Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

141–150 of 713 posts

Re: Google flags Immich sites as dangerous

#141

The open internet is done. Monopolies control everything. We have an iOS app in the store for 3 years and out of the blue apple is demanding we provide new licenses that don’t exist and threaten to kick our app out. Nothing changed in 3 years. Getting sick of these companies able to have this level of control over everything, you can’t even self host anymore apparently.

> We have an iOS app in the store for 3 years and out of the blue apple is demanding we provide new licenses that don’t exist and threaten to kick our app out.

Crazy! If you can elaborate here, please do.

Re: Google flags Immich sites as dangerous

#142
post #99

The same thing happened to me earlier this year with a self-hosted instance of Umami Analytics. https://news.ycombinator.com/item?id=42779544#42783321 Unironically, including a threat of legal action in my appeal on the Google Search Console was what stopped our instance getting flagged in the end.

Could you provide your text? Having same issue for years https://news.ycombinator.com/item?id=45678095

Re: Google flags Immich sites as dangerous

#144
post #96

Earlier quoted context omitted.

Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…

I don't think the Internet should be run by being on special lists (other than like, a globally run registry of domain names)... I get that SPAM, etc., are an issue, but, like f* google-chrome, I want to browse the web, not some carefully curated list of sites some giant tech company has chosen. A) you shouldn't be using google-chrome at all B) Firefox should definitely not be using that list either C) if you are goi…

Oh god, you reminded me the horrors of hosting my own mailserver and all of the white/blacklist BS you have to worry about being a small operator (it's SUPER easy to end up on the blacklists, and is SUPER hard to get onto whitelists)

Re: Google flags Immich sites as dangerous

#145
post #96

Earlier quoted context omitted.

Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…

That means the Safe Browsing abuse could be weaponized against self-hosted services, oh my...

New directive from the Whitehouse. Block all non approved sites. If you don't do it we will block your merger etc...

Re: Google flags Immich sites as dangerous

#146

Insane that one company can dictate what websites you're allowed to visit. Telling you what apps you can run wasn't far enough.

I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.

[flagged]

Re: Google flags Immich sites as dangerous

#147

This is #1 on HN for a while now and I suspect it's because many of us are nervous about it happening to us (or have already had our own homelab domains flagged!). So is there someone from Google around who can send this along to the right team to ensure whatever heuristic has gone wrong here is fixed for good?

I doubt Google the corporation cares one bit, and any individual employees who do care would likely struggle against the system to cause significant change.

The best we all can do is to stop using Google products and encourage our friends and family to do likewise. Make sure in our own work that we don't force others to rely on Google either.

Re: Google flags Immich sites as dangerous

#148
post #54

The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

> The one thing I never understood about these warnings is how they don't run afoul of libel laws. I’m not a lawyer, but this hasn’t ever been taken to court, has it? It might qualify as libel.

you only sue somebody poorer than you

Re: Google flags Immich sites as dangerous

#149
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

Show me a platform not made out of duct tape and I'll show you a platform nobody uses.

Re: Google flags Immich sites as dangerous

#150

A good takeaway is to separate different domains for different purposes. I had prior been tossing up the pros/cons of this (such as teaching the user to accept millions of arbitrary TLDs as official), but I think this article (and other considerations) have solidified it for me. For example www.contoso.com (public) www.contoso.blog (public with user comments) contoso.net (internal) staging.contoso.dev (dev/zero trust…

The biggest con of this is that to a user it will seem much more like phishing.

It happened to me a while ago that I suddenly got emails from "githubnext.com". Well, I know Github and I know that it's hosted at "github.com". So, to me, that was quite obviously phishing/spam.

Turns out it was real...

Post reply on HN