Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

151–160 of 713 posts

Re: Google flags Immich sites as dangerous

#151
post #54

The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

This is tricky to get right.

If the false positive rate is consistently 0.0%, that is a surefire sign that the detector is not effective enough to be useful.

If a false positive is libel, then any useful malware detector would occasionally do libel. Since libel carries enormous financial consequences, nobody would make a useful malware detector.

I am skeptical that changing the wording in the warning resolves the fundamental tension here. Suppose we tone it down: "This executable has traits similar to known malware." "This website might be operated by attackers."

Would companies affected by these labels be satisfied by this verbiage? How do we balance this against users' likelihood of ignoring the warning in the face of real malware?

Re: Google flags Immich sites as dangerous

#152
post #124

Earlier quoted context omitted.

I don't think the Internet should be run by being on special lists (other than like, a globally run registry of domain names)... I get that SPAM, etc., are an issue, but, like f* google-chrome, I want to browse the web, not some carefully curated list of sites some giant tech company has chosen. A) you shouldn't be using google-chrome at all B) Firefox should definitely not be using that list either C) if you are goi…

Firefox and Safari also use the list. At least by default, I think you can turn it off in firefox. And on the whole, I think it is valuable to have _a_ list of known-unsafe sites. And note that Safe Browsing is a blocklist, not an allowlist. The problem is that at least some of the people maintaining this list seem to be a little trigger happy. And I definitely thing Google probably isn't the best custodian of such a…

>I think it is valuable to have _a_ list of known-unsafe sites

And how and who should define what is consider unsafe sites?

Re: Google flags Immich sites as dangerous

#154
post #71

Earlier quoted context omitted.

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

"The engineering equivalent of a car made of duct tape" Kind of. But do you have a better proposition?

I'd probably say we ought to use DNS.

Re: Google flags Immich sites as dangerous

#155

Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge

> JavaScript date objects are 1 indexed for years and days, but 0 indexed for months.

I don't disagree that months should be 1-indexed, but I would not make that assumption solely based on days/years being 1-indexed, since 0-indexing those would be psychotic.

Re: Google flags Immich sites as dangerous

#156
post #97

Earlier quoted context omitted.

PSL and the way cookies work is just part of the mess. A new approach could solve that in a different way, taking into account all the experience we had with scriptkiddies and professional scammers and pishers since then. But I also don't really have an idea where and how to start.

And of course, if the new solution completely invalidates old sites, it just won't get picked up. People prefer slightly broken but accessible to better designed but inaccessible.

> People prefer slightly broken but accessible to better designed but inaccessible.

It's not even broken as the edge cases are addressed by ad-hoc solutions.

OP is complaining about global infrastructure not having a pristine design. At best it's a complain over a desirable trait. It's hardly a reason to pull the Jr developer card and mindlessly advocate for throwing everything out and starting over.

Re: Google flags Immich sites as dangerous

#157
post #152
post #124

Earlier quoted context omitted.

Firefox and Safari also use the list. At least by default, I think you can turn it off in firefox. And on the whole, I think it is valuable to have _a_ list of known-unsafe sites. And note that Safe Browsing is a blocklist, not an allowlist. The problem is that at least some of the people maintaining this list seem to be a little trigger happy. And I definitely thing Google probably isn't the best custodian of such a…

>I think it is valuable to have _a_ list of known-unsafe sites And how and who should define what is consider unsafe sites?

Ideally there should be several/many and the user should be able to direct their browser as to which they would like to use (or none at all)

Re: Google flags Immich sites as dangerous

#159
Us nerds *really* need to come together in creating a publicly owned browser (non chromium)

Surely among us devs, as we realize app stores increasingly hostile, that the open web is worth fighting for, and that we have the numbers to build solutions?

Re: Google flags Immich sites as dangerous

#160

Earlier quoted context omitted.

I will go with Google being bad / evil for 500. Google 90s to 2010 is nothings like Google 2025. There is a reason they removed "Don't be evil" ... being evil and authoritarian makes more money. Looking at you Manifest V2 ... pour one out for your homies.

Sympathy for the devil, people keep using Google's browser because the safe search guards catch more bad actors than they false positive good actors.

> people keep using Google's browser because the safe search guards catch more bad actors than they false positive good actors.

This is the first thing i disable in Chrome, Firefox and Edge. The only safe thing they do is safely sending all my browsing history to Google or Microsoft.

Post reply on HN