Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

491–500 of 713 posts

Re: Google flags Immich sites as dangerous

#491

We really need an internet Bill of Rights. Google has too much power to delete your company from existence with no due process or recourse. If any company controls some (high) percentage of a particular market, say web browsers, search, or e-commerce, or social media, the public's equal access should start to look more like a right and less like an at-will contract. 30 years ago, if a shop had a falling out with the…

I know someone with a small business that applied for Venmo Business account (which is the main payment method in their community industry) and Venmo refused to open the account and didn't provide any reason as to why saying that they have the right to choose to refuse providing the service, which they do . But all the competitors of that business in the area do have a Venmo and take payment this way so it is basical…

Same thing with Paypal - I opened a business account, was able to do one transaction and was shut down for fraud. I tested a donation to myself. Under $10. Lifetime ban.

fuck paypal

Re: Google flags Immich sites as dangerous

#492

Earlier quoted context omitted.

Perhaps we need a different "type" of internet. I don't have the expertise to even explain what this would look like, but I know that if politics, religion, junk science and a hundred other influences have anything to do with it, it will eventually become too stupid to use.

Making a "smart person only" Internet is a social problem, not a technology problem.

We had a "smart person only internet". Then it became financially prudent to make it an "everyone internet", then we had the dot com boom, Apple, Google, etc bloom from that.

We _still_ have a "smart person only internet" really, it's just now used mostly for drug and weapon sales ( Tor )

Re: Google flags Immich sites as dangerous

#493

Earlier quoted context omitted.

Yes, my family Immich instance is blocked from indexing both via headers and robots.txt, yet it's still flagged by Google as dangerous.

I'm kind of curious, do you have your own domain for immich or is this part of a malware-flagged subdomain issue? It's kind of wild to me that Google would flag all instances of a particular piece of self-hosted software as malicious.

I have my own domain, and Immich is hosted on an "immich" subdomain.

Re: Google flags Immich sites as dangerous

#494

Earlier quoted context omitted.

File a small claim for damages up to 10,000 to 20,000 USD depending on your local statues. It’s actually pretty quick and easy. They cannot defend themselves with lawyers, so a director usually has to show up.

In all US states corporations may be represented by lawyers in small claims cases. The actual difference is that in higher courts corporations usually must be represented by lawyers whereas many states allow normal employees to represent corporations when defending small claims cases, but none require it.

This is just so inaccurate, at least for California.

Re: Google flags Immich sites as dangerous

#495

Earlier quoted context omitted.

In 2025 you can use Beeper (or run your own local Matrix server with the opensource bridges) and get the same result with WhatsApp, Signal, Telegram, Discord, Google Messages, etc. etc.

You'd have to break most of those platforms' TOS to do so.

Was Pidgin TOS-compliant back in the day? I'm a young whippersnapper, so I don't have experience with it myself.

Re: Google flags Immich sites as dangerous

#496

Never host your test environments as Subdomains of your actual production domain. You'll also run into email reputation as well as cookie hell. You can get a lot of cookies from the production env if not managed well.

This. I cannot believe the rest of the comments on this are seemingly completely missing the problem here & kneejerk-blaming Google for being an evil corp. This is a real issue & I don't feel like the article from the Immich team acknowledges it. Far too much passing the buck, not enough taking ownership.

There's quite a few comments of people having this happen to them when they self-host Immich, the issue you point out seems minor in comparison.

Re: Google flags Immich sites as dangerous

#497

Earlier quoted context omitted.

No later than last weekend I was comtemplating migrating my family pictures to a self-hosted Immich instance... I guess a workaround Google's crap would be to put an htpasswd/basic auth in front of Immich, blocking Google to get to the content and flagging it.

Add a custom "welcome message" in Server Settings ( https://my.immich.app/admin/system-settings?isOpen=server ) to make your login page look different compared to all other default Immich login pages. This is probably the easiest non-intrusive tweak to work around the repeated flagging by Safe Browsing, still no 100% guarantee. I agree that strict access blocking (with extra auth or IP ACL) can work better. Though I'…

Thank you for the "welcome message" suggestion! I'll implement that in the hope it may help in the future.

Re: Google flags Immich sites as dangerous

#498

Earlier quoted context omitted.

I'm kind of curious, do you have your own domain for immich or is this part of a malware-flagged subdomain issue? It's kind of wild to me that Google would flag all instances of a particular piece of self-hosted software as malicious.

I have my own domain, and Immich is hosted on an "immich" subdomain.

I see, thank you for clarifying.

I'm guessing Google's phishing analysis must be going off the rails seeing all of these login prompts saying "immich" when there's an actual immich cloud product online.

If I were tasked with automatically finding phishing pages, I too would struggle to find a solution to differentiate open-source, self-hosted software from phishing pages.

I find it curious that this is happening to Immich so often while none of my own self-hosted services have ever had this problem, though. Maybe this is why so many self-hosted tools have you configure a name/descriptor/title/whatever for your instance, so they can say "log in to " rather than "log in to Product"? Not that Immich doesn't offer such a setting.

Re: Google flags Immich sites as dangerous

#499

I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.

Update: my appeal of the false positive has been accepted by Google and my domain is now unblocked.

Re: Google flags Immich sites as dangerous

#500

We really need an internet Bill of Rights. Google has too much power to delete your company from existence with no due process or recourse. If any company controls some (high) percentage of a particular market, say web browsers, search, or e-commerce, or social media, the public's equal access should start to look more like a right and less like an at-will contract. 30 years ago, if a shop had a falling out with the…

Force interoperability. In 2009 I could run Pidgin and load messages from AIM, FB Messages, Yahoo... Where did that go? I suspect the EU will be the first region to push the big tech companies on this.

> 2009 I could run Pidgin and load messages from AIM, FB Messages, Yahoo... Where did that go?

https://www.youtube.com/watch?v=mBcY3W5WgNU

But seriously; the internet is now overrun with AI Slop, Spam, and automated traffic. To try to do something about it requires curation, somebody needs to decide what is junk, which is completely antithetical to open protocols. This problem is structurally unsolvable, there is no solution, there's either a useless open internet or a useful closed one. The internet is voting with Cloudflare, Discord, Facebook, to be useful, not open. The alternative is trying to figure out how to run a decentralized dictatorship that only allows good things to happen; a delusion.

The only other solution is accountability, a presence tied to your physical identity; so that an attacker cannot just create 100,000 identities from 25,000 IP addresses and smash your small forum with them. That's an even less popular idea, even though it would make open systems actually possible. Building your own search engine or video platform would be super easy, barely an inconvenience. No need for Cloudflare if the police know who every visitor is. No need for a spam filter, if the government can enforce laws perfectly.

Take a look at email, the mother of all open protocols (older than HTTP). What happened? Radical recentralization to companies that had effective spam management, and now we on HN complain we can't break through, someone needs to do something about that centralization, so that we can go back to square one where people get spammed to death again, which will inevitably repeat the discretion required -> who has the best discretion -> flee there cycle. Go figure.

Post reply on HN