The G privilege.In actuality, it is not limited to Vivaldi because it is absent from all browsers except Chrome.
Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
The G privilege.In actuality, it is not limited to Vivaldi because it is absent from all browsers except Chrome.
Let's analyze your responseYour read of Google’s wording is reasonable, but it helps to separate “known to Google Search” from “known to Safe Browsing,” and to understand what “unknown” can mean in practice.
“Unknown websites” does not necessarily mean “rare”
Google’s indexing/crawling for Search is a different system from Safe Browsing reputation and classification. A site can be “indexed” (or simply exist) without being “known/assessed enough” for Safe Browsing’s purposes at the moment you visit it.
“Unknown” can include things like:
- Newly registered domains and freshly created subdomains
- Short-lived phishing/scam infrastructure
- New URLs/paths on otherwise known domains (Safe Browsing often reasons at URL-level granularity, not just domain-level)
- Redirect chains and tracking links
- CDN-hosted content, file download URLs, and “one-off” campaign links
So it’s true that Enhanced Protection isn’t designed to upload full telemetry for every normal page view, but “unknown” can still be triggered more often than many users expect, especially if you browse broadly, click external links, or encounter lots of redirects.
Agree but you don't know what the privacy policy is of the services it sends your shortened URL to.The use of Osprey also respects privacy.
I believe that, given how my Chrome is configured, using Standard Protection is an excellent compromise, even from a privacy perspective.
You’re right that every one of those categories is also a legitimate “high risk” signal, and from a pure security angle it makes sense to scrutinize them harder. The disagreement in these discussions usually isn’t “is it wrong to check?”, it’s “is it acceptable to share more of my browsing data with a vendor to enable that checking?”Let's analyze your response
1. Analyse Newly registered or newly seen.
Have a look at URLHAUS arround 95% to 99% of the malware and phishing classifies as "new" because most are short lived
2. Short-lived phishing/scam infrastrructure
Again what is wrong about checking them?
3. New URL's/paths on ontherwise known domains
Mhww that is a valid point, but these are also typical for hacked websites being used as "download" donkeys for malware distribution? So what is wrong about checking them
4. Redirect chains and tracking linkc
Chrome itself has a maximum on redirection and blocks it. It would not have implemented this practice when multiple redirection was not a way of malware distribution, so again what is wrong about this?
5. CDN-hosted content, file download URLs, and “one-off” campaign links
File download URL's should be checked so again, well done Chrome advanced malware protection. One-off's classify as new in my book and I don;t mind them being checked either.
Conclusion:
Only the CDN-hosted and one-off campaigns are the ones which I would not have chosen to send to Google servers. Compare that to Microsoft's advanced protection (sending every URL) and I still don't understand why Google's protection has such a bad name, compared to Edge (which is worst in terms of privacy when you compare head to head).
Agree but you don't know what the privacy policy is of the services it sends your shortened URL to.
Well I certainly agree on the Trust and incentives point you are raising. About the third point (URL sensitivity) may i remind you that Google promises to make them non-identifiable (and please @Bot don't start a discussion on this). This thread was intended to put things in perspective about the second point (optics and misunderstanding), (so @Bot thanks for helping out and raising this "Trust and incentives" aspect).You’re right that every one of those categories is also a legitimate “high risk” signal, and from a pure security angle it makes sense to scrutinize them harder.
So why does Google Enhanced Protection get a “bad name,” while Edge is often tolerated?
A few non-technical reasons drive this more than the actual mechanics:
- Trust and incentives: Google’s core business is advertising. Even if Safe Browsing is a separate security system with documented safeguards, many privacy-focused users are less willing to grant Google additional browsing-related signals than they are with a vendor they already “expect telemetry from.”
- Optics and misunderstandings: a lot of people oversimplify it to “Enhanced = sends everything,” which is not what Google documents. That bad simplification spreads easily.
- URL sensitivity: even “just URLs” can be very sensitive because URLs frequently contain identifiers and intent. Users who’ve been burned by link-based identifiers (invite links, reset links, shared docs) tend to default to minimizing any full-URL disclosure.
That’s a fair way to frame it.Well I certainly agree on the Trust and incentives point you are raising. About the third point (URL sensitivity) may i remind you that Google promises to make them non-identifiable (and please @Bot don't start a discussion on this). This thread was intended to put things in perspective about the second point (optics and misunderstanding), (so @Bot thanks for helping out and raising this "Trust and incentives" aspect).
I am happy with the conclusion: Google's enhanced security actually does not have a bad privacy policy. Problem is that the executing organisation of that policy has a questionable reputation on that matter.
Avira Browser Safety as long as it is German (Avast transferred legal to US for browser plugin already) and not Gen Digital is okay (they should only keep anonymized known bad URL hits).Indeed, Brave has proxied Google Safe Browsing requests since they implemented it in 2018. No data is directly communicated with Google.
Safe Browsing already promoted privacy as a standard by using partial hash matching since 2007. Brave periodically downloads a local hash prefix list through the proxy for this purpose, and full hashes are only compared in the case of a prefix match.
I do recommend bolstering your browser security by adding another reputation and URL blocking service to your setup, but it's unlikely to be quite as privacy-friendly.
I don't use the browser plugin, just Web Guard. As a user in the US, my Avast data is stored and processed by Gen Digital Inc. in the United States according to this privacy policy statement:Avira Browser Safety as long as it is German (Avast transferred legal to US for browser plugin already) and not Gen Digital is okay (they should only keep anonymized known bad URL hits).
For EEA users, the primary controller is often Avast Software s.r.o. (Czech Republic) or NortonLifeLock Ireland Limited, but your data may still be transferred to and processed by Gen Digital entities elsewhere.Note that samples (files, URLs and other malicious identifiers) used for malware and scam analysis are kept in our systems as long as it is necessary to ensure proper functionality of the AV product. These samples are not connected with users or other individuals and the retention periods indicated above do not apply to this use.
…We collect much of this data in a pseudonymized or anonymized form…
Location Data may include:
Device Data may include:
- IP address
Security Data may include:
- Operating system (including version or platform)
- Browser type, version, and settings
Product Data may include:
- Browsing activity
- Search terms
- Product version and preferred Language
- URL of blocked websites
- Metadata (e.g., number of blocked websites and number of unsafe websites clicked)
Members who viewed this thread in the last 5 minutes