I recently booked a hotel using the website booking.com - when I wanted
to book via the hotel's own website I was diverted to booking.com. I
rarely book hotels. I don't really know how it might work for other people.
I booked the hotel and had a confirmation that the room was booked and
that I will be asked to pay when I check out at the end of my stay.
Over the last 2 days I have had whatsapp messages that purport to be
from booking.com asking me to give my full details including credit card details and the CVV code on my card. And warning me that if I fail to
give these details the rooms will be offered to someone else.
The messages come from "phone number from Chile" and link to a website "https://preverify-stayguestioncheckdetails.com/"
Having nearly fallen for what appears to be a scam, and having had a
further reminder from that Whatsapp number telling me to respond
urgenly, I have tried to report the site using several "report phishing attempt" websites. Yet it seems the site is still up and running.
I wonder what else I ought to do, to protect others from being scammed?
Any views? Are there so many scammers that the authorities simply can't
or won't keep up?
I recently booked a hotel using the website booking.com - when I wanted
to book via the hotel's own website I was diverted to booking.com. I
rarely book hotels. I don't really know how it might work for other people.
I booked the hotel and had a confirmation that the room was booked and
that I will be asked to pay when I check out at the end of my stay.
Over the last 2 days I have had whatsapp messages that purport to be
from booking.com asking me to give my full details including credit card details and the CVV code on my card. And warning me that if I fail to
give these details the rooms will be offered to someone else.
The messages come from "phone number from Chile" and link to a website "https://preverify-stayguestioncheckdetails.com/"
Having nearly fallen for what appears to be a scam, and having had a
further reminder from that Whatsapp number telling me to respond
urgenly, I have tried to report the site using several "report phishing attempt" websites. Yet it seems the site is still up and running.
I wonder what else I ought to do, to protect others from being scammed?
Any views? Are there so many scammers that the authorities simply can't
or won't keep up?
The Todal <the_todal@icloud.com> wrote:
I recently booked a hotel using the website booking.com - when I wanted
to book via the hotel's own website I was diverted to booking.com. I
rarely book hotels. I don't really know how it might work for other people. >>
I booked the hotel and had a confirmation that the room was booked and
that I will be asked to pay when I check out at the end of my stay.
Over the last 2 days I have had whatsapp messages that purport to be
from booking.com asking me to give my full details including credit card
details and the CVV code on my card. And warning me that if I fail to
give these details the rooms will be offered to someone else.
The messages come from "phone number from Chile" and link to a website
"https://preverify-stayguestioncheckdetails.com/"
Having nearly fallen for what appears to be a scam, and having had a
further reminder from that Whatsapp number telling me to respond
urgenly, I have tried to report the site using several "report phishing
attempt" websites. Yet it seems the site is still up and running.
I wonder what else I ought to do, to protect others from being scammed?
Any views? Are there so many scammers that the authorities simply can't
or won't keep up?
Have you reported it to booking.com?
I suppose there's a chance it's just coincidence. Do the messages mention
the specific location / hotel / date of your booking? Or just generic?
If they know specifics, it sounds like Booking told the hotel your phone number (so they can contact you if you are late, etc). And somewhere the phone number has been leaked to the people running the scam. Which must be against Booking's contract with the hotel. That's something Booking can
jump on (potentially de-list the hotel).
I wouldn't have high hopes of them doing very much, but cutting off their source of customers has a lot more power than expecting 'someone else' to do something via generic 'report phishing' websites. There isn't exactly a
team of crack commandos on alert for those reports.
Theo
On 2026-09-20, The Todal <the_todal@icloud.com> wrote:
I recently booked a hotel using the website booking.com - when I wanted
to book via the hotel's own website I was diverted to booking.com. I
rarely book hotels. I don't really know how it might work for other people. >>
I booked the hotel and had a confirmation that the room was booked and
that I will be asked to pay when I check out at the end of my stay.
Over the last 2 days I have had whatsapp messages that purport to be
from booking.com asking me to give my full details including credit card
details and the CVV code on my card. And warning me that if I fail to
give these details the rooms will be offered to someone else.
The messages come from "phone number from Chile" and link to a website
"https://preverify-stayguestioncheckdetails.com/"
Having nearly fallen for what appears to be a scam, and having had a
further reminder from that Whatsapp number telling me to respond
urgenly, I have tried to report the site using several "report phishing
attempt" websites. Yet it seems the site is still up and running.
I wonder what else I ought to do, to protect others from being scammed?
Any views? Are there so many scammers that the authorities simply can't
or won't keep up?
If the site is hosted in the UK then there is no chance anyone will take
any action. If it is hosted abroad then the chance is even less.
I would be a bit concerned whether you booked via the real booking.com. Perhaps try finding a phone number for the hotel and checking with them directly whether you have a valid booking.
On 20/09/2026 12:00, Theo wrote:
Have you reported it to booking.com?
I haven't.
Google AI tells me: Yes, this is an official phishing scam.
Text like preverify-stayguestioncheckdetails is a randomly generated or deceptively named domain designed to mimic legitimate booking platforms
like Booking.com or hotel check-in apps.
I suppose there's a chance it's just coincidence. Do the messages mention the specific location / hotel / date of your booking? Or just generic?
I have omitted the end of the URL which was a code especially for me,
which took me to a web page which appeared to mimic the booking.com page
for my reservation and contained my full name (but not my email address)
and the date of my booking, as if those details had been leaked by booking.com or perhaps there has been a data breach.
In the past when I have reported defective sites they have quickly been flagged by Google as suspicious. That doesn't seem to be happening now.
On 20/09/2026 12:21, Jon Ribbens wrote:
On 2026-09-20, The Todal <the_todal@icloud.com> wrote:
I recently booked a hotel using the website booking.com - when I wanted
to book via the hotel's own website I was diverted to booking.com. I
rarely book hotels. I don't really know how it might work for other people. >>>
I booked the hotel and had a confirmation that the room was booked and
that I will be asked to pay when I check out at the end of my stay.
Over the last 2 days I have had whatsapp messages that purport to be
from booking.com asking me to give my full details including credit card >>> details and the CVV code on my card. And warning me that if I fail to
give these details the rooms will be offered to someone else.
The messages come from "phone number from Chile" and link to a website
"https://preverify-stayguestioncheckdetails.com/"
Having nearly fallen for what appears to be a scam, and having had a
further reminder from that Whatsapp number telling me to respond
urgenly, I have tried to report the site using several "report phishing
attempt" websites. Yet it seems the site is still up and running.
I wonder what else I ought to do, to protect others from being scammed?
Any views? Are there so many scammers that the authorities simply can't
or won't keep up?
If the site is hosted in the UK then there is no chance anyone will take
any action. If it is hosted abroad then the chance is even less.
I would be a bit concerned whether you booked via the real booking.com.
Perhaps try finding a phone number for the hotel and checking with them
directly whether you have a valid booking.
Good point - but my acknowledgment of my booking was made via email not
via whatsapp. I suppose all communications via Whatsapp should be
regarded as deeply suspicious.
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have quickly been
flagged by Google as suspicious. That doesn't seem to be happening now.
It's AIs all the way down - I suspect no human is actioning such reports
(why would Google, it's a cost centre). Also if you went to the link directly then Google wasn't involved (ie you didn't Google-search for the link). It is possible the link is in or could be added to various lists of scam sites, but whether your browser is using such lists is down to your setup.
On 20/09/2026 12:33, The Todal wrote:
[quoted text muted]
Last week it was not possible to log on to my Amazon account because the *only* place they would send a confirmatory code was to "my" Whatsapp
account (I don't have one)
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have quickly been >>>> flagged by Google as suspicious. That doesn't seem to be happening now. >>>It's AIs all the way down - I suspect no human is actioning such reports >>> (why would Google, it's a cost centre). Also if you went to the link
directly then Google wasn't involved (ie you didn't Google-search for the >>> link). It is possible the link is in or could be added to various lists of >>> scam sites, but whether your browser is using such lists is down to your >>> setup.
If Todal is using Chrome then Google is involved, because Chrome will
automatically check all site visits against the "Google Safe Browsing"
service which is one of the lists of scam sites that you mentioned.
(It's designed to work in such a way that it neither sends to Google
a list of all sites you visit, nor send to you a list of all suspicious
sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
The client sends at least 4 bytes of the SHA256 hash of the url of the site name and defined substrings of the site name (without parameters).
Google will usually be able to deduce the sites.
On Sun, 20 Sep 2026 16:06:34 +0100, Jeff Layman wrote:
On 20/09/2026 12:33, The Todal wrote:
[quoted text muted]
Last week it was not possible to log on to my Amazon account because the
*only* place they would send a confirmatory code was to "my" Whatsapp
account (I don't have one)
Here you need to beware. Once you have foolishly been roped into going on whatsapp a lot of providers will use that as an endpoint.
I was dragooned into joining the street whatsapp and now - against my
wishes, will and anything I can do to reverse it - uBer are using it as
my only contact point.
On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have quickly been >>>>> flagged by Google as suspicious. That doesn't seem to be happening now. >>>>It's AIs all the way down - I suspect no human is actioning such reports >>>> (why would Google, it's a cost centre). Also if you went to the link
directly then Google wasn't involved (ie you didn't Google-search for the >>>> link). It is possible the link is in or could be added to various lists of
scam sites, but whether your browser is using such lists is down to your >>>> setup.
If Todal is using Chrome then Google is involved, because Chrome will
automatically check all site visits against the "Google Safe Browsing"
service which is one of the lists of scam sites that you mentioned.
(It's designed to work in such a way that it neither sends to Google
a list of all sites you visit, nor send to you a list of all suspicious
sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
The client sends at least 4 bytes of the SHA256 hash of the url of the
site name and defined substrings of the site name (without parameters).
Google will usually be able to deduce the sites.
It will very rarely send anything at all, and Google will not usually
be able to deduce the site.
"Never single source a key resource!" is a good proverb, but is there actually anything wrong with Whatsapp?
On 22/09/2026 14:01, Jon Ribbens wrote:
On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have
quickly been flagged by Google as suspicious. That doesn't seem
to be happening now.
It's AIs all the way down - I suspect no human is actioning such
reports (why would Google, it's a cost centre). Also if you went
to the link directly then Google wasn't involved (ie you didn't
Google-search for the link). It is possible the link is in or
could be added to various lists of scam sites, but whether your
browser is using such lists is down to your setup.
If Todal is using Chrome then Google is involved, because Chrome will
automatically check all site visits against the "Google Safe Browsing" >>>> service which is one of the lists of scam sites that you mentioned.
(It's designed to work in such a way that it neither sends to Google
a list of all sites you visit, nor send to you a list of all suspicious >>>> sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing
The client sends at least 4 bytes of the SHA256 hash of the url of the >>> site name and defined substrings of the site name (without parameters).
Google will usually be able to deduce the sites.
It will very rarely send anything at all, and Google will not usually
be able to deduce the site.
Why will Google not usually be able to deduce the site ?
On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
On 22/09/2026 14:01, Jon Ribbens wrote:
On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have
quickly been flagged by Google as suspicious. That doesn't seem
to be happening now.
It's AIs all the way down - I suspect no human is actioning such
reports (why would Google, it's a cost centre). Also if you went
to the link directly then Google wasn't involved (ie you didn't
Google-search for the link). It is possible the link is in or
could be added to various lists of scam sites, but whether your
browser is using such lists is down to your setup.
If Todal is using Chrome then Google is involved, because Chrome will >>>>> automatically check all site visits against the "Google Safe Browsing" >>>>> service which is one of the lists of scam sites that you mentioned.
(It's designed to work in such a way that it neither sends to Google >>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>> sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>> The client sends at least 4 bytes of the SHA256 hash of the url of the >>>> site name and defined substrings of the site name (without parameters). >>>> Google will usually be able to deduce the sites.
It will very rarely send anything at all, and Google will not usually
be able to deduce the site.
Why will Google not usually be able to deduce the site ?
Well for a start because the Safe Browsing protocol generally doesn't
send any information at all to Google when you visit a site. It instead downloads the list of "bad sites" partial hashes from Google to your
browser. It's only if there is a match between the site you're visiting
and one of the partial hashes in the list that the browser then needs
to fetch further information to confirm the hit.
On 23/09/2026 12:12, Jon Ribbens wrote:
On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
On 22/09/2026 14:01, Jon Ribbens wrote:
On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have
quickly been flagged by Google as suspicious. That doesn't seem >>>>>>>> to be happening now.
It's AIs all the way down - I suspect no human is actioning such >>>>>>> reports (why would Google, it's a cost centre). Also if you went >>>>>>> to the link directly then Google wasn't involved (ie you didn't
Google-search for the link). It is possible the link is in or
could be added to various lists of scam sites, but whether your
browser is using such lists is down to your setup.
If Todal is using Chrome then Google is involved, because Chrome will >>>>>> automatically check all site visits against the "Google Safe Browsing" >>>>>> service which is one of the lists of scam sites that you mentioned. >>>>>>
(It's designed to work in such a way that it neither sends to Google >>>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>>> sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>>> The client sends at least 4 bytes of the SHA256 hash of the url of the
site name and defined substrings of the site name (without parameters). >>>>> Google will usually be able to deduce the sites.
It will very rarely send anything at all, and Google will not usually
be able to deduce the site.
Why will Google not usually be able to deduce the site ?
Well for a start because the Safe Browsing protocol generally doesn't
send any information at all to Google when you visit a site. It instead
downloads the list of "bad sites" partial hashes from Google to your
browser. It's only if there is a match between the site you're visiting
and one of the partial hashes in the list that the browser then needs
to fetch further information to confirm the hit.
You initially wrote "nor send to you a list of all suspicious sites".
Did that mean that they initially send you a list of all the partial hashes for suspicious sites, which is then updated at intervals (Update API)?
Rather than the Lookup API which does not send a list of all partial hashes?
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
On 23/09/2026 12:12, Jon Ribbens wrote:
On 2026-09-22, Nick Finnigan <nix@genie.co.uk> wrote:
On 22/09/2026 14:01, Jon Ribbens wrote:
On 2026-09-21, Nick Finnigan <nix@genie.co.uk> wrote:
On 20/09/2026 23:39, Jon Ribbens wrote:
On 2026-09-20, Theo <theom+news@chiark.greenend.org.uk> wrote:
The Todal <the_todal@icloud.com> wrote:
In the past when I have reported defective sites they have
quickly been flagged by Google as suspicious. That doesn't seem >>>>>>>>> to be happening now.
It's AIs all the way down - I suspect no human is actioning such >>>>>>>> reports (why would Google, it's a cost centre). Also if you went >>>>>>>> to the link directly then Google wasn't involved (ie you didn't >>>>>>>> Google-search for the link). It is possible the link is in or >>>>>>>> could be added to various lists of scam sites, but whether your >>>>>>>> browser is using such lists is down to your setup.
If Todal is using Chrome then Google is involved, because Chrome will >>>>>>> automatically check all site visits against the "Google Safe Browsing" >>>>>>> service which is one of the lists of scam sites that you mentioned. >>>>>>>
(It's designed to work in such a way that it neither sends to Google >>>>>>> a list of all sites you visit, nor send to you a list of all suspicious >>>>>>> sites.)
https://developers.google.com/safe-browsing/reference/URLs.and.Hashing >>>>>> The client sends at least 4 bytes of the SHA256 hash of the url of the
site name and defined substrings of the site name (without parameters). >>>>>> Google will usually be able to deduce the sites.
It will very rarely send anything at all, and Google will not usually >>>>> be able to deduce the site.
Why will Google not usually be able to deduce the site ?
Well for a start because the Safe Browsing protocol generally doesn't
send any information at all to Google when you visit a site. It instead
downloads the list of "bad sites" partial hashes from Google to your
browser. It's only if there is a match between the site you're visiting
and one of the partial hashes in the list that the browser then needs
to fetch further information to confirm the hit.
You initially wrote "nor send to you a list of all suspicious sites".
Did that mean that they initially send you a list of all the partial hashes >> for suspicious sites, which is then updated at intervals (Update API)?
Rather than the Lookup API which does not send a list of all partial hashes?
Yes. The idea of the "Update API" is that the browser can tell if any
given URL is "bad" (while maintaining the maximum possible privacy for
the user), but using the same data a bad actor cannot get a list of all
bad URLs (since you cannot convert a hash back to a URL).
The Lookup API is a different thing which has the advantage of being
simpler to write a program to use, but doesn't maintain privacy since
by definition it sends all checked URLs to Google. I don't think Chrome
uses this API.
On 24/09/2026 11:23, Jon Ribbens wrote:
Yes. The idea of the "Update API" is that the browser can tell if any
given URL is "bad" (while maintaining the maximum possible privacy for
the user), but using the same data a bad actor cannot get a list of all
bad URLs (since you cannot convert a hash back to a URL).
The Lookup API is a different thing which has the advantage of being
simpler to write a program to use, but doesn't maintain privacy since
by definition it sends all checked URLs to Google. I don't think Chrome
uses this API.
Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe
Safe Browsing
Standard protection
Protects against sites, downloads and extensions that are known to be dangerous. When you visit a site, Chrome sends an obfuscated portion
of the URL to Google through a privacy server that hides your IP
address. If a site does something suspicious, full URLs and bits of
page content are also sent.
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe
Safe Browsing
Standard protection
Protects against sites, downloads and extensions that are known to be
dangerous. When you visit a site, Chrome sends an obfuscated portion
of the URL to Google through a privacy server that hides your IP
address. If a site does something suspicious, full URLs and bits of
page content are also sent.
That's talking about the hashes I think, but it's also an extremely abbreviated description of what's happening, and hence not particularly accurate.
https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works
"Chrome checks the sites that you go to ... against Google's list of
unsafe sites ... Chrome periodically downloads and stores the most
recent copy of this list on your device"
Note that if the hash *does* match something on the 'suspicious' list,
then some information is sent to Google to confirm the match, which is
why I said Chrome would "very rarely" send anything and not "never".
Note I have been talking about the 'Standard protection' option, which
is the default I believe. If you choose to enable 'Enhanced protection'
then it does indeed send URLs to Google.
On 24/09/2026 17:41, Jon Ribbens wrote:
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>
Safe Browsing
Standard protection
Protects against sites, downloads and extensions that are known to be
dangerous. When you visit a site, Chrome sends an obfuscated portion
of the URL to Google through a privacy server that hides your IP
address. If a site does something suspicious, full URLs and bits of
page content are also sent.
That's talking about the hashes I think, but it's also an extremely
abbreviated description of what's happening, and hence not particularly
accurate.
That is what Chrome tells me for Standard Protection.
There's a better description here:
https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works
"Chrome checks the sites that you go to ... against Google's list of
unsafe sites ... Chrome periodically downloads and stores the most
recent copy of this list on your device"
Yes, but is that all it does? The text following is...
"Each time you visit a website or attempt a download, Chrome first checks
if the URL is on the list of safe sites stored on your device. If it's not, Chrome sends an obfuscated portion of the URL to Google through a privacy server that hides your IP address"
Note that if the hash *does* match something on the 'suspicious' list,
then some information is sent to Google to confirm the match, which is
why I said Chrome would "very rarely" send anything and not "never".
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
On 24/09/2026 17:41, Jon Ribbens wrote:
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>>
Safe Browsing
Standard protection
Protects against sites, downloads and extensions that are known to be
dangerous. When you visit a site, Chrome sends an obfuscated portion
of the URL to Google through a privacy server that hides your IP
address. If a site does something suspicious, full URLs and bits of
page content are also sent.
That's talking about the hashes I think, but it's also an extremely
abbreviated description of what's happening, and hence not particularly
accurate.
That is what Chrome tells me for Standard Protection.
Yes, hence why I linked to a fuller explanation from Google themselves:
There's a better description here:
https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works
"Chrome checks the sites that you go to ... against Google's list of >>> unsafe sites ... Chrome periodically downloads and stores the most >>> recent copy of this list on your device"
Yes, but is that all it does? The text following is...
"Each time you visit a website or attempt a download, Chrome first checks
if the URL is on the list of safe sites stored on your device. If it's not, >> Chrome sends an obfuscated portion of the URL to Google through a privacy
server that hides your IP address"
Indeed, that's why I went on to say:
Note that if the hash *does* match something on the 'suspicious' list,
then some information is sent to Google to confirm the match, which is
why I said Chrome would "very rarely" send anything and not "never".
The text from Google you quote above is still, of course, a simplified
and abbreviated explanation. It is aimed at ordinary people rather than computer programmers. They have to err in one direction or another, and they've made the wise and commendable decision to err in the direction
of being overly cautious in their description.
On 25/09/2026 00:13, Jon Ribbens wrote:
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
On 24/09/2026 17:41, Jon Ribbens wrote:
On 2026-09-24, Nick Finnigan <nix@genie.co.uk> wrote:
Desktop Chrome 154.0.8037.58: chrome://settings/security?search=safe >>>>>
Safe Browsing
Standard protection
Protects against sites, downloads and extensions that are known to be >>>>> dangerous. When you visit a site, Chrome sends an obfuscated portion >>>>> of the URL to Google through a privacy server that hides your IP
address. If a site does something suspicious, full URLs and bits of
page content are also sent.
That's talking about the hashes I think, but it's also an extremely
abbreviated description of what's happening, and hence not particularly >>>> accurate.
That is what Chrome tells me for Standard Protection.
Yes, hence why I linked to a fuller explanation from Google themselves:
There's a better description here:
https://support.google.com/chrome/answer/13844634?sjid=3630318418115789033-EU#zippy=%2Chow-we-protect-your-data%2Chow-safe-browsing-works
"Chrome checks the sites that you go to ... against Google's
list of unsafe sites ... Chrome periodically downloads and
stores the most recent copy of this list on your device"
Yes, but is that all it does? The text following is...
"Each time you visit a website or attempt a download, Chrome first
checks if the URL is on the list of safe sites stored on your
device. If it's not, Chrome sends an obfuscated portion of the URL
to Google through a privacy server that hides your IP address"
Indeed, that's why I went on to say:
Note that if the hash *does* match something on the 'suspicious' list, >>>> then some information is sent to Google to confirm the match, which is >>>> why I said Chrome would "very rarely" send anything and not "never".
That's not what I quoted. It refers to a list of *safe* sites, not suspicious. If it is *not* on the *safe* list, it is sent to Google.
The text from Google you quote above is still, of course, a simplified
and abbreviated explanation. It is aimed at ordinary people rather than
computer programmers. They have to err in one direction or another, and
they've made the wise and commendable decision to err in the direction
of being overly cautious in their description.
Cautious, in that they don't explain how small the *safe* list is?
Ok, I looked into it some more, to find out what the differences are
between the last version of Safe Browsing that I am entirely familiar
with and the latest v5. The differences are the addition of the "safe"
lists, and that Chrome in "Standard Protection mode" now uses a new
API called "Real Time Mode". It appears that phishing sites are now
often very short-lived (of the other of minutes) to avoid detection,
and the local lists, being updated less often than this, were
insufficient to keep up.
"Real Time Mode" does send some information to Google if the site is
not on a safe list. However:
* it only send a one-way hash, of only part of the URL
* it sends the info via a privacy server which anonymises it
* the protocol allows for sending multiple hashes, including random
made-up ones, to obscure which one the user is actually visiting
(but I don't know to what extent Chrome uses this feature)
Personally I am happy with this balance between privacy and security.
It is hard to see what more could be asked of Google here. But if you
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 74 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 34:33:33 |
| Calls: | 1,196 |
| Calls today: | 1 |
| Files: | 1,354 |
| D/L today: |
16 files (19,622K bytes) |
| Messages: | 294,696 |