Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

571–580 of 713 posts

Re: Google flags Immich sites as dangerous

#571
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

In another comment in this thread, it was confirmed that these PR host names are only generated from branches internal to Immich or labels applied by maintainers, and that this does not automatically happen for arbitrary PRs submitted by external parties. So this isn’t the use case for the public suffix list - it is in no way public or externally user-generated. What would you recommend for this actual use case? Even…

If these are dev subdomains that are actually for internal use only, then a very reliable fix is to put basic auth on them, and give internal staff the user/password. It does not have to be strong, in fact it can be super simple. But it will reliably keep out crawlers, including Google.

Re: Google flags Immich sites as dangerous

#572
post #54

The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

> The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker"

Being wrong doesn't count as libel.

If a company has a detection tool, makes reasonable efforts to make sure it is accurate, and isn't being malicious, you'll have a hard time making a libel case

Re: Google flags Immich sites as dangerous

#573

Earlier quoted context omitted.

> mitigating false positives First & foremost I really need to emphasise that, despite the misleading article title, this was not a false positive. Google flagged this domain for legitimate reasons. I think there's likely a conversation to be had about messaging - Chrome's warning page seems a little scarier than it should be, Firefox's is more measured in its messaging. But in terms of the API service Google are pro…

> First & foremost I really need to emphasise that, despite the misleading article title, this was not a false positive. Google flagged this domain for legitimate reasons. Judging by what a person from the Immich team said, that does not seem to be true? > the whole system only works for PRs from internal branches - https://news.ycombinator.com/item?id=45681230 So unless one of the developers in the team published so…

> unless one of the developers in the team published something malicious through that system

If that happened we'd have much bigger problems than Google's flagging.

Re: Google flags Immich sites as dangerous

#574
post #491

Earlier quoted context omitted.

Same thing with Paypal - I opened a business account, was able to do one transaction and was shut down for fraud. I tested a donation to myself. Under $10. Lifetime ban. fuck paypal

Fuck PayPal. Fwiw Venmo is run by the same thugs who run PayPal. So go figure.

Yup. Both bad companies IMO

Re: Google flags Immich sites as dangerous

#575
post #491

Earlier quoted context omitted.

Same thing with Paypal - I opened a business account, was able to do one transaction and was shut down for fraud. I tested a donation to myself. Under $10. Lifetime ban. fuck paypal

That’s not unique to PayPal. Pretty much any payment processor that detects a proprietor paying themselves is going to throw up a red flag for circular cash flow fraud and close the account. Bank-operated payment processors are often slower to catch it, but they will also boot you for this.

Ok - but maybe tell me that? They won't officially tell me anything or let me talk to a person. Form email every time.

At the time I didn't have a better way to test that my form worked.

Re: Google flags Immich sites as dangerous

#576
post #563

Earlier quoted context omitted.

> 2009 I could run Pidgin and load messages from AIM, FB Messages, Yahoo... Where did that go? https://www.youtube.com/watch?v=mBcY3W5WgNU But seriously; the internet is now overrun with AI Slop, Spam, and automated traffic. To try to do something about it requires curation , somebody needs to decide what is junk , which is completely antithetical to open protocols. This problem is structurally unsolvable, there is n…

Why should curation be centralized? We do not need a "decentralized dictatorship" (what would that even be? that's antithetical) and we certainly do not need a centralized one. It seems crazy that your solutions to AI, spam, and "automated traffic" (I don't know what that is, I assume web crawlers and such) is that the police control every single transaction. First off, we can simply let the user, or client software,…

> For mail, couldn't we come up with a mail-DNS, that authenticates senders?

So RFC 7672? https://datatracker.ietf.org/doc/html/rfc7672

Re: Google flags Immich sites as dangerous

#577

Earlier quoted context omitted.

I think google is crumbling under the weight of their size. They are no longer able to process the requested commercials with due diligence.

They can afford to hire thousands of people to swiftly identify scams and take punitive action. And pay them well.

They can, but as long as regulators let them get away with it, they will just pocket the money instead. Google are, imho, an evil company.

Re: Google flags Immich sites as dangerous

#578

Insane that one company can dictate what websites you're allowed to visit. Telling you what apps you can run wasn't far enough.

I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.

If you ask, the leaders in that area of Google will tell you something like "we're actually HELPING users because we're giving them targeted ads that are for the things they're looking for at the time they're looking for it, which only makes things for the user better." Then you show them a picture of YouTube ads or something and it transitions to "well, look, we gotta pay for this somehow, and at least's it's free, and isn't free information for all really great?"

Re: Google flags Immich sites as dangerous

#579
post #556
post #491

Earlier quoted context omitted.

Same thing with Paypal - I opened a business account, was able to do one transaction and was shut down for fraud. I tested a donation to myself. Under $10. Lifetime ban. fuck paypal

I sold some camera equipment on eBay once. PayPal flagged my account as fraudulent, asked for a receipt for the equipment which I did not have (I bought it years before), so they banned my account indefinitely. Randomly, years later, they turned it back on. Thanks, I guess?

They want to make money off your transactions again I guess. Must get more from Ebay

Re: Google flags Immich sites as dangerous

#580
post #531

Earlier quoted context omitted.

The reason Google doesn’t block Microsoft isn’t that they’re “looking out for Microsoft.” They’re looking out for themselves by being aware that blocking something that millions of people use would be bad for business.

So why isn't blocking something that is starred 82k times on GitHub bad for business.

That's peanuts compared to Microsoft's userbase
Post reply on HN