Skip to content

Security hints: URLhaus reputation provider #286

Description

@mortenn

Part of #285, #249, and meta #245.

Provider

URLhaus by abuse.ch.

Fit

Best first reputation-provider candidate. It has a focused malware URL use case and clearer product fit than broad public reputation APIs. It is not a general phishing or website safety verdict provider.

Data Sent

Depending on endpoint, Browser Picker may send the full URL or host to URLhaus. The UI must disclose the exact value before the request starts.

API / Terms Notes

URLhaus API use requires an abuse.ch Auth-Key. The community API is available under fair-use principles, while commercial or for-profit use may require the enhanced commercial API. URLhaus focuses on active malware distribution URLs and excludes many broader abuse categories such as phishing-only reports.

Acceptance Notes

  • Disabled by default.
  • User-triggered only unless a future automatic-check setting explicitly enables reputation checks.
  • Bring-your-own Auth-Key; never bundle a shared key.
  • Do not log the submitted URL, host, or Auth-Key.
  • Handle rate limits, provider failures, and inconclusive results as neutral states.
  • Make clear that a no-match result does not mean the URL is safe.
  • Do not automatically call this provider when a URL matches Defaults.

Out of Scope

  • Submitting URLs to URLhaus.
  • Treating URLhaus as a phishing verdict provider.
  • RDAP or public CT history lookups.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions