If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
There is no law appointing that organization as a world wide authority on tainted/non tainted sites. The fact it's used by one or more browsers in that way is a lawsuit waiting to happen. Because they, the browsers, are pointing a finger to someone else and accusing them of criminal behavior. That is what a normal user understands this warning as. Turns out they are wrong. And in being wrong they may well have harmed…
Google flags Immich sites as dangerous
241–250 of 713 posts
Re: Google flags Immich sites as dangerous
#242Earlier quoted context omitted.
PSL and the way cookies work is just part of the mess. A new approach could solve that in a different way, taking into account all the experience we had with scriptkiddies and professional scammers and pishers since then. But I also don't really have an idea where and how to start.
And of course, if the new solution completely invalidates old sites, it just won't get picked up. People prefer slightly broken but accessible to better designed but inaccessible.
We live in world where whatever faang adopts is de facto a standard. Accessible these days means google/gmail/facebook/instagram/tiktok works. Everything else is usually forced to follow along.
People will adopt whatever gives them access to their daily dose of doomscrolling and then complain about rather crucial part of their lives like online banking not working.
> And of course, if the new solution completely invalidates old sites, it just won't get picked up.
Old sites don't matter, only high-traffic sites riddled with dark patterns matter. That's the reality, even if it is harsh.
Re: Google flags Immich sites as dangerous
#243The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.
> They are directly calling you a scammer and "attacker". No they're not. The word "scammer" does not appear. They're saying attackers on the site and they use the word "might". This includes third-party hackers who have compromised the site. They never say the owner of the site is the attacker. I'm quite sure their lawyers have vetted the language very carefully.
I think that might count as libel.
Re: Google flags Immich sites as dangerous
#244Earlier quoted context omitted.
There is no law appointing that organization as a world wide authority on tainted/non tainted sites. The fact it's used by one or more browsers in that way is a lawsuit waiting to happen. Because they, the browsers, are pointing a finger to someone else and accusing them of criminal behavior. That is what a normal user understands this warning as. Turns out they are wrong. And in being wrong they may well have harmed…
As far as I know there is currently no international alternative authority for this. So definitely not ideal, but better than not having the warnings.
You're honor, we hurt the plaintiff because it's better than nothing!
Re: Google flags Immich sites as dangerous
#245Earlier quoted context omitted.
I'm almost positive GMail scanning messages is one cause. My domain got put on the list for a URL that would have been unknowable to anyone but GMail and my sister who I invited to a shared Immich album. It was a URL like this that got emailed directly to 1 person: https://photos.example.com/albums/xxxxxxxx-xxxx-xxxx-xxxx-xx... Then suddenly the domain is banned even though there was never a way to discover that URL…
Well, that's potentially horrifying. I would love for someone to attempt this in as controlled of a manner as possible. I would assume it's possible for anyone using Google DNS servers to also trigger some type of metadata inspection resulting in this type of situation as well. Also - when you say banned, you're speaking of the "red screen of death" right? Not a broader ban from the domain using Google Workplace serv…
Yes.
> I would love for someone to attempt this in as controlled of a manner as possible.
I'm pretty confident they scanned a URL in GMail to trigger the blocking of my domain. If they've done something as stupid as tying GMail phishing detection heuristics into the safe browsing block list, you might be able to generate a bunch of phishy looking emails with direct links to someone's login page to trigger the "red screen of death".
Re: Google flags Immich sites as dangerous
#246I’m launching a web version for an online game. What to do to prevent this from happening?
Re: Google flags Immich sites as dangerous
#247Earlier quoted context omitted.
In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…
> Since there was and remains no algorithmic method of finding the highest level at which a domain may be registered for a particular top-level domain A centralized list like this not just for domains as a whole (e.g. co.uk) but also specific sites (e.g. s3-object-lambda.eu-west-1.amazonaws.com) is both kind of crazy in that the list will bloat a lot over the years, as well as a security risk for any platform that ne…
Re: Google flags Immich sites as dangerous
#248I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.
I guess a workaround Google's crap would be to put an htpasswd/basic auth in front of Immich, blocking Google to get to the content and flagging it.
Re: Google flags Immich sites as dangerous
#249If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
Re: Google flags Immich sites as dangerous
#250Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge