友情提醒:苹果手机要把这个关掉!不然信息会回传腾讯!

l
lcccbwmm
楼主 (北美华人网)
Apple's Fraudulent Website Warning feature in Safari for iOS and Mac has [url=https://reclaimthenet.org/apple-safari-ip-addresses-tencent/]come under scrutiny[/url] for using Chinese internet giant Tencent as one of its Safe Browsing providers.

The Safari feature has long sent data to Google Safe Browsing to cross-reference URLs against a blacklist and protect users against phishing scams and sites that attempt to push malware. However, it's unclear when Apple started sending user data to Tencent as well.

Apple notes in iOS that it sends some user IP addresses to Tencent, but most users are probably unaware of the fact. The mention can be found in the "About Safari & Privacy" screen, which is linked via small text under the Privacy & Security section in Settings -> Safari. The Fraudulent Website Warning feature also found here is enabled by default, so users aren't likely to know that their IP address may be logged unless they opt to view the information screen.

Apple's reference to Tencent has been found on devices running [url=https://www.macrumors.com/roundup/ios-13/]iOS 13[/url], but some [url=https://rd2.huaren.us/huaren.php?hrtopic_id=2462962&hrurl=https%3a%2f%2ftwitter.com%2fStijnDV%2fstatus%2f1092515697694003200%3fref_src%3dtwsrc%255Etfw%257Ctwcamp%255Etweetembed%257Ctwterm%255E1092515697694003200%26amp%3bref_url%3dhttps%253A%252F%252Freclaimthenet.org%252Fapple-safari-ip-addresses-tencent%252F]tweets[/url] suggest versions as early as iOS 12.2 also included the Chinese company as a safe browsing provider.

At this point, it's difficult to know for sure whether Apple users residing outside of China are having their data sent to Tencent, but the company appears to be mentioned on iPhones and iPads registered in the U.S. and the U.K., and possibly in other countries, too.


The privacy implications of shifting Safe Browsing to Tencent's servers are unknown, because Apple hasn't said much about it. However, according to Johns Hopkins University professor [url=https://blog.cryptographyengineering.com/2019/10/13/dear-apple-safe-browsing-might-not-be-that-safe/]Matthew Green[/url], a malicious provider could theoretically use Google's Safe Browsing approach to de-anonymize a user by linking their site requests.

Apple's [url=https://www.macrumors.com/2019/10/13/apple-tv-shows-told-avoid-china-criticism/]relationship with the Chinese government[/url] has come in for [url=https://www.macrumors.com/2019/10/11/tim-cook-defends-removal-hkmaplive-from-app-store/]increasing criticism[/url] lately, and that could make customers uneasy about Apple's links to Tencent, which is known to [url=https://www.bloomberg.com/news/articles/2019-08-06/tencent-helps-communist-party-pay-homage-to-the-china-dream]work closely with the Chinese Communist Party[/url].

As such, Green believes users "deserve to be informed about this kind of change and to make choices about it. At very least, users should learn about these changes before Apple pushes the feature into production, and thus asks millions of their customers to trust them."

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our [url=https://forums.macrumors.com/forumdisplay.php?f=47]Politics, Religion, Social Issues[/url] forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.
l
lcccbwmm
星球大战
在美国买的没事吧
l
lcccbwmm
小心为上,美国买的也是中国产的,出产设置这项就是打开的,唉,心塞,科技越发达越不安全
蓝光加湿器
据说美国是发给Google
h
healthy
到底是要关了这个还是开了这个好?没看懂
d
durkin
美国手机是发给哪里?对我来说发给google和发给tecent差很多的。
S
Shirleyba
不是应该开着吗
p
pmmp
到底是要enable还是disable? ---发自Huaren 官方 iOS APP
A
AbeLoveMe
disable,因为开着就会自动计算把你信息送给人。
c
completefull
美国买的居然是enabled
赶紧把它关了
d
drchao
苹果回应: 这个新增的“诈骗网站警告”服务,其实是为了帮助用户避开已经被辨识的诈骗网站,默认是采用Google提供的网站列表,但因为中国地区无法使用Google服务,因此,区域设定为中国的装置,则改从腾讯接收诈骗网站列表。
n
namamae
杞人忧天,没啥问题的。。 在中国,不用腾讯你用谁?
冰是睡着的水
中国寄过来的,刚看了一下,是打开的,难道关掉? google 和腾讯有啥区别?
l
lookinghard
我坚决不能让系书记看到我看的黄色网站。 积极支持LZ的建议,如何中国的都是坏的。也包括中国人。 逢中必反,最后反到中国人
l
laalaatou
如果disable,会不会不小心点击了诈骗网站被窃取信息呢?
H
HeyStranger
美国手机是发给哪里?对我来说发给google和发给tecent差很多的。
durkin 发表于 10/16/2019 2:16:47 PM [url=https://forums.huaren.us/showtopic.aspx?topicid=2462962&postid=81635178#81635178][img][/img][/url]

你要是长期在美国呆的话那就不一定了
y
yogi
同问
如果disable,会不会不小心点击了诈骗网站被窃取信息呢? laalaatou 发表于 10/16/2019 4:56:00 PM [url=https://forums.huaren.us/showtopic.aspx?topicid=81636546&postid=81636546#81636546][img][/img][/url]
我想我是疯了
我去,如果真的,Apple 可以被告吧?
为什么我只有privacy没有privacy and security这个选项?
水蓝
多谢楼主提醒。最近发现手机设置里不少项都是自动默认允许的,但是我记得曾经关掉过的。还有那个最新版本的更新,据说手机会慢,而且打电话的时候容易断线。
y
yangyangzj
为什么我这边是不能改的啊!
d
doudouyzgf
我的也不能改


为什么我这边是不能改的啊!

yangyangzj 发表于 10/16/2019 8:30:00 PM
T
TuscanSun
我的改不了

☆ 发自 iPhone 华人一网 1.14.05
w
wohoy
Mark. ---发自Huaren 官方 iOS APP
g
goodboys
有没有明白人来科普一下?到底要不要DISABLE啊?
l
lcccbwmm
到底是要关了这个还是开了这个好?没看懂
healthy 发表于 10/16/2019 2:14:12 PM


文章里面就是提醒要关了,disable,不然会在发送欺诈钓鱼网站的同时把使用者手机的IP地址也发给腾讯。
l
lcccbwmm
华盛顿邮报:据分析,“学习强国”app通过内置后门可以收集其一亿多用户的手机数据
https://www.washingtonpost.com/world/asia_pacific/chinese-app-on-xis-ideology-allows-data-access-to-100-million-users-phones-report-says/2019/10/11/2d53bbae-eb4d-11e9-bafb-da248f8d5734_story.html

The Chinese Communist Party appears to have “superuser” access to the entire data on more than 100 million Android-based cellphones through a back door in a propaganda app that the government has been promoting aggressively this year.

https://pincong.rocks/article/6553
d
dupont2009
为什么我这边是不能改的啊!
yangyangzj 发表于 10/16/2019 8:30:44 PM
l
lcccbwmm
各大网站都有报道,大数据监控只有中国人自己昏昏欲睡,欧美都慢慢觉醒了

https://www.msn.com/en-us/news/technology/chinese-app-on-xis-ideology-allows-data-access-to-100-million-users-phones-report-says/ar-AAIGo5K

Chinese app on Xi’s ideology allows data access to users’ phones, report says

https://www.cnbc.com/2019/10/14/china-xi-jinping-ideology-app-has-backdoor-that-could-let-beijing-snoop-on-users-report.html

Chinese app pushing Xi’s ideology has ‘backdoor’ that could let Beijing snoop on users, report says
t
tangchaoren
应该是打开。防止被恶意恶性网站钓鱼。
mitbbs的某猥琐男经常发的帖子里有钓鱼网页链接,iphone开着这个选项,你的信息和手机电脑就很难被泄漏被黑。
腾讯和google获取你的信息,只要装了微信和引擎,信息自动收录。NSC也有你的全套信息。
类比一下,你的信用卡信息,可以被大公司知道,但不能被黑客和个人钓鱼。
有没有明白人来科普一下?到底要不要DISABLE啊?
goodboys 发表于 10/16/2019 10:32:47 PM

如果你想去一个银行网站,然后去的是假的那个。如果enable了,网页会显示这个是个假网站。如果disable了,你就不知道然后会照常输入你的密码,就给盗用了。你觉得第三方认证能拿到你什么信息?只是你的IP和去的网站而已,有什么大不了的?
l
lcccbwmm

如果你想去一个银行网站,然后去的是假的那个。如果enable了,网页会显示这个是个假网站。如果disable了,你就不知道然后会照常输入你的密码,就给盗用了。你觉得第三方认证能拿到你什么信息?只是你的IP和去的网站而已,有什么大不了的?

睿 发表于 10/16/2019 11:04:51 PM


嗯,你别关,在每天用个强国软件最安全。
t
troy2011
这个是提醒你去的网站是不是钓鱼网站。你自己不在乎去不去钓鱼网站当然可以关掉了。 还有这个东西就算要送信息,难道不是送给苹果或者Google?怎么会给腾讯了?为啥老是不懂然后就发这种危言耸听的信息?难道自己不会狗一下?

☆ 发自 iPhone 华人一网 1.14.05


嗯,你别关,在每天用个强国软件最安全。

lcccbwmm 发表于 10/16/2019 11:19:46 PM


你的IP和去什么网站,你知道你输入网址到打开网页一路上多少服务器有记录你这个request吗?从你的internet provider,到路上的路由器,到那个网站的服务器,都有这个记录,不要说政府也有记录。你以为关了那个就没有了,只是少一个而已,而且自己风险大好多。