Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,426
30,607



Following user concern over Apple using Chinese company Tencent as one of its Safe Browsing partners for Safari, Apple has issued a statement assuring customers that website URLs are not shared with its safe browsing partners.

For those unfamiliar with the feature, Safari sends data to Google Safe Browsing to cross reference URLs against a blacklist to protect users against scams and malicious sites. It recently came to light that Apple is also using Tencent for this purpose, and there was concern that data from users outside of China was being sent to Tencent.

apple-safari-fraudulent-website-warning-tencet-800x1008.jpeg

According to Apple's statement, that is not the case, and Tencent is used for devices that have their region code set to mainland China. Users in the United States, the UK, and other countries do not have their website browsing checked against Tencent's safe list.
Apple protects user privacy and safeguards your data with Safari Fraudulent Website Warning, a security feature that flags websites known to be malicious in nature. When the feature is enabled, Safari checks the website URL against lists of known websites and displays a warning if the URL the user is visiting is suspected of fraudulent conduct like phishing.

To accomplish this task, Safari receives a list of websites known to be malicious from Google, and for devices with their region code set to mainland China, it receives a list from Tencent. The actual URL of a website you visit is never shared with a safe browsing provider and the feature can be turned off.
Safari occasionally receives a list of hash prefixes of URLs known to be malicious from Google or Tencent, choosing between them based on the device's region setting (Tencent for China, Google for other countries). Hash prefixes are the same across multiple URLs, which means the hash prefix received by Safari does not uniquely identify a URL.

Prior to loading a website, when the fraudulent website warning feature is toggled on, Safari checks whether a website URL has a hash prefix to match the hash prefixes of malicious sites. If a match is found, Safari sends the hash prefix to its safe browsing provider and then asks for the full list of URLs that have a hash prefix that matches the suspicious one.

When Safari receives the list of URLs, it checks the original suspicious URL against the list, and if there is a match, Safari shows the warning pop up suggesting users stay away from the site. The check happens on the user's device, and the URL itself is not shared with the safe browsing provider, but because Safari communicates directly with the safe browsing provider, the providers do receive device IP addresses.

Information about Apple's safe browsing partners can be found in the About Safari and Privacy screen, available in the Privacy and Security section of the Safari portion of the Settings app. Fraudulent website protection is enabled by default, and those still concerned about the safety check feature can turn it off by deselecting the "Fraudulent Website Warning" toggle.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Article Link: Apple Clarifies Tencent's Role in Fraudulent Website Warnings, Says No URL Data is Shared and Checks are Limited to Mainland China
 
Last edited:

s54

Suspended
Sep 25, 2012
505
586
Apple is digging its own grave with all of the recent pro-China (aka pro-CCP) narrative.

First, it was Apple's direct anti-democracy stance against HK and now this. Shame on them. I'm very glad to not have upgraded my iPhone in almost 3 years.
 

1144557

Cancelled
Sep 13, 2018
925
2,413
so everyone freaked out about privacy when in reality the list is cached and evaluated locally for both China and the rest of the world. OK.

I wouldn't say '"everyone," just those ignorant enough to not wait for the full/both sides of the story.

I dont want to get political, but since this is in that section, this is EXACTLY why many many people agree with the President on that topic. There is FAR too much sloppy reporting/rereporting of news that isnt fully vetted before putting out there.

And once a juicy story gets out there statically far far more people see the original story than retraction. The damage is done
 

Nugget

Contributor
Nov 24, 2002
2,122
1,357
Tejas Hill Country
It is so infuriating to read all the posts from people who think this is any kind of privacy concern. There is no problem here at all. Nothing interesting or personal from your device is being sent to Google or Tencent. The system is designed with privacy in mind and the way it works is not suspicious at all.
 

Count Blah

macrumors 68040
Jan 6, 2004
3,192
2,748
US of A
so everyone freaked out about privacy when in reality the list is cached and evaluated locally for both China and the rest of the world and only those that match a list of known problem sites are sent for further evaluation. OK.
So according to you, it’s better if people continued to ignore privacy?

No thanks, I’ll take caution over flippant disregard, any day.
 

jsmith189

macrumors 68000
Jan 12, 2014
1,705
3,406
Looks like i8t's slowly the time to depart from Safari.

If they continue hugging this much with China, looks like it will soon be the time to depart from Apple as well.

I mean, seriously, what the heck, Apple???

How is it "hugging with China" if literally the only people that (voluntarily) deal with the Chinese provider are... people in China? Also, you can turn it off, so this isn't a Safari thing either.

I swear people either don't read or just choose to take out of it what they want lol. This is absolutely a non-issue, but people are seeing trigger words and running with it.
 

thisisnotmyname

macrumors 68020
Oct 22, 2014
2,438
5,251
known but velocity indeterminate
So according to you, it’s better if people continued to ignore privacy?

No thanks, I’ll take caution over flippant disregard, any day.

Where did I say that? I'm very much in favor of strong privacy controls. My comment had to do with the need for everyone to knee-jerk respond to everything immediately without pausing a beat to understand whether it's really an issue or not.
 

1144557

Cancelled
Sep 13, 2018
925
2,413
Looks like i8t's slowly the time to depart from Safari.


If they continue hugging this much with China, looks like it will soon be the time to depart from Apple as well.


I mean, seriously, what the heck, Apple???

Reading is fundamental "for devices with their region code set to mainland China, it receives a list from Tencent " If you live IN CHINA then it goes to Tencent.

Otherwise to Google. So how EXACTLY is leaving Apple for Android (Google) going to help again? Pluhlease do tell.

And if you are in China where do you think other companies go then? To Google which is blocked in China?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.