Earlier quoted context omitted.
This. I cannot believe the rest of the comments on this are seemingly completely missing the problem here & kneejerk-blaming Google for being an evil corp. This is a real issue & I don't feel like the article from the Immich team acknowledges it. Far too much passing the buck, not enough taking ownership.
Both things can be problems. 1. You should host dev stuff and separate domains. 2. Google shouldn't be blocking your preview environments.
Google flags Immich sites as dangerous
371–380 of 713 posts
Re: Google flags Immich sites as dangerous
#372I write a couple of libraries for creating GOV.UK services and Google has flagged one of them as dangerous. I've appealed the decision several times but it's like screaming into a void. https://govuk-components.netlify.app/ I use Google Workspace for my company email, so that's the only way for me to get in contact with a human, but they refuse to go off script and won't help me contact the actual department responsi…
Re: Google flags Immich sites as dangerous
#373They have to fix their SSL certs. "Kubernetes Ingress Controller Fake Certificate" aint gonna cut it.
Re: Google flags Immich sites as dangerous
#374Earlier quoted context omitted.
> This allows any member of the public with a GitHub account to deploy any arbitrary code to that subdomain without any review or approval from the Immich team. This part is not correct: the "preview" label can be set only by collaborators. > a subdomain of a domain that they also use for production traffic To clarify this part: the only production traffic that immich.cloud serves are static map tiles (tiles.immich.c…
> This part is not correct: the "preview" label can be set only by collaborators. That's good & is a decent starting point. A decent second step might be to have the Github Actions workflow also check the approval status of the PR before deploying (requiring all collaborators to be constantly aware that the risk of applying a label is similar to that of an approval seems less viable)
Re: Google flags Immich sites as dangerous
#375If there are any googlers here, I'd like to report an even more dangerous website. As much as 30-50% of the traffic to it relates to malware or scams, and it has gone unpunished for a very long time. The address appears to be adsense.google.com.
What i really don't understand at least here in Europe the advertising partner (adsense) must investigate at least minimally whether the advertising is illegal or fraudulent, i understand that sites.google etc are under "safe harbor" but that's not the point with adsense since people from google "click" the publish button and also get money to publish that ad.
Re: Google flags Immich sites as dangerous
#376Happened to me last week. One morning we wake up and the whole company website does not work. Not advice with some time to fix any possible problem, just blocked. We gave very bad image to our clients and users, and had to give explanations of a false positive from google detection. The culprit, according to google search console, was a double redirect on our web email domain (/ -> inbox -> login). After just moving…
Re: Google flags Immich sites as dangerous
#377Earlier quoted context omitted.
Use one of the forks. librewolf, waterfox, zen. Firefox itself lost trust when Mozilla tried to push the new Terms of Use earlier this year. That was so aggressively user-hostile that nobody should trust Mozilla ever again. Using a fork puts an insulation layer between you and Mozilla. Librewolf is just a directly de-mozillaed and privacy-enhanced Firefox, similar to Ungoogled Chromium. I've been trying to get in the…
> Firefox itself lost trust when Mozilla tried to push the new Terms of Use earlier this year. Those terms of use aren't in place any longer. I'm surprised that listening to the users is viewed as something bad.
Re: Google flags Immich sites as dangerous
#378Safe Browsing collects a lot of data, such as hashes of URLs (URLs can be easily decoded by comparison) and probably other interactions with web like downloads. But how effective is it in malware detection? The benefits seem to me dubious. It looks like a feature offered to collect browsing data, useful to maybe 1% in special situations.
Re: Google flags Immich sites as dangerous
#379Happened to me last week. One morning we wake up and the whole company website does not work. Not advice with some time to fix any possible problem, just blocked. We gave very bad image to our clients and users, and had to give explanations of a false positive from google detection. The culprit, according to google search console, was a double redirect on our web email domain (/ -> inbox -> login). After just moving…
I'm beginning to seriously think we need a new internet, another protocol, other browsers just to break up the insane monopolies that has been formed, because the way things are going soon all discourse will be censored, and competitors will be blocked soon. We need something that's good for small and medium businesses again, local news and get an actual marketplace going - you know what the internet actually promise…
Any new protocol not only has to overcome the huge incumbent that is the web, it has to do so grassroots against the power of global capital (trillions of dollars of it). Of course, it also has to work in the first place and not be captured and centralised like another certain open and decentralised protocol has (i.e., the Web).
Is that easier than the states doing their jobs and writing a couple pages of text?
Re: Google flags Immich sites as dangerous
#380A friend / client of mine used some kind of WordPress type of hosting service with a simple redirect. The host got on the bad sites list. This also polluted their own domain, even when the redirect was removed, and had the odd side effect that Google would no longer accept email from them. We requested a review and passed it, but the email blacklist appears to be permanent. (I already checked and there are no spam pr…
Wow. That scares me. I've been using my own domain that got (wrongly) blacklisted this week for 25 years and can't imagine having email impacted.
And avoid using subdomains.