Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

101–110 of 713 posts

Re: Google flags Immich sites as dangerous

#101
> The most alarming thing was realizing that a single flagged subdomain would apparently invalidate the entire domain.

Correct. It works this way because in general the domain has the rights over routing all the subdomains. Which means if you were a spammer, and doing something untoward on a subdomain only invalidated the subdomain, it would be the easiest game in the world to play.

malware1.malicious.com

malware2.malicious.com

... Etc.

Re: Google flags Immich sites as dangerous

#102

Earlier quoted context omitted.

so its skill issue ??? or just google being bad????

I will go with Google being bad / evil for 500. Google 90s to 2010 is nothings like Google 2025. There is a reason they removed "Don't be evil" ... being evil and authoritarian makes more money. Looking at you Manifest V2 ... pour one out for your homies.

Sympathy for the devil, people keep using Google's browser because the safe search guards catch more bad actors than they false positive good actors.

Re: Google flags Immich sites as dangerous

#103
post #96
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…

I don't think the Internet should be run by being on special lists (other than like, a globally run registry of domain names)...

I get that SPAM, etc., are an issue, but, like f* google-chrome, I want to browse the web, not some carefully curated list of sites some giant tech company has chosen.

A) you shouldn't be using google-chrome at all B) Firefox should definitely not be using that list either C) if you are going to have a "safe sites" list, that should definitely be a non-profit running that, not an automated robot working for a large probably-evil company...

Re: Google flags Immich sites as dangerous

#104
post #96
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…

> When users host an open source self hosted project like immich, jellyfin, etc. on their own domain...

I was just deploying your_spotify and gave it your-spotify. and there was a warning in the logs that talked about thud, linking the issue:

https://github.com/Yooooomi/your_spotify/issues/271

Re: Google flags Immich sites as dangerous

#106
This happened to one of our documentation sites. My co-workers all saw it before I did, because Brave (my daily driver) wasn't showing it. I'm not sure if Brave is more relaxed in determining when a site is "dangerous" but I was glad not to be seeing it, because it was a false positive.

Re: Google flags Immich sites as dangerous

#107
post #97

Earlier quoted context omitted.

> A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. I don't see how that solves the issue that PSL tries to fix. I was a script kiddy hosting neopets phishing pages on free cpanel servers from .ripway.com back in 2007. Browsers were way less capable then.

PSL and the way cookies work is just part of the mess. A new approach could solve that in a different way, taking into account all the experience we had with scriptkiddies and professional scammers and pishers since then. But I also don't really have an idea where and how to start.

And of course, if the new solution completely invalidates old sites, it just won't get picked up. People prefer slightly broken but accessible to better designed but inaccessible.

Re: Google flags Immich sites as dangerous

#108

Earlier quoted context omitted.

so its skill issue ??? or just google being bad????

I will go with Google being bad / evil for 500. Google 90s to 2010 is nothings like Google 2025. There is a reason they removed "Don't be evil" ... being evil and authoritarian makes more money. Looking at you Manifest V2 ... pour one out for your homies.

downvoted for saying truth

many google employee is in here, so I dont expect them to be agree with you

Re: Google flags Immich sites as dangerous

#109
post #93
post #76

Earlier quoted context omitted.

A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionabl…

"You could take about 90% of that out and into dedicated tools " But then you would loose plattform independency, the main selling point of this atrocity. Having all those APIs in a sandbox that mostly just work on billion devices is pretty powerful and a potential succesor to HTML would have to beat that, to be adopted. The best thing to happen, that I can see, is that a sane subset crystalizes, that people start to…

But do we need e.g serial port or raw USB access straight from a random website? Even WebRTC is a bit of a stretch. There is a lot of cruft in modern browsers that does little except increase attack surface.

This all just drives a need to come up with ever more tacked-on protection schemes because browsers have big targets painted on them.

Re: Google flags Immich sites as dangerous

#110
post #96

Earlier quoted context omitted.

Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…

I don't think the Internet should be run by being on special lists (other than like, a globally run registry of domain names)... I get that SPAM, etc., are an issue, but, like f* google-chrome, I want to browse the web, not some carefully curated list of sites some giant tech company has chosen. A) you shouldn't be using google-chrome at all B) Firefox should definitely not be using that list either C) if you are goi…

There are other browsers if you want to browse the web with the blinders off.

It's browser beware when you do, but you can do it.

Post reply on HN