Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

51–60 of 713 posts

Re: Google flags Immich sites as dangerous

#51
post #32

Tangential to the flagging issue, but is there any documentation on how Immich is doing the PR site generation feature? That seems pretty cool, and I'd be curious to learn more.

It's open source, you can find this trivially yourself in less than a minute.

https://github.com/immich-app/devtools/tree/a9257b33b5fb2d30...

Re: Google flags Immich sites as dangerous

#52
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

I think it's somewhat tribal webdev knowledge that if you host user generated content you need to be on the PSL otherwise you'll eventually end up where Immich is now. I'm not sure how people not already having hit this very issue before is supposed to know about it beforehand though, one of those things that you don't really come across until you're hit by it.

so its skill issue ??? or just google being bad????

Re: Google flags Immich sites as dangerous

#53
post #14

Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge

The Postgres query parameters one is funny. 65k parameters is not enough for you?!

> PostgreSQL USER is cursed > The USER keyword in PostgreSQL is cursed because you can select from it like a table, which leads to confusion if you have a table name user as well.

is even funnier :D

Re: Google flags Immich sites as dangerous

#54
The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables.

They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

Re: Google flags Immich sites as dangerous

#55
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

The root cause is bad behaviour by google. This is merely a workaround.

Re: Google flags Immich sites as dangerous

#57
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

The root cause is bad behaviour by google. This is merely a workaround.

[flagged]

Re: Google flags Immich sites as dangerous

#58
post #42

google: we make going to the DMV look delightful by comparison!

They are not the government and should not have this vast, unaccountable monopoly power with no accountability and no customer service.

the government probably shouldn't either?

Re: Google flags Immich sites as dangerous

#59
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

This is not about user content, but about their own preview environments! Google decided their preview environments were impersonating... Something? And decided to block the entire domain.

Re: Google flags Immich sites as dangerous

#60
post #57

Earlier quoted context omitted.

The root cause is bad behaviour by google. This is merely a workaround.

[flagged]

>You might not think it is, but internet is filled utterly dangerous, scammy, phisy, malwary websites

Google is happy to take their money and show scammy ads. Google ads are the most common vector for fake software support scams. Most people google something like "microsoft support" and end up there. Has Google ever banned their own ad domains?

Google is the last entity I would trust to be neutral here.

Post reply on HN