Firefox Now Uses Google Safe Browsing API
posted by Nick Wilsdon on August 13, 2008Mozilla has integrated Google’s new Safe Browsing Blacklist into the Firefox browser. Users who try to access a page that has been flagged as dangerous will be given an warning page, urging them not to continue.
Phishing Protection is turned on by default in Firefox 2 or later, and works by checking the sites that you browse to against a list of known phishing sites.
This list is automatically downloaded and regularly updated within Firefox when the Phishing Protection feature is enabled. Since phishing attacks can occur very quickly, there’s also an option to check the sites you browse to against an online service for more up-to-date protection. This enhanced capability, and other Phishing Protection settings, can be configured in Firefox’s Security settings.
Here are screenshots of the warning pages shown to users, if you are a FF user then click this link to view the Mozilla test page (safe). If my older copy of Flock is any indication, the warnings used to be given in the form of a pop-up (first screenshot). The site was grayed out but still visible in the background and you could bypass the function by clicking the link “This isn’t a web forgery”.

The latest version of the function in my copy of Firefox 3 is more severe. You are not taken to the site but shown a warning page from Mozilla. The only way to bypass the page is by clicking on the small and more ominous text “Ignore this warning”. While some users could agree that a well-known site was not a forgery, this warning is more direct. It’s not hard to imagine the effect this would have on your site traffic.

This move makes quick detection of malware of phishing on your site more important than ever. Firefox are reported to hold upwards of 25% marketshare but in some industry section, especially tech, this can be even higher. Microsoft has recently stated that IE 8 will also have an anti-malware filter. Jose Francisco Bonnin has already released code for IE which will integrate Google’s API results into the application.
Sign up to a free SERPGuard account and receive email and RSS warnings if your site(s) are blacklisted.

|
Leave a Reply