Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

641–650 of 713 posts

Re: Google flags Immich sites as dangerous

#641

Earlier quoted context omitted.

In the past, browsers used an algorithm which only denied setting wide-ranging cookies for top-level domains with no dots (e.g. com or org). However, this did not work for top-level domains where only third-level registrations are allowed (e.g. co.uk). In these cases, websites could set a cookie for .co.uk which would be passed onto every website registered under co.uk. Since there was and remains no algorithmic meth…

All web encryption is backed by static list of root certs each browser maintains. Idk any other way to solve it for the general public (ideally each user would probably pick what root certs they trust), but it does seem crazy.

We already have a solution to solve it: DNS-based Authentication of Named Entities (DANE)

This solution is even more obvious today where most certificates are just DNS lookups with extra steps.

Re: Google flags Immich sites as dangerous

#642

Earlier quoted context omitted.

I think what gets me more is I don't see an easy way to add suffixes to the list. I'm sure if I dig I can figure it out but you'd think given how its used they'd have an obvious step by step guide on the website

Last link the menu header: https://publicsuffix.org/submit/ Which then links to: https://github.com/publicsuffix/list/wiki/Guidelines#submitt... Fairly obvious and typical webpage > documentation flow I think, doesn't seem too hard to find.

Ok so we need a GitHub (Microsoft) account to avoid needing a Google account to in case some undocumented system decides to shut down a website we host. Great.

Re: Google flags Immich sites as dangerous

#643

Earlier quoted context omitted.

I will go with Google being bad / evil for 500. Google 90s to 2010 is nothings like Google 2025. There is a reason they removed "Don't be evil" ... being evil and authoritarian makes more money. Looking at you Manifest V2 ... pour one out for your homies.

Don't get me wrong, Google is bad/evil in many ways, but the public suffix list exists to solve a real risk to users. Google is flagging this for a legit reason in this particular case.

It's not a legit reason at all. A website isn't "unsafe" just because it looks similar to another one to Google's AI. At best such an automated flag should trigger a human review, not take the website offline.

Google needs to be held liable for the damages they do in cases like this or they will continue to implement the laziest solutions as long as they can externalize the costs.

Re: Google flags Immich sites as dangerous

#644

Earlier quoted context omitted.

I will go with Google being bad / evil for 500. Google 90s to 2010 is nothings like Google 2025. There is a reason they removed "Don't be evil" ... being evil and authoritarian makes more money. Looking at you Manifest V2 ... pour one out for your homies.

Sympathy for the devil, people keep using Google's browser because the safe search guards catch more bad actors than they false positive good actors.

This is not an honest argument. Most people don't even know this web censorship mechanism exists until they see something (usually legit) blocked.

Re: Google flags Immich sites as dangerous

#645
post #124

Earlier quoted context omitted.

I don't think the Internet should be run by being on special lists (other than like, a globally run registry of domain names)... I get that SPAM, etc., are an issue, but, like f* google-chrome, I want to browse the web, not some carefully curated list of sites some giant tech company has chosen. A) you shouldn't be using google-chrome at all B) Firefox should definitely not be using that list either C) if you are goi…

Firefox and Safari also use the list. At least by default, I think you can turn it off in firefox. And on the whole, I think it is valuable to have _a_ list of known-unsafe sites. And note that Safe Browsing is a blocklist, not an allowlist. The problem is that at least some of the people maintaining this list seem to be a little trigger happy. And I definitely thing Google probably isn't the best custodian of such a…

> I think it is valuable to have _a_ list of known-unsafe sites

But this is not that list because sites are added using opaque automated processes that are clearly not being reviewed by humans - even if those sites have been removed previously after manual review.

Re: Google flags Immich sites as dangerous

#646

Earlier quoted context omitted.

That means the Safe Browsing abuse could be weaponized against self-hosted services, oh my...

New directive from the Whitehouse. Block all non approved sites. If you don't do it we will block your merger etc...

Yeah it's only time until someone in power will realize there is already a mechanism for global web censorship that they can make use of.

Re: Google flags Immich sites as dangerous

#647
post #393

Earlier quoted context omitted.

Is the subdomain named immich or something more general?

The subdomain is "immich", which has crossed my mind as a potential flagging characteristic.

Don't accept that rhetoric. Google shouldn't get to decide how you can design your own website.

Re: Google flags Immich sites as dangerous

#648
post #57

Earlier quoted context omitted.

The root cause is bad behaviour by google. This is merely a workaround.

[flagged]

It's not a "service" at all. It's Google maliciously inserting themselves into the browsing experience of users, including those that consciously choose a non-Google browser, in order to build a global web censorship system.

Re: Google flags Immich sites as dangerous

#650

Earlier quoted context omitted.

There is no law appointing that organization as a world wide authority on tainted/non tainted sites. The fact it's used by one or more browsers in that way is a lawsuit waiting to happen. Because they, the browsers, are pointing a finger to someone else and accusing them of criminal behavior. That is what a normal user understands this warning as. Turns out they are wrong. And in being wrong they may well have harmed…

As far as I know there is currently no international alternative authority for this. So definitely not ideal, but better than not having the warnings.

The alternative is to not do this.
Post reply on HN