Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Apple clarifies Safari Safe Browsing feature following Tencent data reports [u]

Apple uses Safe Browsing systems from Google to protect against phishing

Last updated

Following a report alleging that Safari was sending URLs to China, Apple has clarified that this is not the case and has detailed how the Safe Browsing feature works.

Reports on Monday claimed Apple has been sending browsing data to Chinese technology firm Tencent as part of its anti-phishing systems, and may be expanding how much it uses the firm. From iOS 11 in 2017, Apple has stated on devices bought in China that it uses Tencent, but at some point that same privacy notice has appeared on US iPhones and iPads too.

The information is contained with a privacy notice that is reached via Settings, Safari, About Safari Search & Privacy. It's not clear when this detail was added, but users on Twitter claim to have seen it from iOS 12.2. It is now on all iOS 13 devices.

Apple uses the service as part of its anti-phishing features, and specifically the iOS Fraudulent Website Warning. This is the service that detects when a site may be masquerading as another one, or may contain malware.

Apple has now responded to the claims with a statement to AppleInsider and other venues.

Apple protects user privacy and safeguards your data with Safari Fraudulent Website Warning, a security feature that flags websites known to be malicious in nature.When the feature is enabled, Safari checks the website URL against lists of known websites and displays a warning if the URL the user is visiting is suspected of fraudulent conduct like phishing.

To accomplish this task, Safari receives a list of websites known to be malicious from Google, and for devices with their region code set to mainland China, it receives a list from Tencent. The actual URL of a website you visit is never shared with a safe browsing provider and the feature can be turned off.

The Safari privacy notice that now includes mention of Tencent The Safari privacy notice that now includes mention of Tencent

Apple's privacy notice does describe the overall process for both firms.

"Before visiting a website, Safari may send information calculated from the website address to Google Safe Browsing and Tencent Safe Browsing to check if the website is fraudulent," it says.

Significantly, it also cautions that the website address may not be the only data that these companies receive.

"These safe browsing providers may also log your IP address," it adds.

The presence of Tencent in the privacy information does not mean that data is being sent to the firm, only that Apple may use it for this feature when needed. The possible logging of IP addresses by either Google or Tencent may be necessary for their phishing prevention systems.

However, Apple did not announce the use of this second company in what is a significant area of its privacy work. And the Fraudulent Website Warning feature is turned on by default.

To turn it off, go to Settings, Safari and toggle Fraudulent Website Warning. Note, however, that you will then lose the protection against malicious sites.

Updated: 12:40 ET: Updated with response from Apple.



51 Comments

gatorguy 24627 comments · 13 Years

Yeah, I was waiting on this story to hit AI. What started out a a drip of China/Apple issues is turning into a faucet. 

Curiously while other parts of Apple's Chinese ToS appears only on Chinese handsets (ie iCloud), this disclosure of Tencent receiving browsing data also appears on US handsets. 

Before the expected sideshow of "Can't be worse than Google" begins Google uses a number of methods to ensure they can't know the exact webpage you are attempting to visit in any particular instance, maintaining user privacy in Fraudulent Website checks.  There is no such assurance from Tencent and it's automatically allowed unless you disable it. But that also requires Fraud warnings from Google be turned off as well which makes it not such a good idea to disable for many. The two services should have separate toggles., not an all or nothing.

doctwelve 56 comments · 6 Years

Et tu AI? You were the guys who fought against the apple-bashing on engadget and the verge and lately you've been jumping on the bandwagon. I expect this kind of click-bait crap from macrumors now, but not you. If you think Apple is flagrantly opening their user's privacy to nefarious Chinese officials just because then I don't know what to say. 

rotateleftbyte 1630 comments · 12 Years

Google or Tencent? Which is the less nasty? Difficult to say really.
I really don't want my data even if it is for site validation going anywhere near Google. As I'm highly unlikely to ever go to China then Tencent is not that a problem to me.
Google gets everywhere and into everything. Everything we do it feeding its inasiable appetite for spying on each and everyone of us.

CloudTalkin 916 comments · 5 Years

gatorguy said:
Yeah, I was waiting on this story to hit AI. What started out a a drip is turning into a faucet. 

This is really a yawn though.  Tencent already gets copious amounts of data from Apple users.  They get copious amounts of data from users of every platform... especially if those users are gamers.  It seems every site is copying and pasting the same info without actually paying attention to who the company is they're referencing here.  Tencent is beast.  They have been receiving more relevant customer data from all platforms for years.  Comparatively speaking this situation is nothing, but viewed through the lens of the last week of Apple's Chinese acquiescence, I can see why people are a bit up in arms. 

I've seen people on other sites yammering about how to turn off Safe Browsing.  As if that would stop the flow of info going to Tencent.  Ha! Complete waste of time.

gatorguy 24627 comments · 13 Years

gatorguy said:
Yeah, I was waiting on this story to hit AI. What started out a a drip is turning into a faucet. 
This is really a yawn though.  Tencent already gets copious amounts of data from Apple users.  They get copious amounts of data from users of every platform... especially if those users are gamers.  It seems every site is copying and pasting the same info without actually paying attention to who the company is they're referencing here.  Tencent is beast.  They have been receiving more relevant customer data from all platforms for years.  Comparatively speaking this situation is nothing, but viewed through the lens of the last week of Apple's Chinese acquiescence, I can see why people are a bit up in arms. 

I've seen people on other sites yammering about how to turn off Safe Browsing.  As if that would stop the flow of info going to Tencent.  Ha! 

Agreed. Fraudulent Websites checks in a relative molehill in the larger data stockpiling picture.