Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

71–80 of 713 posts

Re: Google flags Immich sites as dangerous

#71
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

"The engineering equivalent of a car made of duct tape"

Kind of. But do you have a better proposition?

Re: Google flags Immich sites as dangerous

#72
post #32

Tangential to the flagging issue, but is there any documentation on how Immich is doing the PR site generation feature? That seems pretty cool, and I'd be curious to learn more.

Pretty sure Immich is on github, so I assume they have a workflow for it, but in case you're interested in this concept in general, gitlab has first-class support for this which I've been using for years: https://docs.gitlab.com/ci/review_apps/ . Very cool and handy stuff.

Re: Google flags Immich sites as dangerous

#73

Them maintaining a page of gotchas is a really cool idea - https://immich.app/cursed-knowledge

> There is a user in the JavaScript community who goes around adding "backwards compatibility" to projects. They do this by adding 50 extra package dependencies to your project, which are maintained by them.

This is a spicy one, would love to know more.

Re: Google flags Immich sites as dangerous

#74
post #57

Earlier quoted context omitted.

[flagged]

Please point me to where GoDaddy or any other hosting site mentions public suffix, or where Apple or Google or Mozilla have a listing hosting best practices that include avoiding false positives by Safe Browsing…

>GoDaddy or any other hosting site mentions public suffix

They don't need to mention it because they handle it on behalf of the client. Them recommending best practices like using separate domains makes as much sense as them recommending what TLS configs to use.

>or where Apple or Google or Mozilla have a listing hosting best practices that include avoiding false positives by Safe Browsing…

Since were those sites the go to place to learn how to host a site? Apple doesn't offer anything related to web hosting besides "a computer that can run nginx". Google might be the place to ask if you were your aunt and "google" means "internet" to her. Mozilla is the most plausible one because they host MDN, but hosting documentation on HTML/CSS/JS doesn't necessarily mean they offer hosting advice, any more than expecting docs.djangoproject.com to contain hosting advice.

Re: Google flags Immich sites as dangerous

#75
post #54

The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

> The one thing I never understood about these warnings is how they don't run afoul of libel laws.

I’m not a lawyer, but this hasn’t ever been taken to court, has it? It might qualify as libel.

Re: Google flags Immich sites as dangerous

#76
post #71

Earlier quoted context omitted.

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

"The engineering equivalent of a car made of duct tape" Kind of. But do you have a better proposition?

A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionable utility.

End of random rant.

Re: Google flags Immich sites as dangerous

#77
post #56
post #44

Is there any linkage to the semifactoid that immich Web gui looks very like Google Photos or is that just one of the coincidences?

Not a coincidence, Immich was started as a personal replacement for Google Photos.

The coincidence here would be google flagging it as malware, not the origin story of the look and feel.

Re: Google flags Immich sites as dangerous

#79

Them maintaining a page of gotchas is a really cool idea - https://immich.app/cursed-knowledge

> There is a user in the JavaScript community who goes around adding "backwards compatibility" to projects. They do this by adding 50 extra package dependencies to your project, which are maintained by them. This is a spicy one, would love to know more.

It links to a commit; the removed deps are by GitHub user ljharb.

Re: Google flags Immich sites as dangerous

#80

Insane that one company can dictate what websites you're allowed to visit. Telling you what apps you can run wasn't far enough.

I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.

Absolutely fuck Google
Post reply on HN