The .internal.immich.cloud sites do not have matching certs! Navigating to https://main.preview.internal.immich.cloud , I'm right away informed by the browser that the connection is not secure due to an issue with the certificate. The problem is that it has the following CN (common name): main.preview.internal.immich.build. The list of alternative names also contains that same domain name. It does not match the site:…
Google flags Immich sites as dangerous
611–620 of 713 posts
Re: Google flags Immich sites as dangerous
#612Simply opening a case saying that this is our website not impersonating anyone else is unlikely to get anything resolved. Just because it's your website, and you're not a bad agent doesn't prove that no part of the site is under the control of a bad agent, and that your site isn't accidentally hosting something malicious somewhere, or have some UI that is exploitable for cross-site scripting or whatever.
Re: Google flags Immich sites as dangerous
#613Looking forward to Louis Rossmann's reaction. Wouldn't be surprised if this leads to a lawsuit over monopolistic behavior - this is clearly abusing their dominant position in the browser space to eliminate competitors in photos sharing.
Re: Google flags Immich sites as dangerous
#614Earlier quoted context omitted.
I really don't know how they got nerds to think scummy advertising is cool. If you think about it, the thing they make money on - no user actually wants ads or wants to see them, ever. Somehow Google has some sort of nerd cult that people think its cool to join such an unethical company.
[flagged]
>I think they all are pretty happy with the deal and would not switch to a paid ad-free version.
If they were given a low friction option to pay the advertise price for these services I think a lot would choose it. Advertisement pays almost nothing per person. Almost every person could pay more than the cost to serve them an ad. To use a service ad free for a year would cost less than $1 per user. This differs on the platform obviously with stuff like youtube being far more expensive but for day to day stuff the cost is low.
Re: Google flags Immich sites as dangerous
#615Earlier quoted context omitted.
I'll flip that around on you: why oh why do we need to browsers to carry these security holes in them? The Stadia flasher is a good example: how do I know that a website doesn't contain a device flasher that will turn one of my connected devices into a malicious actor that will attempt to take over whatever machine it's plugged into?
You know because there is an explicit permission box that pops out and asks if you want to give this website access to a device, and asks you to select that device. Same as your camera/microphone/location.
Re: Google flags Immich sites as dangerous
#616Earlier quoted context omitted.
Why should curation be centralized? We do not need a "decentralized dictatorship" (what would that even be? that's antithetical) and we certainly do not need a centralized one. It seems crazy that your solutions to AI, spam, and "automated traffic" (I don't know what that is, I assume web crawlers and such) is that the police control every single transaction. First off, we can simply let the user, or client software,…
> For mail, couldn't we come up with a mail-DNS, that authenticates senders? So RFC 7672? https://datatracker.ietf.org/doc/html/rfc7672
Also, I think it solves a different problem: it prevents spoofing/MITM but what about legitimate certificates? We would still need CAs that actually curate their customers and hold them accountable. And we would need email servers/clients to differentiate between strict CAs and ones that are used solely for encryption purposes.
I don't know that DNS should be applied to emails as is anyway but I find it could force spammers to operate with publicly available information which would make holding them accountable easier.
Re: Google flags Immich sites as dangerous
#617Earlier quoted context omitted.
I love Immich & greatly appreciate the amazing work the team put into maintaining it, but between the OP & this "Cursed Knowledge" page, the apparent team culture of shouting from the rooftops complaints that expose their own ignorance about technology is a little concerning to be honest. I've now read the entire Cursed Knowledge list & - while I found some of them to be invaluable insights & absolutely love the idea…
> Carriage returns in bash scripts are cursed Also the full story here seemed to be 1. Person installs git on Windows with autocrlf enabled, automatically converting all LF to CRLF (very cursed in itself in my opinion). 2. Does their thing with git on the Windows' side (clone, checkout, whatever). 3. Then runs the checked out (and now broken due to autocrlf) code on Linux instead of Windows via WSL. The biggest footg…
Re: Google flags Immich sites as dangerous
#618Earlier quoted context omitted.
I'm beginning to seriously think we need a new internet, another protocol, other browsers just to break up the insane monopolies that has been formed, because the way things are going soon all discourse will be censored, and competitors will be blocked soon. We need something that's good for small and medium businesses again, local news and get an actual marketplace going - you know what the internet actually promise…
IPFS has been doing some great work around decentralization that actually scales (Netflix uses it internally to speed up container delivery), but a) it's only good for static content, b) things still need friendly URLs, and c) once it becomes the mainstream, bad actors will find a way to ruin it anyway. These apply to a lot of other decentralized systems too.
Re: Google flags Immich sites as dangerous
#619Earlier quoted context omitted.
[flagged]
You should not be downvoted. Either HN has had an influx of ignorant normies or it's google bots attacking any negative comments
Re: Google flags Immich sites as dangerous
#620Earlier quoted context omitted.
sites.google.com
The same outfit is runimg a domain called blogger. Reminds me of MS blocking a website of mine for dangerous script . The offending thing i did was use document.write to put copyright 2025 (with the current year) at the end of static pages.