

    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people.

    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Sun Sep 20 11:21:04 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-20, The Todal <the_todal@icloud.com> wrote:
    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people.

    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    If the site is hosted in the UK then there is no chance anyone will take
    any action. If it is hosted abroad then the chance is even less.

    I would be a bit concerned whether you booked via the real booking.com.
    Perhaps try finding a phone number for the hotel and checking with them directly whether you have a valid booking.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Theo@theom+news@chiark.greenend.org.uk to uk.legal.moderated on Sun Sep 20 12:00:55 2026
    From Newsgroup: uk.legal.moderated

    The Todal <the_todal@icloud.com> wrote:
    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people.

    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    Have you reported it to booking.com?

    I suppose there's a chance it's just coincidence. Do the messages mention
    the specific location / hotel / date of your booking? Or just generic?

    If they know specifics, it sounds like Booking told the hotel your phone
    number (so they can contact you if you are late, etc). And somewhere the
    phone number has been leaked to the people running the scam. Which must be against Booking's contract with the hotel. That's something Booking can
    jump on (potentially de-list the hotel).

    I wouldn't have high hopes of them doing very much, but cutting off their source of customers has a lot more power than expecting 'someone else' to do something via generic 'report phishing' websites. There isn't exactly a
    team of crack commandos on alert for those reports.

    Theo

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From The Todal@the_todal@icloud.com to uk.legal.moderated on Sun Sep 20 12:40:55 2026
    From Newsgroup: uk.legal.moderated

    On 20/09/2026 12:00, Theo wrote:
    The Todal <the_todal@icloud.com> wrote:
    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people. >>
    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card
    details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website
    "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing
    attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    Have you reported it to booking.com?

    I haven't.
    Google AI tells me: Yes, this is an official phishing scam. Text like preverify-stayguestioncheckdetails is a randomly generated or
    deceptively named domain designed to mimic legitimate booking platforms
    like Booking.com or hotel check-in apps.


    I suppose there's a chance it's just coincidence. Do the messages mention
    the specific location / hotel / date of your booking? Or just generic?

    I have omitted the end of the URL which was a code especially for me,
    which took me to a web page which appeared to mimic the booking.com page
    for my reservation and contained my full name (but not my email address)
    and the date of my booking, as if those details had been leaked by
    booking.com or perhaps there has been a data breach.



    If they know specifics, it sounds like Booking told the hotel your phone number (so they can contact you if you are late, etc). And somewhere the phone number has been leaked to the people running the scam. Which must be against Booking's contract with the hotel. That's something Booking can
    jump on (potentially de-list the hotel).

    I wouldn't have high hopes of them doing very much, but cutting off their source of customers has a lot more power than expecting 'someone else' to do something via generic 'report phishing' websites. There isn't exactly a
    team of crack commandos on alert for those reports.

    Theo


    Thanks.

    In the past when I have reported defective sites they have quickly been flagged by Google as suspicious. That doesn't seem to be happening now.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From The Todal@the_todal@icloud.com to uk.legal.moderated on Sun Sep 20 12:33:23 2026
    From Newsgroup: uk.legal.moderated

    On 20/09/2026 12:21, Jon Ribbens wrote:
    On 2026-09-20, The Todal <the_todal@icloud.com> wrote:
    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people. >>
    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card
    details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website
    "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing
    attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    If the site is hosted in the UK then there is no chance anyone will take
    any action. If it is hosted abroad then the chance is even less.

    I would be a bit concerned whether you booked via the real booking.com. Perhaps try finding a phone number for the hotel and checking with them directly whether you have a valid booking.


    Good point - but my acknowledgment of my booking was made via email not
    via whatsapp. I suppose all communications via Whatsapp should be
    regarded as deeply suspicious.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Theo@theom+news@chiark.greenend.org.uk to uk.legal.moderated on Sun Sep 20 13:58:04 2026
    From Newsgroup: uk.legal.moderated

    The Todal <the_todal@icloud.com> wrote:
    On 20/09/2026 12:00, Theo wrote:

    Have you reported it to booking.com?

    I haven't.
    Google AI tells me: Yes, this is an official phishing scam.

    What is an "official" phishing scam? How does it compare with an unofficial one?

    Text like preverify-stayguestioncheckdetails is a randomly generated or deceptively named domain designed to mimic legitimate booking platforms
    like Booking.com or hotel check-in apps.

    That is obvious without asking an AI.

    I suppose there's a chance it's just coincidence. Do the messages mention the specific location / hotel / date of your booking? Or just generic?

    I have omitted the end of the URL which was a code especially for me,
    which took me to a web page which appeared to mimic the booking.com page
    for my reservation and contained my full name (but not my email address)
    and the date of my booking, as if those details had been leaked by booking.com or perhaps there has been a data breach.

    That sounds like a breach at the hotel end. eg perhaps Booking doesn't
    share the email address but they do share the phone number.

    In the past when I have reported defective sites they have quickly been flagged by Google as suspicious. That doesn't seem to be happening now.

    It's AIs all the way down - I suspect no human is actioning such reports
    (why would Google, it's a cost centre). Also if you went to the link
    directly then Google wasn't involved (ie you didn't Google-search for the link). It is possible the link is in or could be added to various lists of scam sites, but whether your browser is using such lists is down to your
    setup.

    The only real way to stop it is to kick the hotel off the Booking platform, which only Booking can do.

    Theo

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jeff Layman@Jeff@invalid.invalid to uk.legal.moderated on Sun Sep 20 16:06:34 2026
    From Newsgroup: uk.legal.moderated

    On 20/09/2026 12:33, The Todal wrote:
    On 20/09/2026 12:21, Jon Ribbens wrote:
    On 2026-09-20, The Todal <the_todal@icloud.com> wrote:
    I recently booked a hotel using the website booking.com - when I wanted
    to book via the hotel's own website I was diverted to booking.com. I
    rarely book hotels. I don't really know how it might work for other people. >>>
    I booked the hotel and had a confirmation that the room was booked and
    that I will be asked to pay when I check out at the end of my stay.

    Over the last 2 days I have had whatsapp messages that purport to be
    from booking.com asking me to give my full details including credit card >>> details and the CVV code on my card. And warning me that if I fail to
    give these details the rooms will be offered to someone else.

    The messages come from "phone number from Chile" and link to a website
    "https://preverify-stayguestioncheckdetails.com/"

    Having nearly fallen for what appears to be a scam, and having had a
    further reminder from that Whatsapp number telling me to respond
    urgenly, I have tried to report the site using several "report phishing
    attempt" websites. Yet it seems the site is still up and running.

    I wonder what else I ought to do, to protect others from being scammed?
    Any views? Are there so many scammers that the authorities simply can't
    or won't keep up?

    If the site is hosted in the UK then there is no chance anyone will take
    any action. If it is hosted abroad then the chance is even less.

    I would be a bit concerned whether you booked via the real booking.com.
    Perhaps try finding a phone number for the hotel and checking with them
    directly whether you have a valid booking.


    Good point - but my acknowledgment of my booking was made via email not
    via whatsapp. I suppose all communications via Whatsapp should be
    regarded as deeply suspicious.

    Last week it was not possible to log on to my Amazon account because the *only* place they would send a confirmatory code was to "my" Whatsapp
    account (I don't have one). When I tried the alternative the logon site offered of a code via SMS to my phone, it reported that I had tried to
    log on too many times that day (I hadn't logged on previously that day)
    and I should try later. The fault - assuming it was that - was not fixed
    until the next day, when I was able to log on via an SMS code.
    --
    Jeff

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nicholas Collin Paul de =?UTF-8?Q?Glouce=C5=BFter?=@thanks-to@Taf.com to uk.legal.moderated on Sun Sep 20 18:58:08 2026
    From Newsgroup: uk.legal.moderated

    The Todal <the_Todal@ICloud.com> wrote: |--------------------------------------------------------------|
    |"Are there so many scammers that the authorities simply [. . ]|
    |[. . .] won't keep up?" | |--------------------------------------------------------------|

    Whether there is only 1 tortfeasor or only 1 criminal or many
    tortfeasors or many criminals, whether a delict or a tort or a crime
    is a scam or some other illegality, authorities simply do not bother
    to attempt to comply with their jobs' descriptions, because they are
    staffed by lazy hypocrites who are parasites of taxes who get paid
    whether or NOT they attempt to comply with their jobs' descriptions.
    (S. HTTP://Gloucester.Insomnia247.NL/ fuer Kontaktdaten!)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Sun Sep 20 22:39:38 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have quickly been
    flagged by Google as suspicious. That doesn't seem to be happening now.

    It's AIs all the way down - I suspect no human is actioning such reports
    (why would Google, it's a cost centre). Also if you went to the link directly then Google wasn't involved (ie you didn't Google-search for the link). It is possible the link is in or could be added to various lists of scam sites, but whether your browser is using such lists is down to your setup.

    If Todal is using Chrome then Google is involved, because Chrome will automatically check all site visits against the "Google Safe Browsing"
    service which is one of the lists of scam sites that you mentioned.

    (It's designed to work in such a way that it neither sends to Google
    a list of all sites you visit, nor send to you a list of all suspicious
    sites.)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jethro@jethro_UK@hotmailbin.com to uk.legal.moderated on Mon Sep 21 16:19:09 2026
    From Newsgroup: uk.legal.moderated

    On Sun, 20 Sep 2026 16:06:34 +0100, Jeff Layman wrote:

    On 20/09/2026 12:33, The Todal wrote:
    [quoted text muted]

    Last week it was not possible to log on to my Amazon account because the *only* place they would send a confirmatory code was to "my" Whatsapp
    account (I don't have one)

    Here you need to beware. Once you have foolishly been roped into going on whatsapp a lot of providers will use that as an endpoint.

    I was dragooned into joining the street whatsapp and now - against my
    wishes, will and anything I can do to reverse it - uBer are using it as
    my only contact point.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Tue Sep 22 13:01:27 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have quickly been >>>> flagged by Google as suspicious. That doesn't seem to be happening now. >>>
    It's AIs all the way down - I suspect no human is actioning such reports >>> (why would Google, it's a cost centre). Also if you went to the link
    directly then Google wasn't involved (ie you didn't Google-search for the >>> link). It is possible the link is in or could be added to various lists of >>> scam sites, but whether your browser is using such lists is down to your >>> setup.

    If Todal is using Chrome then Google is involved, because Chrome will
    automatically check all site visits against the "Google Safe Browsing"
    service which is one of the lists of scam sites that you mentioned.

    (It's designed to work in such a way that it neither sends to Google
    a list of all sites you visit, nor send to you a list of all suspicious
    sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
    The client sends at least 4 bytes of the SHA256 hash of the url of the site name and defined substrings of the site name (without parameters).
    Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually
    be able to deduce the site.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jeff Layman@Jeff@invalid.invalid to uk.legal.moderated on Tue Sep 22 15:08:59 2026
    From Newsgroup: uk.legal.moderated

    On 21/09/2026 17:19, Jethro wrote:
    On Sun, 20 Sep 2026 16:06:34 +0100, Jeff Layman wrote:

    On 20/09/2026 12:33, The Todal wrote:
    [quoted text muted]

    Last week it was not possible to log on to my Amazon account because the
    *only* place they would send a confirmatory code was to "my" Whatsapp
    account (I don't have one)

    Here you need to beware. Once you have foolishly been roped into going on whatsapp a lot of providers will use that as an endpoint.

    I was dragooned into joining the street whatsapp and now - against my
    wishes, will and anything I can do to reverse it - uBer are using it as
    my only contact point.

    Just as with WhatCrapp, I have no other social media accounts. I can,
    though, unfortunately see a time when something important can't be done without one. :-(
    --
    Jeff

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nicholas Collin Paul de =?UTF-8?Q?Glouce=C5=BFter?=@thanks-to@Taf.com to uk.legal.moderated on Tue Sep 22 15:15:28 2026
    From Newsgroup: uk.legal.moderated

    "Never single source a key resource!" is a good proverb, but is there
    actually anything wrong with Whatsapp?
    (S. HTTP://Gloucester.Insomnia247.NL/ fuer Kontaktdaten!)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Tue Sep 22 17:31:09 2026
    From Newsgroup: uk.legal.moderated

    On 22/09/2026 14:01, Jon Ribbens wrote:
    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have quickly been >>>>> flagged by Google as suspicious. That doesn't seem to be happening now. >>>>
    It's AIs all the way down - I suspect no human is actioning such reports >>>> (why would Google, it's a cost centre). Also if you went to the link
    directly then Google wasn't involved (ie you didn't Google-search for the >>>> link). It is possible the link is in or could be added to various lists of
    scam sites, but whether your browser is using such lists is down to your >>>> setup.

    If Todal is using Chrome then Google is involved, because Chrome will
    automatically check all site visits against the "Google Safe Browsing"
    service which is one of the lists of scam sites that you mentioned.

    (It's designed to work in such a way that it neither sends to Google
    a list of all sites you visit, nor send to you a list of all suspicious
    sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
    The client sends at least 4 bytes of the SHA256 hash of the url of the
    site name and defined substrings of the site name (without parameters).
    Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually
    be able to deduce the site.

    Why will Google not usually be able to deduce the site ?

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jeff Layman@Jeff@invalid.invalid to uk.legal.moderated on Wed Sep 23 09:42:00 2026
    From Newsgroup: uk.legal.moderated

    On 22/09/2026 16:15, Nicholas Collin Paul de Glouce++ter wrote:
    "Never single source a key resource!" is a good proverb, but is there actually anything wrong with Whatsapp?

    You mean other than it's owned by that corporate paragon of virtue Meta? <https://en.wikipedia.org/wiki/WhatsApp#Controversies_and_criticism>
    --
    Jeff

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Wed Sep 23 11:12:29 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
    On 22/09/2026 14:01, Jon Ribbens wrote:
    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have
    quickly been flagged by Google as suspicious. That doesn't seem
    to be happening now.

    It's AIs all the way down - I suspect no human is actioning such
    reports (why would Google, it's a cost centre). Also if you went
    to the link directly then Google wasn't involved (ie you didn't
    Google-search for the link). It is possible the link is in or
    could be added to various lists of scam sites, but whether your
    browser is using such lists is down to your setup.

    If Todal is using Chrome then Google is involved, because Chrome will
    automatically check all site visits against the "Google Safe Browsing" >>>> service which is one of the lists of scam sites that you mentioned.

    (It's designed to work in such a way that it neither sends to Google
    a list of all sites you visit, nor send to you a list of all suspicious >>>> sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
    The client sends at least 4 bytes of the SHA256 hash of the url of the >>> site name and defined substrings of the site name (without parameters).
    Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually
    be able to deduce the site.

    Why will Google not usually be able to deduce the site ?

    Well for a start because the Safe Browsing protocol generally doesn't
    send any information at all to Google when you visit a site. It instead downloads the list of "bad sites" partial hashes from Google to your
    browser. It's only if there is a match between the site you're visiting
    and one of the partial hashes in the list that the browser then needs
    to fetch further information to confirm the hit.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nicholas Collin Paul de =?UTF-8?Q?Glouce=C5=BFter?=@thanks-to@Taf.com to uk.legal.moderated on Wed Sep 23 11:42:44 2026
    From Newsgroup: uk.legal.moderated

    Jeff Layman <Jeff@invalid.invalid> wrote:
    |----------------------------|
    |"You mean other than [. . .]|
    |[. . .]" |
    |----------------------------|

    Yes. (By the way I created no Meta account.)
    (S. HTTP://Gloucester.Insomnia247.NL/ fuer Kontaktdaten!)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Thu Sep 24 09:08:03 2026
    From Newsgroup: uk.legal.moderated

    On 23/09/2026 12:12, Jon Ribbens wrote:
    On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
    On 22/09/2026 14:01, Jon Ribbens wrote:
    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have
    quickly been flagged by Google as suspicious. That doesn't seem
    to be happening now.

    It's AIs all the way down - I suspect no human is actioning such
    reports (why would Google, it's a cost centre). Also if you went
    to the link directly then Google wasn't involved (ie you didn't
    Google-search for the link). It is possible the link is in or
    could be added to various lists of scam sites, but whether your
    browser is using such lists is down to your setup.

    If Todal is using Chrome then Google is involved, because Chrome will >>>>> automatically check all site visits against the "Google Safe Browsing" >>>>> service which is one of the lists of scam sites that you mentioned.

    (It's designed to work in such a way that it neither sends to Google >>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>> sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>> The client sends at least 4 bytes of the SHA256 hash of the url of the >>>> site name and defined substrings of the site name (without parameters). >>>> Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually
    be able to deduce the site.

    Why will Google not usually be able to deduce the site ?

    Well for a start because the Safe Browsing protocol generally doesn't
    send any information at all to Google when you visit a site. It instead downloads the list of "bad sites" partial hashes from Google to your
    browser. It's only if there is a match between the site you're visiting
    and one of the partial hashes in the list that the browser then needs
    to fetch further information to confirm the hit.


    You initially wrote "nor send to you a list of all suspicious sites".
    Did that mean that they initially send you a list of all the partial hashes for suspicious sites, which is then updated at intervals (Update API)?
    Rather than the Lookup API which does not send a list of all partial hashes?

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Thu Sep 24 10:23:22 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 23/09/2026 12:12, Jon Ribbens wrote:
    On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
    On 22/09/2026 14:01, Jon Ribbens wrote:
    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have
    quickly been flagged by Google as suspicious. That doesn't seem >>>>>>>> to be happening now.

    It's AIs all the way down - I suspect no human is actioning such >>>>>>> reports (why would Google, it's a cost centre). Also if you went >>>>>>> to the link directly then Google wasn't involved (ie you didn't
    Google-search for the link). It is possible the link is in or
    could be added to various lists of scam sites, but whether your
    browser is using such lists is down to your setup.

    If Todal is using Chrome then Google is involved, because Chrome will >>>>>> automatically check all site visits against the "Google Safe Browsing" >>>>>> service which is one of the lists of scam sites that you mentioned. >>>>>>
    (It's designed to work in such a way that it neither sends to Google >>>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>>> sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>>> The client sends at least 4 bytes of the SHA256 hash of the url of the
    site name and defined substrings of the site name (without parameters). >>>>> Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually
    be able to deduce the site.

    Why will Google not usually be able to deduce the site ?

    Well for a start because the Safe Browsing protocol generally doesn't
    send any information at all to Google when you visit a site. It instead
    downloads the list of "bad sites" partial hashes from Google to your
    browser. It's only if there is a match between the site you're visiting
    and one of the partial hashes in the list that the browser then needs
    to fetch further information to confirm the hit.

    You initially wrote "nor send to you a list of all suspicious sites".
    Did that mean that they initially send you a list of all the partial hashes for suspicious sites, which is then updated at intervals (Update API)?
    Rather than the Lookup API which does not send a list of all partial hashes?

    Yes. The idea of the "Update API" is that the browser can tell if any
    given URL is "bad" (while maintaining the maximum possible privacy for
    the user), but using the same data a bad actor cannot get a list of all
    bad URLs (since you cannot convert a hash back to a URL).

    The Lookup API is a different thing which has the advantage of being
    simpler to write a program to use, but doesn't maintain privacy since
    by definition it sends all checked URLs to Google. I don't think Chrome
    uses this API.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Thu Sep 24 13:21:35 2026
    From Newsgroup: uk.legal.moderated

    On 24/09/2026 11:23, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 23/09/2026 12:12, Jon Ribbens wrote:
    On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
    On 22/09/2026 14:01, Jon Ribbens wrote:
    On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
    On 20/09/2026 23:39, Jon Ribbens wrote:
    On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
    The Todal <the_todal@icloud.com> wrote:
    In the past when I have reported defective sites they have
    quickly been flagged by Google as suspicious. That doesn't seem >>>>>>>>> to be happening now.

    It's AIs all the way down - I suspect no human is actioning such >>>>>>>> reports (why would Google, it's a cost centre). Also if you went >>>>>>>> to the link directly then Google wasn't involved (ie you didn't >>>>>>>> Google-search for the link). It is possible the link is in or >>>>>>>> could be added to various lists of scam sites, but whether your >>>>>>>> browser is using such lists is down to your setup.

    If Todal is using Chrome then Google is involved, because Chrome will >>>>>>> automatically check all site visits against the "Google Safe Browsing" >>>>>>> service which is one of the lists of scam sites that you mentioned. >>>>>>>
    (It's designed to work in such a way that it neither sends to Google >>>>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>>>> sites.)

    https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>>>> The client sends at least 4 bytes of the SHA256 hash of the url of the
    site name and defined substrings of the site name (without parameters). >>>>>> Google will usually be able to deduce the sites.

    It will very rarely send anything at all, and Google will not usually >>>>> be able to deduce the site.

    Why will Google not usually be able to deduce the site ?

    Well for a start because the Safe Browsing protocol generally doesn't
    send any information at all to Google when you visit a site. It instead
    downloads the list of "bad sites" partial hashes from Google to your
    browser. It's only if there is a match between the site you're visiting
    and one of the partial hashes in the list that the browser then needs
    to fetch further information to confirm the hit.

    You initially wrote "nor send to you a list of all suspicious sites".
    Did that mean that they initially send you a list of all the partial hashes >> for suspicious sites, which is then updated at intervals (Update API)?
    Rather than the Lookup API which does not send a list of all partial hashes?

    Yes. The idea of the "Update API" is that the browser can tell if any
    given URL is "bad" (while maintaining the maximum possible privacy for
    the user), but using the same data a bad actor cannot get a list of all
    bad URLs (since you cannot convert a hash back to a URL).

    The Lookup API is a different thing which has the advantage of being
    simpler to write a program to use, but doesn't maintain privacy since
    by definition it sends all checked URLs to Google. I don't think Chrome
    uses this API.

    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe

    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be dangerous. When you visit a site, Chrome sends an obfuscated portion of the URL to Google through a privacy server that hides your IP address. If a
    site does something suspicious, full URLs and bits of page content are also sent.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Thu Sep 24 16:41:18 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 24/09/2026 11:23, Jon Ribbens wrote:
    Yes. The idea of the "Update API" is that the browser can tell if any
    given URL is "bad" (while maintaining the maximum possible privacy for
    the user), but using the same data a bad actor cannot get a list of all
    bad URLs (since you cannot convert a hash back to a URL).

    The Lookup API is a different thing which has the advantage of being
    simpler to write a program to use, but doesn't maintain privacy since
    by definition it sends all checked URLs to Google. I don't think Chrome
    uses this API.

    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe

    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be dangerous. When you visit a site, Chrome sends an obfuscated portion
    of the URL to Google through a privacy server that hides your IP
    address. If a site does something suspicious, full URLs and bits of
    page content are also sent.

    That's talking about the hashes I think, but it's also an extremely
    abbreviated description of what's happening, and hence not particularly accurate. There's a better description here:

    https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works

    "Chrome checks the sites that you go to ... against Google's list of
    unsafe sites ... Chrome periodically downloads and stores the most
    recent copy of this list on your device"

    Note that if the hash *does* match something on the 'suspicious' list,
    then some information is sent to Google to confirm the match, which is
    why I said Chrome would "very rarely" send anything and not "never".

    Note I have been talking about the 'Standard protection' option, which
    is the default I believe. If you choose to enable 'Enhanced protection'
    then it does indeed send URLs to Google.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Thu Sep 24 22:41:23 2026
    From Newsgroup: uk.legal.moderated

    On 24/09/2026 17:41, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:


    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe

    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be
    dangerous. When you visit a site, Chrome sends an obfuscated portion
    of the URL to Google through a privacy server that hides your IP
    address. If a site does something suspicious, full URLs and bits of
    page content are also sent.

    That's talking about the hashes I think, but it's also an extremely abbreviated description of what's happening, and hence not particularly accurate.

    That is what Chrome tells me for Standard Protection.

    There's a better description here:

    https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works

    "Chrome checks the sites that you go to ... against Google's list of
    unsafe sites ... Chrome periodically downloads and stores the most
    recent copy of this list on your device"


    Yes, but is that all it does? The text following is...

    "Each time you visit a website or attempt a download, Chrome first checks
    if the URL is on the list of safe sites stored on your device. If it's not, Chrome sends an obfuscated portion of the URL to Google through a privacy server that hides your IP address"

    Note that if the hash *does* match something on the 'suspicious' list,
    then some information is sent to Google to confirm the match, which is
    why I said Chrome would "very rarely" send anything and not "never".

    Note I have been talking about the 'Standard protection' option, which
    is the default I believe. If you choose to enable 'Enhanced protection'
    then it does indeed send URLs to Google.



    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Thu Sep 24 23:13:04 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 24/09/2026 17:41, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:


    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>
    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be
    dangerous. When you visit a site, Chrome sends an obfuscated portion
    of the URL to Google through a privacy server that hides your IP
    address. If a site does something suspicious, full URLs and bits of
    page content are also sent.

    That's talking about the hashes I think, but it's also an extremely
    abbreviated description of what's happening, and hence not particularly
    accurate.

    That is what Chrome tells me for Standard Protection.

    Yes, hence why I linked to a fuller explanation from Google themselves:

    There's a better description here:

    https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works

    "Chrome checks the sites that you go to ... against Google's list of
    unsafe sites ... Chrome periodically downloads and stores the most
    recent copy of this list on your device"

    Yes, but is that all it does? The text following is...

    "Each time you visit a website or attempt a download, Chrome first checks
    if the URL is on the list of safe sites stored on your device. If it's not, Chrome sends an obfuscated portion of the URL to Google through a privacy server that hides your IP address"

    Indeed, that's why I went on to say:

    Note that if the hash *does* match something on the 'suspicious' list,
    then some information is sent to Google to confirm the match, which is
    why I said Chrome would "very rarely" send anything and not "never".

    The text from Google you quote above is still, of course, a simplified
    and abbreviated explanation. It is aimed at ordinary people rather than computer programmers. They have to err in one direction or another, and
    they've made the wise and commendable decision to err in the direction
    of being overly cautious in their description.

    Full disclosure: I have not read the relevant part of the Chrome source
    code, and although I have personally written a client for the Update API
    on a previous version of Safe Browsing, I am not fully au fait with the
    newly released version 5.

    *However*, I know for a certain fact that the previous version of the
    Update API does not involve uploading any information to Google for the
    vast majority of web site visits, and I know for a certain fact that the
    very latest version of Chrome shows me in its debugging information at chrome://safe-browsing/#tab-db-manager that it has a local copy of
    millions of hash prefixes including for both 'good' and 'bad' sites.
    So I am pretty confident that it is still working in broadly the same
    manner as the version I am fully familiar with.

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Sun Sep 27 16:01:03 2026
    From Newsgroup: uk.legal.moderated

    On 25/09/2026 00:13, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 24/09/2026 17:41, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:


    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>>
    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be
    dangerous. When you visit a site, Chrome sends an obfuscated portion
    of the URL to Google through a privacy server that hides your IP
    address. If a site does something suspicious, full URLs and bits of
    page content are also sent.

    That's talking about the hashes I think, but it's also an extremely
    abbreviated description of what's happening, and hence not particularly
    accurate.

    That is what Chrome tells me for Standard Protection.

    Yes, hence why I linked to a fuller explanation from Google themselves:

    There's a better description here:

    https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works

    "Chrome checks the sites that you go to ... against Google's list of >>> unsafe sites ... Chrome periodically downloads and stores the most >>> recent copy of this list on your device"

    Yes, but is that all it does? The text following is...

    "Each time you visit a website or attempt a download, Chrome first checks
    if the URL is on the list of safe sites stored on your device. If it's not, >> Chrome sends an obfuscated portion of the URL to Google through a privacy
    server that hides your IP address"

    Indeed, that's why I went on to say:

    Note that if the hash *does* match something on the 'suspicious' list,
    then some information is sent to Google to confirm the match, which is
    why I said Chrome would "very rarely" send anything and not "never".

    That's not what I quoted. It refers to a list of *safe* sites, not suspicious. If it is *not* on the *safe* list, it is sent to Google.

    The text from Google you quote above is still, of course, a simplified
    and abbreviated explanation. It is aimed at ordinary people rather than computer programmers. They have to err in one direction or another, and they've made the wise and commendable decision to err in the direction
    of being overly cautious in their description.

    Cautious, in that they don't explain how small the *safe* list is?

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Jon Ribbens@jon+usenet@unequivocal.eu to uk.legal.moderated on Mon Sep 28 08:12:55 2026
    From Newsgroup: uk.legal.moderated

    On 2026-09-27, Nick Finnigan <nix@genie.co.uk> wrote:
    On 25/09/2026 00:13, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    On 24/09/2026 17:41, Jon Ribbens wrote:
    On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
    Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>>>
    Safe Browsing

    Standard protection
    Protects against sites, downloads and extensions that are known to be >>>>> dangerous. When you visit a site, Chrome sends an obfuscated portion >>>>> of the URL to Google through a privacy server that hides your IP
    address. If a site does something suspicious, full URLs and bits of
    page content are also sent.

    That's talking about the hashes I think, but it's also an extremely
    abbreviated description of what's happening, and hence not particularly >>>> accurate.

    That is what Chrome tells me for Standard Protection.

    Yes, hence why I linked to a fuller explanation from Google themselves:

    There's a better description here:

    https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works

    "Chrome checks the sites that you go to ... against Google's
    list of unsafe sites ... Chrome periodically downloads and
    stores the most recent copy of this list on your device"

    Yes, but is that all it does? The text following is...

    "Each time you visit a website or attempt a download, Chrome first
    checks if the URL is on the list of safe sites stored on your
    device. If it's not, Chrome sends an obfuscated portion of the URL
    to Google through a privacy server that hides your IP address"

    Indeed, that's why I went on to say:

    Note that if the hash *does* match something on the 'suspicious' list, >>>> then some information is sent to Google to confirm the match, which is >>>> why I said Chrome would "very rarely" send anything and not "never".

    That's not what I quoted. It refers to a list of *safe* sites, not suspicious. If it is *not* on the *safe* list, it is sent to Google.

    Ok, I looked into it some more, to find out what the differences are
    between the last version of Safe Browsing that I am entirely familiar
    with and the latest v5. The differences are the addition of the "safe"
    lists, and that Chrome in "Standard Protection mode" now uses a new
    API called "Real Time Mode". It appears that phishing sites are now
    often very short-lived (of the other of minutes) to avoid detection,
    and the local lists, being updated less often than this, were
    insufficient to keep up.

    "Real Time Mode" does send some information to Google if the site is
    not on a safe list. However:

    * it only send a one-way hash, of only part of the URL
    * it sends the info via a privacy server which anonymises it
    * the protocol allows for sending multiple hashes, including random
    made-up ones, to obscure which one the user is actually visiting
    (but I don't know to what extent Chrome uses this feature)

    Personally I am happy with this balance between privacy and security.
    It is hard to see what more could be asked of Google here. But if you
    want, you can set Settings -> Privacy and Security -> Security ->
    Safe Browsing -> No Protection. (I don't recommend doing this.)

    https://blog.google/products-and-platforms/products/chrome/google-chrome-safe-browsing-real-time/
    https://developers.google.com/safe-browsing/reference/Real.Time.Mode

    The text from Google you quote above is still, of course, a simplified
    and abbreviated explanation. It is aimed at ordinary people rather than
    computer programmers. They have to err in one direction or another, and
    they've made the wise and commendable decision to err in the direction
    of being overly cautious in their description.

    Cautious, in that they don't explain how small the *safe* list is?

    No. (And, it contains ~ 10,000 entries, which seems likely to be
    sufficient to cover most of what most people do.)

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Nick Finnigan@nix@genie.co.uk to uk.legal.moderated on Tue Sep 29 09:01:39 2026
    From Newsgroup: uk.legal.moderated

    On 28/09/2026 09:12, Jon Ribbens wrote:

    Ok, I looked into it some more, to find out what the differences are
    between the last version of Safe Browsing that I am entirely familiar
    with and the latest v5. The differences are the addition of the "safe"
    lists, and that Chrome in "Standard Protection mode" now uses a new
    API called "Real Time Mode". It appears that phishing sites are now
    often very short-lived (of the other of minutes) to avoid detection,
    and the local lists, being updated less often than this, were
    insufficient to keep up.

    Thank you.

    "Real Time Mode" does send some information to Google if the site is
    not on a safe list. However:

    * it only send a one-way hash, of only part of the URL
    * it sends the info via a privacy server which anonymises it
    * the protocol allows for sending multiple hashes, including random
    made-up ones, to obscure which one the user is actually visiting
    (but I don't know to what extent Chrome uses this feature)
    Personally I am happy with this balance between privacy and security.
    It is hard to see what more could be asked of Google here. But if you

    They can use a smaller portion of the hash, so that k-anonymity works.

    --- Synchronet 3.22a-Linux NewsLink 1.2