Add Google Safe Browsing protection for end-users
This sounds a good idea, and agreed that existing "safety nets" are quite lacking... Also proxying the API would be non-trivial at scale, unless you wanted to build out infrastructure to do that quickly (i.e. some kind of cache-or-fetch-and-cache)
Realistically most users will get to a bad site either via a search engine (more likely... an ad on a search engine, which Orion + Kagi will avoid), or clicking a link in email. That is handled by most webmail services now (and even some non-web mail) by their protection systems that rewrite links (yuck... but it works for non expert users I guess).
For a real targeted attack you will use a new URL that isn't on a blacklist, so I guess these measures have reducing value in an era of free SSLs and cheap domains!
I think that if someoen wanted something along these lines, they could get something similar-ish with a DNS-based blocking system, such as nextDNS, controlD, etc
though some "adblocker" extensions, eg uBO, also can block these websites, if you set them up to do so
- Edited
Steps to reproduce:
secure http(replace with <https>)://sv.kuvio.cfd/AwETGAx_Pw9CEdkIpVGEkRveeAusJQ6cPxDCX6_pY6DgcYS5_8pNr-ux_8VM2Qscz_ELQYmQj8xx_k3yhjoRTtj1x2_e5E-Bcoiz16wXkTVErQ==?ci=5858952518452624914&n3er=yZSq5A==&fn=Microsoft%20Powerpoint%202019%20VL%2016.46&sd=759782&uu=lIaJhrzOpHZ7iXp6d32Oenx9iHk=!<
Expected behavior:
I shouldn't be able to visit this webpage. It could have some mysterious zero-day and the whole system is infected.
Orion, OS version; hardware type:
Orion 0.99.125.3-rc
Image/Video:
btw its a good idea to replace https with smth like hxxps to prevent it from turning into a hyperlink
Orion is a web browser and is supposed to allow you to visit any site possible.
Even Google’s safe browsing does not block all malicious links. There’s no way to block a threat that isn’t yet known to exist. Unless one could see the future, it’s impossible to proactively block all malicious websites. This is not a problem that Orion can do anything about.
Instead what you should do is upvote the post for custom blocklists.