summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/20101001/000554.html
blob: 13b67d63cfb4233124caa646f6dc5fef2c5cfff6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
 <HEAD>
   <TITLE> [Mageia-dev] Talk of Browsers
   </TITLE>
   <LINK REL="Index" HREF="index.html" >
   <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Talk%20of%20Browsers&In-Reply-To=%3CPine.LNX.4.44.1010010734030.18004-100000%40outpost-priv%3E">
   <META NAME="robots" CONTENT="index,nofollow">
   <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
   <LINK REL="Previous"  HREF="000553.html">
   <LINK REL="Next"  HREF="000562.html">
 </HEAD>
 <BODY BGCOLOR="#ffffff">
   <H1>[Mageia-dev] Talk of Browsers</H1>
    <B>Tux99</B> 
    <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Talk%20of%20Browsers&In-Reply-To=%3CPine.LNX.4.44.1010010734030.18004-100000%40outpost-priv%3E"
       TITLE="[Mageia-dev] Talk of Browsers">tux99-mga at uridium.org
       </A><BR>
    <I>Fri Oct  1 07:43:11 CEST 2010</I>
    <P><UL>
        <LI>Previous message: <A HREF="000553.html">[Mageia-dev] Talk of Browsers
</A></li>
        <LI>Next message: <A HREF="000562.html">[Mageia-dev] Talk of Browsers
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#554">[ date ]</a>
              <a href="thread.html#554">[ thread ]</a>
              <a href="subject.html#554">[ subject ]</a>
              <a href="author.html#554">[ author ]</a>
         </LI>
       </UL>
    <HR>  
<!--beginarticle-->
<PRE>On Thu, 30 Sep 2010, Pascal Terjan wrote:

&gt;<i> Well the complexity of the protocol is to allow firefox to download
</I>&gt;<i> only needed part of the blacklist, without sending the url to google
</I>&gt;<i> and without downloading a huge list periodically.
</I>&gt;<i> All the information passed by firefox to google is which chunk of the
</I>&gt;<i> list it wants do download, this being determined by the beginning of
</I>&gt;<i> the hash of the url.
</I>&gt;<i> It would indeed be simpler to send the url.
</I>
Can you state as a fact that Google has no way to reproduce the url or 
at least the domain name of the site the user is visiting based on the 
information passed on by this Firefox feature to Google?
I don't think this can be said with certainty, thanks to the complexity 
of the protocol.

In any case, regardless what data gets passed on, I think we should 
follow the principle of making sure that apps only interact with remote 
services when the user is aware of it, i.e. INFORMED CONSENT, like I 
mentioned in the previous mail.

Therefore any features that interact automatically with remote services 
without the informed consent of the user should be disabled by default.
(the user is still free to enable them at any time, so we are not 
limiting the user in any way)

The following article makes it very clear why this is always a good 
practice to follow:
<A HREF="http://arstechnica.com/security/news/2010/09/some-android-apps-found-to-covertly-send-gps-data-to-advertisers.ars">http://arstechnica.com/security/news/2010/09/some-android-apps-found-to-covertly-send-gps-data-to-advertisers.ars</A>

</PRE>




<!--endarticle-->
    <HR>
    <P><UL>
        <!--threads-->
	<LI>Previous message: <A HREF="000553.html">[Mageia-dev] Talk of Browsers
</A></li>
	<LI>Next message: <A HREF="000562.html">[Mageia-dev] Talk of Browsers
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#554">[ date ]</a>
              <a href="thread.html#554">[ thread ]</a>
              <a href="subject.html#554">[ subject ]</a>
              <a href="author.html#554">[ author ]</a>
         </LI>
       </UL>

<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>