Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

611–620 of 713 posts

Re: Google flags Immich sites as dangerous

#611

The .internal.immich.cloud sites do not have matching certs! Navigating to https://main.preview.internal.immich.cloud , I'm right away informed by the browser that the connection is not secure due to an issue with the certificate. The problem is that it has the following CN (common name): main.preview.internal.immich.build. The list of alternative names also contains that same domain name. It does not match the site:…

We've already moved them to immich.build

Re: Google flags Immich sites as dangerous

#612

Simply opening a case saying that this is our website not impersonating anyone else is unlikely to get anything resolved. Just because it's your website, and you're not a bad agent doesn't prove that no part of the site is under the control of a bad agent, and that your site isn't accidentally hosting something malicious somewhere, or have some UI that is exploitable for cross-site scripting or whatever.

Sure, but why does Google approve our review over and over again without us making any changes or modifications to the flagged sites/urls? It's a vanilla Immich deployment with docker containers from GitHub pushed there by the core team.

Re: Google flags Immich sites as dangerous

#613

Looking forward to Louis Rossmann's reaction. Wouldn't be surprised if this leads to a lawsuit over monopolistic behavior - this is clearly abusing their dominant position in the browser space to eliminate competitors in photos sharing.

Seems that Rossmann left FUTO in february and started his own foundation in march

Re: Google flags Immich sites as dangerous

#614
post #146

Earlier quoted context omitted.

I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.

[flagged]

You're right but I hate that you're right. The only part I disagree with is

>I think they all are pretty happy with the deal and would not switch to a paid ad-free version.

If they were given a low friction option to pay the advertise price for these services I think a lot would choose it. Advertisement pays almost nothing per person. Almost every person could pay more than the cost to serve them an ad. To use a service ad free for a year would cost less than $1 per user. This differs on the platform obviously with stuff like youtube being far more expensive but for day to day stuff the cost is low.

Re: Google flags Immich sites as dangerous

#615
post #562

Earlier quoted context omitted.

I'll flip that around on you: why oh why do we need to browsers to carry these security holes in them? The Stadia flasher is a good example: how do I know that a website doesn't contain a device flasher that will turn one of my connected devices into a malicious actor that will attempt to take over whatever machine it's plugged into?

You know because there is an explicit permission box that pops out and asks if you want to give this website access to a device, and asks you to select that device. Same as your camera/microphone/location.

But that still gives completely unvetted direct access to the device to a website! People have been pointing to Itch.io games that supposedly require direct USB access. How hard is it to hide a script in there that reprograms a controller into something malicious?

Re: Google flags Immich sites as dangerous

#616
post #563

Earlier quoted context omitted.

Why should curation be centralized? We do not need a "decentralized dictatorship" (what would that even be? that's antithetical) and we certainly do not need a centralized one. It seems crazy that your solutions to AI, spam, and "automated traffic" (I don't know what that is, I assume web crawlers and such) is that the police control every single transaction. First off, we can simply let the user, or client software,…

> For mail, couldn't we come up with a mail-DNS, that authenticates senders? So RFC 7672? https://datatracker.ietf.org/doc/html/rfc7672

I have no knowledge of DANE but its reliance on DNSSEC makes me worried that it would be difficult for people to adopt it.

Also, I think it solves a different problem: it prevents spoofing/MITM but what about legitimate certificates? We would still need CAs that actually curate their customers and hold them accountable. And we would need email servers/clients to differentiate between strict CAs and ones that are used solely for encryption purposes.

I don't know that DNS should be applied to emails as is anyway but I find it could force spammers to operate with publicly available information which would make holding them accountable easier.

Re: Google flags Immich sites as dangerous

#617
post #386

Earlier quoted context omitted.

I love Immich & greatly appreciate the amazing work the team put into maintaining it, but between the OP & this "Cursed Knowledge" page, the apparent team culture of shouting from the rooftops complaints that expose their own ignorance about technology is a little concerning to be honest. I've now read the entire Cursed Knowledge list & - while I found some of them to be invaluable insights & absolutely love the idea…

> Carriage returns in bash scripts are cursed Also the full story here seemed to be 1. Person installs git on Windows with autocrlf enabled, automatically converting all LF to CRLF (very cursed in itself in my opinion). 2. Does their thing with git on the Windows' side (clone, checkout, whatever). 3. Then runs the checked out (and now broken due to autocrlf) code on Linux instead of Windows via WSL. The biggest footg…

The biggest mistake was running Linux programs over files created by Windows programs. Anything you move between those worlds is suspect.

Re: Google flags Immich sites as dangerous

#618

Earlier quoted context omitted.

I'm beginning to seriously think we need a new internet, another protocol, other browsers just to break up the insane monopolies that has been formed, because the way things are going soon all discourse will be censored, and competitors will be blocked soon. We need something that's good for small and medium businesses again, local news and get an actual marketplace going - you know what the internet actually promise…

IPFS has been doing some great work around decentralization that actually scales (Netflix uses it internally to speed up container delivery), but a) it's only good for static content, b) things still need friendly URLs, and c) once it becomes the mainstream, bad actors will find a way to ruin it anyway. These apply to a lot of other decentralized systems too.

In no way does IPFS "actually scale" while it takes two minutes (120 seconds) to find an object.

Re: Google flags Immich sites as dangerous

#619

Earlier quoted context omitted.

[flagged]

You should not be downvoted. Either HN has had an influx of ignorant normies or it's google bots attacking any negative comments

HN is extremely tone-policed. Lines like "holy shit look in a mirror" are likely to attract downvotes because of their form, with no other factors being considered.

Re: Google flags Immich sites as dangerous

#620
post #178

Earlier quoted context omitted.

sites.google.com

The same outfit is runimg a domain called blogger. Reminds me of MS blocking a website of mine for dangerous script . The offending thing i did was use document.write to put copyright 2025 (with the current year) at the end of static pages.

To be fair, that's a legally invalid copyright notice.
Post reply on HN