cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
rcs
New member
Status: New idea

The Firefox Phishing and Malware Protection feature can provide information to Mozilla partners and it is advantageous to make providing that data optional.  It would also be better to make when and how that information is provided transparent to the user.

PROBLEM

Per this Mozilla Support article there are two times when Firefox communicates with Mozilla’s partners while using Phishing and Malware Protection for sites: (1) regular updates to the list of potential threat sites, and (2) checking the safety of "certain executable files".  Case 1 consumes data and case 2 provides data.

DIAGNOSIS

At the nation-state or mega corporate actor level, these cases present threats:

  • Case 1 uniformly consumes data for all users of the service, which could be used for browser fingerprinting because use of that service is elective.
  • Case 2 selectively provides data from unique individuals.  Although the file data may not be readily tied to the user per se by Mozilla or a partner, that traffic could be correlated with other data by nation-state or mega corporate entities to tie the user to each potential threat and whatever conclusions the correlating organizations choose to make about those individuals attempting to access that content (since the format of the executable file metadata is well known, any metadata transmission is cryptographically insecure from nation-state or mega corporate threat actors).
  • There is no transparency to the Firefox user on when or to what partner facility the threat metadata is provided to.

CURE

Provide a configuration option for the Firefox Phishing and Malware Protection feature to optionally turn on the use case 1 and/or use case 2 facilities, such that a user could leverage the blocking of potential threat sites without having to also volunteer information to Mozilla partners.  However adding configuration options to (a) ask the user IF that information should be provided to a partner (similar to prompting where to download a file), (b) TO WHOM that information is provided, and (c) WHAT services that information is provided to (e.g. Google Safe Browsing, Virus Total, etc.). 

Example remediations for the Deceptive content and dangerous software protection settings in Firefox:

  • Add a check box "Block known Phishing and Malware sites using local list in Firefox"
  • Add a check box "Check unknown files using Mozilla security partners"

and then less important but ideally:

  • Add advanced settings for security partner services with options similar to DNS over HTTPS with [ Default | Custom | Off ] selections for which partners and partner services information is provided to.

BENEFITS

  • User can elect to consume security data to block threat sites but not reveal any data to partners.
  • User can opt out of providing information to partners.
  • User can elect to provide information to partners for specific instances rather than everything not in the threat site list.
  • User can elect to provide information to specific partner facilities that the user trusts or wants to contribute to.
  • Mozilla and the user have a workaround should a partner violate the trust of Mozilla and the user (intentionally or unintentionally).
  • These options would provide yet another way Mozilla prioritizes security, transparency, and choice in Firefox.
1 Comment
Status changed to: New idea
Jon
Community Manager
Community Manager

Thanks for submitting an idea to the Mozilla Connect community! Your idea is now open to votes (aka kudos) and comments.