#667050 iceweasel: "Block reported attack sites/web forgeries" should mention its use of Google and allow opt-out #667050
- Package:
- iceweasel
- Source:
- firefox-esr
- Submitter:
- "Stephen Crowley"
- Date:
- 2025-09-18 07:31:20 UTC
- Severity:
- normal
Dear Maintainer, I was curious about the following excessive access to the url GET http://safebrowsing-cache.google.com/safebrowsing/... and realized it was coming from firefox by having the "Block reported attack sites/web forgeries" option. I consider this network spam a bit of a security risk considering all the skullduggery going on with the net these days, at the very least the menu option should explicltly state that it will bombard google with requests for this data.
Why does it matter that the data comes from google specifically? BTW, it's only downloading a list or a delta if you already have a list locally. It's not sending anything related to your browsing. If you click on help, you're brought to a page that explains the settings, and which contains a link to a page explaining how the feature works. Mike
src:iceweasel has been superseded by src:firefox-esr in version 45.0esr-1 in March 2016. Transitional packages to ease upgrades were provided in the wheezy, jessie, stretch and buster releases. The transitional packages have been removed finally before the bullseye release in August 2021. After regular security support for buster ended in August 2022 and LTS support ended in June 2024, I'm closing the remaining bug reports now. Andreas