Live data from Hacker News

Google flags Immich sites as dangerous

immich.app

671–680 of 713 posts

Re: Google flags Immich sites as dangerous

#671

Earlier quoted context omitted.

File a small claim for damages up to 10,000 to 20,000 USD depending on your local statues. It’s actually pretty quick and easy. They cannot defend themselves with lawyers, so a director usually has to show up.

Do small claims apply to things like this where damages are indirect?

I believe so. For me it was helpful to visualize getting up and convincing the judge of the damages.

I’d run a PnL, get average daily income from visitors, then claim that loss as damages. In court I’d bring a simple spreadsheet showing the hole in income as evidence of damages.

If there were contractors to help get the site back up I’d claim their payments as damages and include their invoices as evidence.

Re: Google flags Immich sites as dangerous

#672
post #562

Earlier quoted context omitted.

You know because there is an explicit permission box that pops out and asks if you want to give this website access to a device, and asks you to select that device. Same as your camera/microphone/location.

But that still gives completely unvetted direct access to the device to a website! People have been pointing to Itch.io games that supposedly require direct USB access. How hard is it to hide a script in there that reprograms a controller into something malicious?

If you download a executable from a website and run it .. pretty much the same thing?

If you give USB access, it is not really a website anymore, rather a app delivered through the web. I don't see a fundamental difference in trust.

I rather am able to verify the web based version easier and I certainly won't give access to a random website, just like I don't download random exes from websites.

Performance is lower, yes and well ... like I said, it is all a big mess. Just look at the global namespace in js. I still use it because of that power feature called plattform independence. What I release, people can (mostly) just use. I (mostly) don't care which OS the user has.

Re: Google flags Immich sites as dangerous

#673

Earlier quoted context omitted.

The browser still drives when Google throws up a safety warning. It's just harder to drive to one house, and the homeowner is justifiably irritated about this.

The other commenter's analogy of a small-business is better I think, the issue with the browser problem is that it doesn't hinder one person getting to one house, it hinders all persons getting to one place the owner _wants_ people to get to easily. The browser issue can destroy a small business, one thing I think we can universally agree we don't want. If all of the people who come looking for it find it's being mar…

Here's the thing though: if someone else held the keys, the scenario would be the same unless there was no safe browsing protection. And if there were no safe browsing protection, we'd be trading one ill for another; small business owners facing a much steeper curve to compete vs. everyone being at more risk from malware actors.

I honestly don't immediately know how to weigh those risks against each other, but I'll note that this community likely underestimates the second one. Most web users are not nearly as tech- or socially-savvy as the average HN reader and the various methods of getting someone to a malware subdomain are increasingly sophisticated.

Re: Google flags Immich sites as dangerous

#674

Earlier quoted context omitted.

> Monopolistic companies may not actively impose restrictions which harm others (includes businesses) That's not generally how monopoly is interpreted in the US (although jurisprudence on this may be shifting). In general, the litmus test is consumer harm. A company is allowed to control 99% of the market if they do it by providing a better experience to consumers than other companies can; that's just "being successf…

> Too broad. It harms me when Google blocks my malware distribution service because I'm interested in getting malware on your machine; I really want your Bitcoin wallet passwords, you see. ;) That's okay, a random company failing to protect users from harm is still better than harming an innocent person by accident. They already fail in many cases, obviously we accept a failure rate above 0%. You also skipped over th…

I think there's an unevaluated tension in goals between keeping users safe from malware here and making it easy for new sites to reach people, regardless of whether those sites display patterns consistent with malware distributors.

I don't think we can easily discard the first in favor of the second. Not nearly as categorically as is done here. Those "false negatives" mean users lose things (bank accounts, privacy, access to their computer) through no fault of their own. We should pause and consider that before weeping and rending our garments that yet another hosting provider solution had a bad day.

You've stopped considering monopoly and correctly considered that the real issue is safe browsing, as a feature, is useful to users and disruptive to new business models. But that's independent of Google; that's the nature of sharing a network between actors that want to provide useful services to people and actors that want to cause harm. If I build a browser today, from scratch, that included safe browsing we'd be in the same place and there'd be no Google in the story.

Re: Google flags Immich sites as dangerous

#675

Earlier quoted context omitted.

So that you can take input from countrollers that haven't been invented yet and won't fit the HID model.

If it hasn't been invented yet we don't know the implications of giving a website access to it either. And that's before realizing it's already a bad idea with existing devices because they were never designed for giving untrusted actors direct access.

That's why we have a privacy and security sandbox in browsers.

Re: Google flags Immich sites as dangerous

#676

Earlier quoted context omitted.

How else am I going to make a game in the browser that be controlled with a controller?

You don't, that's the point: not everything needs to be crammed into a browser.

Unlikely. The convenience incentives are far too high to leave features on the table.

Not unlike the programming language or the app (growing until it half-implements LISP or half-implements an email client), the browser will grow until it half-implements an operating system.

For everyone else, there's already w3m.

Re: Google flags Immich sites as dangerous

#677

Be sure to see the team's whole list of Cursed Knowledge. https://immich.app/cursed-knowledge

I love Immich & greatly appreciate the amazing work the team put into maintaining it, but between the OP & this "Cursed Knowledge" page, the apparent team culture of shouting from the rooftops complaints that expose their own ignorance about technology is a little concerning to be honest. I've now read the entire Cursed Knowledge list & - while I found some of them to be invaluable insights & absolutely love the idea…

The Date complaint is

> JavaScript date objects are 1 indexed for years and days, but 0 indexed for months.

This mix of 0 and 1 indexing in calendar APIs goes back a long way. I first remember it coming from Java but I dimly recall Java was copying a Taligent Calendar API.

Re: Google flags Immich sites as dangerous

#678
post #672

Earlier quoted context omitted.

But that still gives completely unvetted direct access to the device to a website! People have been pointing to Itch.io games that supposedly require direct USB access. How hard is it to hide a script in there that reprograms a controller into something malicious?

If you download a executable from a website and run it .. pretty much the same thing? If you give USB access, it is not really a website anymore, rather a app delivered through the web. I don't see a fundamental difference in trust. I rather am able to verify the web based version easier and I certainly won't give access to a random website, just like I don't download random exes from websites. Performance is lower,…

A fule thst lands on my hard drive is aztomatically scanned for malware. That same kindof protection isn't in place against malicious scripts downloaded by my broswer via an opaque HTTPS connection and run in process.

Re: Google flags Immich sites as dangerous

#679
post #572
post #54

The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.

> The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker" Being wrong doesn't count as libel. If a company has a detection tool, makes reasonable efforts to make sure it is accurate, and isn't being malicious, you'll have a hard time making a libel case

There is a truth defence to libel in the USA but there is no good faith defence. Think about it like a traffic accident, you may not have intended to drive into the other car but you still caused damage. Just because you meant well doesn't absolve you from paying for the damages.

Re: Google flags Immich sites as dangerous

#680
post #8

If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....

I think it's somewhat tribal webdev knowledge that if you host user generated content you need to be on the PSL otherwise you'll eventually end up where Immich is now. I'm not sure how people not already having hit this very issue before is supposed to know about it beforehand though, one of those things that you don't really come across until you're hit by it.

Besides user uploaded content it's pretty easy to accidentally destroy the reputation of your main domain with subdomains.

For example:

    1. Add a subdomain to test something out
    2. Complete your test and remove the subdomain from your site
    3. Forget to remove the DNS entry and now your A record points to an IP address
At this point if someone else on that hosting provider gets that IP address assigned, your subdomain is now hosting their content.

I had this happen to me once with PDF books being served through a subdomain on my site. Of course it's my mistake for not removing the A record (I forgot) but I'll never make that mistake again.

10 years of my domain having a good history may have gotten tainted in an unrepairable way. I don't get warnings visiting my site but traffic has slowly gotten worse over time since around that time, despite me posting more and more content. The correlation isn't guaranteed, especially with AI taking away so much traffic but it's something I do think about.

Post reply on HN