Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

231–240 of 713 posts

Re: Google flags Immich sites as dangerous

#231

Maybe a dumb question but what constitutes user-hosted-content? Is a notion page, github repo, or google doc that has user submitted content that can be publicly shared also user-hosted? IMO Google should not be able to use definitive language "Dangerous website" if its automated process is not definitive/accurate. A false flag can erode customer trust.

A website where a user can upload "active code".

The definition of "active code" is broad & sometimes debatable - e.g. do old MySpace websites count - but broadly speaking the best way of thinking about it is in terms of threat model, & the main two there are:

- credential leakage

- phishing

The first is fairly narrow & pertains to uploading server side code or client javascript. If Alice hosts a login page on alice.immich.cloud that contains some session handling bugs in her code, Mallory can add some cute to mallory.immich.cloud to read cookies set on *.immich.cloud to compromise Alice's logins.

The second is much broader as it's mostly about plausible visual impersonation so will also cases where users can only upload CSS or HTML.

Specifically in this case what Immich is doing here is extremely dangerous & this post from them - while I'll give them the benefit of the doubt on being ignorant - is misinformation.

Re: Google flags Immich sites as dangerous

#232
post #171

Earlier quoted context omitted.

Uh… we are. Servo and Ladybird. It’s a shit tonne of work.

Firefox should be on that list. It's clearly a lot closer in functionality to Chrome/Chromium than Servo or Ladybird, so it's easier to switch to it. I like that Servo and Ladybird exist and are developing well, but there's no need to pretend that they're the only available alternatives.

If you knew how the Mozilla corporation was governed, then you would not think that Firefox should be on the list.

Re: Google flags Immich sites as dangerous

#233

Earlier quoted context omitted.

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

Show me a platform not made out of duct tape and I'll show you a platform nobody uses.

Admitting I'm old, but my HP-11C still gets pretty-regular use.

And judging by eBay prices, or the SwissMicros product line, I suspect I have plenty of company.

Re: Google flags Immich sites as dangerous

#234
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

There is no law appointing that organization as a world wide authority on tainted/non tainted sites.

The fact it's used by one or more browsers in that way is a lawsuit waiting to happen.

Because they, the browsers, are pointing a finger to someone else and accusing them of criminal behavior. That is what a normal user understands this warning as.

Turns out they are wrong. And in being wrong they may well have harmed the party they pointed at, in reputation and / or sales.

It's remarkable how short sighted this is, given that the web is so international. Its not a defense to say some third party has a list, and you're not on it so you're dangerous

Incredible

Re: Google flags Immich sites as dangerous

#235
post #177

Can I use this space to comment on how amazing Immich is? I self host lots of stuff, and there’s this one tier above everything else that’s currently, and exclusively, held by Home Assistant and Immich. It is actually _better_ than Google photos (if you keep your db and thumbs on ssd, and run the top model for image search). You give up nothing, and own all your data.

I migrated over from google photos 2 years ago. It has been nothing but amazing. No wonder google has it in its crosshairs.

Re: Google flags Immich sites as dangerous

#237
Given the scale of Google, and the nerdiness required to run Immich, I bet it's just an accident. Nevertheless, I'm very curious as to how senior Google staff looks at Immich, are they actually registering signals that people use immich-go to empty their Google Photos accounts? Do they see this as something potentially dangrous to their business in the long term?

The nerdsphere has been buzzing with Immich for some time now (I started using it a month back and it lives up to its reputation!), and I assume a lot of Googlers are in that sphere (but not neccessarily pro-Google/anti-Immich of course). So I bet they at least know of it. But do they talk about it?

Re: Google flags Immich sites as dangerous

#238

I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.

Just in case you're not sure how to deal with it, you need to request a review via the Google Search Console. You'll need a Google account and you have to verify ownership of the domain via DNS (if you want to appeal the whole domain). After that, you can log into the Google Search Console and you can find "Security Issues" under the "Security & Manual Actions" section.

That area will show you the exact URLs that got you put on the block list. You can request a review from there. They'll send you an email after they review the block.

Hopefully that'll save you from trying to hunt down non-existent malware on a half dozen self-hosted services like I ended up doing.

Re: Google flags Immich sites as dangerous

#239
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

Why is it a centrally maintained list of domains, when there is a whole extensible system for attaching metadata to domain names?

Re: Google flags Immich sites as dangerous

#240
I've rarely seen a HN comment section this overwhelmingly wrong on a technical topic. This community is usually better than this.

Google is an evil company I want the web to be free of, I resent that even Firefox & Safari use this safe browsing service. Immich is a phenomenal piece of software - I've hosted it myself & sung its praises on HN in the past.

Put putting aside David vs Goliath biases here, Google is 100% correct here & what Immich are doing is extremely dangerous. The fact they don't acknowledge that in the blog post shows a security knowledge gap that I'm really hoping is closed over the course of remediating this.

I don't think the Immich team mean any harm but as it currently stands the OP constitutes misinformation.

Post reply on HN