Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

161–170 of 713 posts

Re: Google flags Immich sites as dangerous

#161

I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.

Since other browsers, like Firefox, also use the Google Safe Browsing list, they are affected as well.

Re: Google flags Immich sites as dangerous

#162

I tried to submit this, but the direct link here is probably better than the Reddit thread I linked to: https://old.reddit.com/r/immich/comments/1oby8fq/immich_is_a... I had my personal domain I use for self-hosting flagged. I've had the domain for 25 years and it's never had a hint of spam, phishing, or even unintentional issues like compromised sites / services. It's impossible to know what Google's black box is do…

I'm in a similar boat. Google's false flag is causing issues for my family members who use Chrome, even for internal services that aren't publicly exposed, just because they're on related subdomains. It's scary how much control Google has over which content people can access on the web - or even on their local network!

It's a good opportunity to recommend Firefox when you can show a clear abuse of position

Re: Google flags Immich sites as dangerous

#163

Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge

Some of these seem less cursed, and more just security design? > Some phones will silently strip GPS data from images when apps without location permission try to access them. That strikes me as the right thing to do?

It's not if it silently alters the file. i do want GPS data for geolocation, so that when i import the images in the right places they are already placed where they should be on the map

Re: Google flags Immich sites as dangerous

#166
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

That's the nature of decentralised control. It's not just DNS, phone numbers work in the same way.

Re: Google flags Immich sites as dangerous

#167
post #93

Earlier quoted context omitted.

"You could take about 90% of that out and into dedicated tools " But then you would loose plattform independency, the main selling point of this atrocity. Having all those APIs in a sandbox that mostly just work on billion devices is pretty powerful and a potential succesor to HTML would have to beat that, to be adopted. The best thing to happen, that I can see, is that a sane subset crystalizes, that people start to…

But do we need e.g serial port or raw USB access straight from a random website? Even WebRTC is a bit of a stretch. There is a lot of cruft in modern browsers that does little except increase attack surface. This all just drives a need to come up with ever more tacked-on protection schemes because browsers have big targets painted on them.

> But do we need e.g serial port or raw USB access straight from a random website?

Yes. Regards, CIA, Mossad, FSB etc.

Re: Google flags Immich sites as dangerous

#168
I’d say this is a clear slight from Google, using their Chrome browser because something or someone is inconveniencing another part of their business, google cloud / google photos.

They did a similar thing with the uBlock Origin extension, flagging it with “this extension might be slowing down your browser” in a big red banner in the last few months of manifest v2 on Chrome. After already having to upload the extension yourself to Chrome cause they took it off the extension store cause it was inhibiting on their ad business.

Google is a massive monopolistic company who will pull strings on one side of their business to help another.

With only Firefox not being based on Chromium and still having manifest v2 the future (5 to 10 years from now) looks bleak. With only 1 browser like this web devs can phase it out slowly by not taking it into consideration when coding or Firefox could enshittify to such an extent because of their manifest v2 monopoly that even that wont make it worth it anymore.

Oh and for the ones not in the know, Manifest is the name of a javascript file manifest.js that decides what browser extensions can and cant modify and the “upgrade” from manifest v2 to v3 has made it near impossible for adblockers to block ads.

Re: Google flags Immich sites as dangerous

#169
Safe Browsing collects a lot of data, such as hashes of URLs (URLs can be easily decoded by comparison) and probably other interactions with web like downloads.

But how effective is it in malware detection?

The benefits seem to me dubious. It looks like a feature offered to collect browsing data, useful to maybe 1% in special situations.

Re: Google flags Immich sites as dangerous

#170

Earlier quoted context omitted.

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

Show me a platform not made out of duct tape and I'll show you a platform nobody uses.

regular cars?
Post reply on HN