Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

91–100 of 713 posts

Re: Google flags Immich sites as dangerous

#91
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

The issue isn't the user-hosted content - I'm running a release build of Immich on my own server and Google flagged my entire domain.

Re: Google flags Immich sites as dangerous

#92

Insane that one company can dictate what websites you're allowed to visit. Telling you what apps you can run wasn't far enough.

I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.

unfortunately nobody wants to sacrifice anything nowadays so everyone will keep using google, and microsoft, and tiktok and meta and blah blah

Re: Google flags Immich sites as dangerous

#93
post #76
post #71

Earlier quoted context omitted.

"The engineering equivalent of a car made of duct tape" Kind of. But do you have a better proposition?

A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionabl…

"You could take about 90% of that out and into dedicated tools "

But then you would loose plattform independency, the main selling point of this atrocity.

Having all those APIs in a sandbox that mostly just work on billion devices is pretty powerful and a potential succesor to HTML would have to beat that, to be adopted.

The best thing to happen, that I can see, is that a sane subset crystalizes, that people start to use dominantly, with the rest becoming legacy, only maintained to have it still working.

But I do dream of a fresh rewrite of the web since university (and the web was way slimmer back then), but I got a bit more pragmatic and I think I understood now the massive problem of solving trusted human communication better. It ain't easy in the real world.

Re: Google flags Immich sites as dangerous

#94
post #76
post #71

Earlier quoted context omitted.

"The engineering equivalent of a car made of duct tape" Kind of. But do you have a better proposition?

A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionabl…

>A part of the issue is IMO that browsers have become ridiculously bloated everything-programs.

I don't see how that solves the issue that PSL tries to fix. I was a script kiddy hosting neopets phishing pages on free cpanel servers from .ripway.com back in 2007. Browsers were way less capable then.

Re: Google flags Immich sites as dangerous

#95
post #89
post #74

Earlier quoted context omitted.

>GoDaddy or any other hosting site mentions public suffix They don't need to mention it because they handle it on behalf of the client. Them recommending best practices like using separate domains makes as much sense as them recommending what TLS configs to use. >or where Apple or Google or Mozilla have a listing hosting best practices that include avoiding false positives by Safe Browsing… Since were those sites the…

The underlying question is how are people supposed to know about this before they have a big problem ?

[flagged]

Re: Google flags Immich sites as dangerous

#96
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

Looking through some of the links in this post, I there are actually two separate issues here:

1. Immich hosts user content on their domain. And should thus be on the public suffic list.

2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and possibly a domain that might look suspicious to someone unfamiliar with the project, because it includes the name of the software in the domain. Something like immich.example.com.

The first one is fairly straightforward to deal with, if you know about the public suffix list. I don't know of a good solution for the second though.

Re: Google flags Immich sites as dangerous

#97
post #76

Earlier quoted context omitted.

A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionabl…

> A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. I don't see how that solves the issue that PSL tries to fix. I was a script kiddy hosting neopets phishing pages on free cpanel servers from .ripway.com back in 2007. Browsers were way less capable then.

PSL and the way cookies work is just part of the mess. A new approach could solve that in a different way, taking into account all the experience we had with scriptkiddies and professional scammers and pishers since then. But I also don't really have an idea where and how to start.

Re: Google flags Immich sites as dangerous

#98

Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge

Some of these seem less cursed, and more just security design?

>Some phones will silently strip GPS data from images when apps without location permission try to access them.

That strikes me as the right thing to do?

Re: Google flags Immich sites as dangerous

#99
The same thing happened to me earlier this year with a self-hosted instance of Umami Analytics.

https://news.ycombinator.com/item?id=42779544#42783321

Unironically, including a threat of legal action in my appeal on the Google Search Console was what stopped our instance getting flagged in the end.

Re: Google flags Immich sites as dangerous

#100
Maybe a dumb question but what constitutes user-hosted-content?

Is a notion page, github repo, or google doc that has user submitted content that can be publicly shared also user-hosted?

IMO Google should not be able to use definitive language "Dangerous website" if its automated process is not definitive/accurate. A false flag can erode customer trust.

Post reply on HN