Has this impacted your self hosted instances of Immich? Are you hosting Immich via subdomain?
Related:
https://immich.app/blog/google-flags-immich-as-dangerous
Has this impacted your self hosted instances of Immich? Are you hosting Immich via subdomain?
Related:
80 Comments
aarch0x40@lemmy.world · 172 pts · 296d
Google, protecting you from privacy
InnerScientist@lemmy.world · 39 pts · 296d
Google protecting Google from FOSS.
They're right too, after using Immich I don't want to go back.
witten@lemmy.world · 2 pts · 295d
wesker@lemmy.sdf.org · 75 pts · 296d
I have identified the problem.
Prathas@lemmy.zip · 1 pts · 293d
... for which all solutions are pitifully incapable, relatively speaking.
ramenshaman@lemmy.world · 57 pts · 296d
I smell fear.
Vex_Detrause@lemmy.ca · 2 pts · 295d
I knew it was too good to be true when they give away free pic storage for their pixel phones. I just didn't listen to my gut.
Dirk@lemmy.ml · 55 pts · 296d
The URLs mentioned in their blog article all have a wrong certificate (different host name).
I am sure if they fix it Google’s system would reclassify the sites as safe.
porcoesphino@mander.xyz · 12 pts · 296d
I think that marking things as "safe" could have more complications than this depending on their definition but I think you're right that's probably all this issue is. This is almost the only sane comment here. Everyone else seems to be frothing at the mouth and I'm guessing its a decent mix of not understanding much of how these systems work (and blindly running tutorials for those that do self host) and blind ideology (big companies are bad / any practice that restricts my personal freedom in any way is bad)
anyhow2503@lemmy.world · 1 pts · 295d
I don't blame people for thinking that something is off after reading the linked blog post. This wouldn't be the first time Google does something like this to OSS that poses some kind of potential threat to their business model (this is also mentioned in the post).
Rooty@lemmy.world · 1 pts · 294d
Yes? I don't want to live in a world where giant companies decide what I can and cannot see. And big companies are bad, they act as pseudo governments that aren't accountable to anyone, we used to break them apart before they started buying up politicians and political power.
porcoesphino@mander.xyz · 1 pts · 294d
Agreed after the yes.
I'm not sure how what you said either: justifies the comments not fitting that label; justifies that "any practice that restricts my personal freedom in any way is bad" is a practical ideology; or even establishes much a link between what you've quoted and what you've said. And I think you need to be doing one of those to be making a counter argument
RheumatoidArthritis@mander.xyz · 3 pts · 295d
Yeah, sure, 5 years after google flagged one of the sites i hosted, some firewalls (including isp-level blocks) mark the domain as unsafe. Google removed the block after more than a week but the stink continues until today.
It was also a development domain and we were forced to change it.
Darkcoffee@sh.itjust.works · 35 pts · 296d
They've also started warning against android apps from outside repos. Basically they want to force people to use their ai-filled bullshit apps.
Meron35@lemmy.world · 35 pts · 296d
Immich users flag Google sites as dangerous
makingStuffForFun@lemmy.ml · 23 pts · 296d
Google marks half the apps on my phone as dangerous. Google are evil xxxxxx's
cyberpunk007@lemmy.ca · 22 pts · 295d
Stop using google. Don't you know their motto? "Be evil"
mic_check_one_two@lemmy.dbzer0.com · 6 pts · 295d
Easier said than done, if your end users run Chrome. Because Chrome will automatically block your site if you’re on double secret probation.
The phishing flag usually happens because you have the Username, Password, Log In, and SSO button all on the same screen. Google wants you to have the Username field, the Log In button, and any SSO stuff on one page. Then if you input a username and go to start a password login, Google expects the SSO to disappear and be replaced by the vanilla Log In button. If you simply have all of the fields and buttons on one page, Google flags it as a phishing attempt. Like I guess they expect you to try and steal users’ Google passwords if you have a password field on the same page as a “Sign in with Google” button.
Appoxo@lemmy.dbzer0.com · 7 pts · 295d
Firefox ingests Google SafeBrowsing lists.
If you are falsely flagged as phishing (like I was), then you are fucked regardless of what you use (except you use curl).
I couldnt even bypass the safebrowse warning on my Android phone in Firefox.
Appoxo@lemmy.dbzer0.com · 5 pts · 295d
OP is impacted by Google SafeBrowsing which various websites use.
A_norny_mousse@feddit.org · 16 pts · 296d
Same when you try to deviate from the approved path of email providers or, dog forbid, even self-host email.
This is why I always switch off that "block potentially dangerous sites" setting in my browser - it means Google's blacklists. This is how Google influences the web beyond its own products.
edit: it's much more complex than simple blocklists with email
possiblylinux127@lemmy.zip · 4 pts · 296d
I wouldn't recommend turning off safe browsing
If a page is blocked it is very easy to bypass. However, the warning page will make you take a step back.
For instance, someone could create a fake Lemmy instance at fedit.org to harvest credentials.
hexagonwin@lemmy.sdf.org · 3 pts · 295d
just use ublock origin and a proper password manager. google safe browsing means google sees what sites you browse.
Andres4NY@social.ridetrans.it · 2 pts · 296d
@possiblylinux127 @A_norny_mousse ungoogled-chromium disables safe browsing, and for Debian's chromium package I keep going back and forth about whether to pull that patch in or not.
A_norny_mousse@feddit.org · 1 pts · 295d
@Andres4NY@social.ridetrans.it
Running Debian Stable, I have installed ungoogled-chromium which is also in the repos.
But Librewolf is my main browser, Chromium a rarely used secondary.
What I'm talking about is how these blocklists are used by many other browsers/softwares (e.g. Firefox) as well.
ripcord@lemmy.world · 2 pts · 296d
This is why I always don't use Chrome or Google Search
FreedomAdvocate@lemmy.net.au · 15 pts · 295d
Why are the immich teams internal deployments available to anyone on the open web? If you go to one of their links, like they provide in the article, they have an invalid SSL certificate, which google rightly flags as being a security risk, warns you about it, and stops you from going there without manual intervention. This is standard behaviour and no-one should want google to stop doing this.
I was going to install linux on an old NUC to run immich some time soon, but think I might have to have a look to see if it has been audited by some legit security companies first. How do they not see this issue of their own doing?
chaospatterns@lemmy.world · 9 pts · 295d
It is for pull requests. A user makes a change to the documentation, they want to be able to see the changes on a web page.
If you don't have them on the open web, developers and pull request authors can't see the previews.
The issue they had was being marked as phishing, not the SSL certificate warning page.
Nibodhika@lemmy.world · 0 pts · 295d
So? What that has to do with SSL certificates? Do you think GitHub loses SSL when viewing PRs?
You can have them in the open, but without SSL you can't be sure what you're accessing, i.e. it's trivial to make a malicious site to take it's place an MitM whoever tries to access the real one.
Yes, a website without SSL is very likely a phishing attack, it means someone might be impersonating the real website and so it shouldn't be trusted. Even if by a fluke of chance you hit the right site, all of your communication with it is unencrypted, so anyone in the path can see it clearly.
Count042@lemmy.ml · 4 pts · 295d
No, Google has hit me with this multiple times for sub domains where the subdomain is the name of the product and has a login page.
So, for example, if I have emby running at emby.domain.com they'll mark it as a phishing site. You have to add your domain to their web console and dispute the finding which is probably automated. I've had to do this at least three times now.
All my certs were valid.
Nibodhika@lemmy.world · 2 pts · 295d
Yes, Google has miss reported my websites in the past, all of which were valid, but the person I'm replying to seemed to assume no-SSL is a requirement of the feature, and he doesn't understand that a wrong/missing SSL is indistinguishable from a Phishing attack, and that the SSL error page is the one that warns you about phishing (with reason).
FreedomAdvocate@lemmy.net.au · 0 pts · 295d
Have you seen what browsers say when you have a look at the SSL certificate warning page?
Why is a user made PR publishing a branch to Immich's domain for the user to see?
BCsven@lemmy.ca · 1 pts · 294d
I thought that was how pull requests worked, its a branch if you'veade a departure to edit code, you have the pull request and ask them to merge into the main branch. It should be visible to everyone so everyone can review the change.
FreedomAdvocate@lemmy.net.au · 1 pts · 291d
The branch for the PR shouldn't be hosted on the production site's domain, and that deployment that the company will be testing and reviewing shouldn't be accessible to the public. They even have internal in the URL, while being accessible by external people lol
cyberpunk007@lemmy.ca · 1 pts · 295d
You could just host it inside your network and do an always on VPN. That's what I do.
RheumatoidArthritis@mander.xyz · 7 pts · 295d
Now imagine you're running a successful open source project developed in the open, where it's expected that people outside your core team review and comment on changes.
chaospatterns@lemmy.world · 1 pts · 295d
How would that work? The use case is for previews for pull requests. Somebody submits a change to the website. This creates a preview domain that reviewers and authors can see their proposed changes in a clean environment.
CloudFlare pages gives this behavior out of the box.
cyberpunk007@lemmy.ca · 1 pts · 295d
Ah, I missed that part
cupcakezealot@piefed.blahaj.zone · 12 pts · 296d
this is why you disable google "safe browsing" in librewolf and use badblock instead
ripcord@lemmy.world · 4 pts · 296d
Librewolf has Google "safe browsing" to disable...? Google?
cupcakezealot@piefed.blahaj.zone · 8 pts · 296d
firefox has google safe browser api protection; librewolf disables it by default under librewolf settings.
https://support.mozilla.org/en-US/kb/safe-browsing-firefox-focus
N0x0n@lemmy.ml · 1 pts · 295d
Thanks for sharing this nice blocklist :)
WhyJiffie@sh.itjust.works · 11 pts · 295d
jellyfin had a similar issue too for a long time for servers exposed to the internet. google would always reblock the domains soon after unblocking them. I think they solved it in the latest update. Basically it's that google's scraping bots think that all jellyfin servers are a scam that imitate a "real" website.
01189998819991197253@infosec.pub · 21 pts · 295d
But the malvertisements on Google's front page are ok, I guess
MalReynolds@piefed.social · 3 pts · 295d
What is the usecase for exposing jellyfin to the outernet anyway ?
Appoxo@lemmy.dbzer0.com · 4 pts · 295d
What's the usecase for Netflix? Same case.
WhyJiffie@sh.itjust.works · 3 pts · 295d
watching it remotely, like at friends. even if you can access it on your phone through VPN, the smart TV won't be able to use it
umbrella@lemmy.ml · 11 pts · 294d
NewNewAugustEast@lemmy.zip · 11 pts · 296d
Fuck you google. I can't see youtube videos with my browser because google wants me to sign in. Tells me it is protecting the community.
BULLSHIT.
Because google doesnt make me sign in to view or edit someone elses google docs they are sharing. Which one is more important google? Assholes.
FreedomAdvocate@lemmy.net.au · 1 pts · 295d
I'm guessing the videos are age restricted 18+ videos? You don't have to be signed in to watch any other videos.
asbestos@lemmy.world · 2 pts · 295d
Nope, sometimes it asks for normal videos as well, it really depends on the case since there’s a lot of background stuff happening, making the experience vary between users.
NewNewAugustEast@lemmy.zip · 1 pts · 295d
No, not age restricted.
Happens most frequently with using any VPN, which we use all the time at work and I often use at home or while traveling.
But sometimes it just does it without.
I think most people are signed into their gmail account or have been recently so the cookie is set. It's crazy when you don't have one how hard Google pushes you.
FreedomAdvocate@lemmy.net.au · 1 pts · 295d
YouTube doesn’t force you to sign in unless the content you’re trying to watch is 18+. That’s just how it works. Your IP address makes no difference.
I’m not signed in to YouTube. Ever. On any device. I have never been forced to sign in to watch anything that wasn’t age restricted.
NewNewAugustEast@lemmy.zip · 2 pts · 295d
How should I prove this to you then? You are wrong, it is not just age content.
I could make a short video, or screen capture, but that's more effort than it's worth.
I am telling you, this happens all the damn time and it's getting annoying.
FreedomAdvocate@lemmy.net.au · 2 pts · 291d
Find a video that asks you to sign in that isn't 18+ or private.
That's really zero effort since it "happens all the damn time"
NewNewAugustEast@lemmy.zip · 0 pts · 291d
So weird you should argue about this. Do you always tell people "that doesnt happen to me so it doesn't happen to you". Why would I lie about it?
Why are you such an asshole?
This is my constant experience with youtube. which happened today while I was checking on the hurricane in Jamaica.
FreedomAdvocate@lemmy.net.au · 1 pts · 291d
I tell people things that what they’re saying is wrong when it is wrong.
All you had to say was that it thinks you’re a bot, and then this whole thing could have been avoided. Which vpn are you using?
MrSulu@lemmy.ml · 10 pts · 295d
Deadly to their margins by 0.000000000000000000000000000000000001%
oneser@lemmy.zip · 6 pts · 296d
Similar issues were reported with aves libre early this week, maybe it's related?
https://github.com/deckerst/aves/issues/1802
artyom@piefed.social · 8 pts · 296d
From the OP:
Google Safe Browsing looks to be have been built without consideration for open-source or self-hosted software. Many popular projects have run into similar issues, such as:
Jellyfin
YunoHost
n8n
NextCloud
phoenixz@lemmy.ca · 9 pts · 296d
I'm sure it's all accidental and coincidental that open source project that rival Google just weirdly got flagged as being dangerous. Google also doesn't know how this happened, it just did! Magic!
exu@feditown.com · 2 pts · 295d
It probably is accidental, but they don't care enough to fix the root problem
phoenixz@lemmy.ca · 0 pts · 286d
Uh huh.
Loads of scam projects on play store that rarely get taken down but a competitor on play store gets sabotaged. I'm sure it's purely coincidental
artyom@piefed.social · 2 pts · 296d
Clearly their run-in with the DOJ and subsequent wrist-slap has emboldened them to new heights of anticompetitiveness.
ITGuyLevi@programming.dev · 6 pts · 295d
I got a 'dangerous site' warning and then prompts for crap on my Vaultwarden instance (didn't see it on Immich but this was a while ago). I think I had to prove I owned the domain with some DNS TXT records then let them "recheck" the domain. It seems to have worked.
lambalicious@lemmy.sdf.org · 5 pts · 296d
Why would people have Google security going on if they have set up F-Droid as their appstore? Doesn't that defeat the entire purpose?
Dave@lemmy.nz · 1 pts · 296d
Well according to the OP, it's a list they offer for free and it's integrated with many browsers including Firefox...
Mika@piefed.ca · 0 pts · 296d
Like I understand that if I buy a phone from Apple, and they control everything on the phone and what I can install - well I mean I bought it from Apple, what else did I expect?
But I didn't buy my phone from Google. They should have no say in what I could or couldn't install.
FreedomAdvocate@lemmy.net.au · 3 pts · 295d
You bought a phone running a Google operating system, knowingly so. This one is on you buddy.
ripcord@lemmy.world · 2 pts · 296d
I mean, I don't think it matters if you bought the phone from Google or not (and you could have). Samsung or Motorola or whoever shouldn't have any say either.
Appoxo@lemmy.dbzer0.com · 5 pts · 295d
Was also flagged recently.
In my case it was the root domain which is
So....IDK what they want from me :p My domain doesnt serve public websites (like a blog) destined for public consumption...
FreedomAdvocate@lemmy.net.au · 1 pts · 295d
Is it available for the public to get to? Yes, so that’s why.
possiblylinux127@lemmy.zip · 3 pts · 296d
Hopefully your Immich server isn't public facing...
spaghettiwestern@sh.itjust.works · 3 pts · 296d
IMO Google Save Browsing was built with consideration for open-source and self-hosted software, but it has nothing to do with user safety, just like blocking Android apps from 3rd party sites has nothing to do with user safety. The harder they make it to move away from their products by making using alternatives difficult, the more money they make and money is now the only objective. Even if this only adds a fraction of a fraction of a percent to their profit it's something Google will implement.
The old social contract of businesses being of benefit to the community as a whole in addition to making a profit is long gone.
Onomatopoeia@lemmy.cafe · 1 pts · 295d
Google has always been evil. Why else was their byline "Don't be evil"?
If you have to make such a disclaimer...