Given the scale of Google, and the nerdiness required to run Immich, I bet it's just an accident. Nevertheless, I'm very curious as to how senior Google staff looks at Immich, are they actually registering signals that people use immich-go to empty their Google Photos accounts? Do they see this as something potentially dangrous to their business in the long term? The nerdsphere has been buzzing with Immich for some t…
Google flags Immich sites as dangerous
301–310 of 713 posts
Re: Google flags Immich sites as dangerous
#302Re: Google flags Immich sites as dangerous
#303Re: Google flags Immich sites as dangerous
#304Earlier quoted context omitted.
Yeah - that website keeps on spamming me down with useless stuff. I was able to block most of this via ublock origin but Google disabled this - can not download it from here anymore: https://chromewebstore.google.com/detail/ublock-origin/cjpal... Funniest nonsense "explanation": "This extension is no longer available because it doesn't follow best practices for Chrome extensions." In reality Google killed it because…
[flagged]
Librewolf is just a directly de-mozillaed and privacy-enhanced Firefox, similar to Ungoogled Chromium. I've been trying to get in the habit of using Zen Browser, which has a bunch of UI changes.
Re: Google flags Immich sites as dangerous
#305Earlier quoted context omitted.
In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…
> Since there was and remains no algorithmic method of finding the highest level at which a domain may be registered for a particular top-level domain A centralized list like this not just for domains as a whole (e.g. co.uk) but also specific sites (e.g. s3-object-lambda.eu-west-1.amazonaws.com) is both kind of crazy in that the list will bloat a lot over the years, as well as a security risk for any platform that ne…
I’m not sure how you’d have this - it’s for the public facing side of user hosted content, surely that must be public?
> We already have the concept of a .well-known directory that you can use, when talking to a specific site.
But the point is to help identify dangerous sites, by definition you can’t just let the sites mark themselves as trustworthy and rotate around subdomains. If you have an approach that doesn’t have to trust the site, you also don’t need any definition at the top level you could just infer it.
Re: Google flags Immich sites as dangerous
#306Never host your test environments as Subdomains of your actual production domain. You'll also run into email reputation as well as cookie hell. You can get a lot of cookies from the production env if not managed well.
This. I cannot believe the rest of the comments on this are seemingly completely missing the problem here & kneejerk-blaming Google for being an evil corp. This is a real issue & I don't feel like the article from the Immich team acknowledges it. Far too much passing the buck, not enough taking ownership.
Re: Google flags Immich sites as dangerous
#307Earlier quoted context omitted.
I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.
[flagged]
Except for those that are making money off adds directly or indirectly, and who believe in their god given right to my attention and my data.
> I'm increasingly blown away by takes on here that are so dramatic and militant about things that barely even register to most people.
Things 'barely even registering to most people' is not as strong a position as you may think it is. Oxygen barely registers to most people. But take it away and they register it just fine (for a short while). The 'regular' people that you know have been steadily conditioned to an ever worsening experience to the point that they barely recognize the websites they visit when seeing the web with an adblocker for the first time.
Re: Google flags Immich sites as dangerous
#308I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.
It may well be a false positive of Google's heuristics but home server security can be challenging - I would look at ruling out the possibility of it being real first.
It certainly sounds like a separate root issue to this article, even if the end result looks the same.
Re: Google flags Immich sites as dangerous
#309Earlier quoted context omitted.
> what Immich are doing is extremely dangerous I've read the article and don't see anything dangerous, much less extremely so. Care to explain?
They're auto-deploying PRs to a subdomain of a domain that they also use for production traffic. This allows any member of the public with a GitHub account to deploy any arbitrary code to that subdomain without any review or approval from the Immich team. That's bad for two reasons: 1. PR deploys on public repos are inherently tricky as code gains access to the server environment, so you need to be diligent about seg…
This part is not correct: the "preview" label can be set only by collaborators.
> a subdomain of a domain that they also use for production traffic
To clarify this part: the only production traffic that immich.cloud serves are static map tiles (tiles.immich.cloud)
Overall, I share your concerns, and as you already mentioned, a dedicated "immich.build" domain is the way to go.
Re: Google flags Immich sites as dangerous
#310Earlier quoted context omitted.
Yeah - that website keeps on spamming me down with useless stuff. I was able to block most of this via ublock origin but Google disabled this - can not download it from here anymore: https://chromewebstore.google.com/detail/ublock-origin/cjpal... Funniest nonsense "explanation": "This extension is no longer available because it doesn't follow best practices for Chrome extensions." In reality Google killed it because…
You know what? I don't even mind them killing it, because of course there are a whole pile of items under the anti-trust label that google is doing so why not one more. But what I do take issue with is the gaslighting, their attempt to make the users believe that this is in the users interests, rather than in google's interests. If we had functional anti-trust laws then this company would have been broken up long ago…