• MrSulu@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    1 day ago

    Deadly to their margins by 0.000000000000000000000000000000000001%

  • yeehaw@lemmy.ca
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    2
    ·
    edit-2
    1 day ago

    Stop using google. Don’t you know their motto? “Be evil”

    • mic_check_one_two@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Easier said than done, if your end users run Chrome. Because Chrome will automatically block your site if you’re on double secret probation.

      The phishing flag usually happens because you have the Username, Password, Log In, and SSO button all on the same screen. Google wants you to have the Username field, the Log In button, and any SSO stuff on one page. Then if you input a username and go to start a password login, Google expects the SSO to disappear and be replaced by the vanilla Log In button. If you simply have all of the fields and buttons on one page, Google flags it as a phishing attempt. Like I guess they expect you to try and steal users’ Google passwords if you have a password field on the same page as a “Sign in with Google” button.

      • Appoxo@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 day ago

        Firefox ingests Google SafeBrowsing lists.
        If you are falsely flagged as phishing (like I was), then you are fucked regardless of what you use (except you use curl).

        I couldnt even bypass the safebrowse warning on my Android phone in Firefox.

  • Appoxo@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    1 day ago

    Was also flagged recently.
    In my case it was the root domain which is

    1. Geofiltered to only my own Country in Cloudflare
    2. Geofiltered to only my country in my firewall
    3. Protected by Authelia (except the root domain which says 404 when accessing)

    So…IDK what they want from me :p My domain doesnt serve public websites (like a blog) destined for public consumption…

  • FreedomAdvocate@lemmy.net.au
    link
    fedilink
    English
    arrow-up
    18
    arrow-down
    4
    ·
    2 days ago

    Why are the immich teams internal deployments available to anyone on the open web? If you go to one of their links, like they provide in the article, they have an invalid SSL certificate, which google rightly flags as being a security risk, warns you about it, and stops you from going there without manual intervention. This is standard behaviour and no-one should want google to stop doing this.

    I was going to install linux on an old NUC to run immich some time soon, but think I might have to have a look to see if it has been audited by some legit security companies first. How do they not see this issue of their own doing?

    • chaospatterns@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      edit-2
      2 days ago

      It is for pull requests. A user makes a change to the documentation, they want to be able to see the changes on a web page.

      If you don’t have them on the open web, developers and pull request authors can’t see the previews.

      The issue they had was being marked as phishing, not the SSL certificate warning page.

      • FreedomAdvocate@lemmy.net.au
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        2 days ago

        The issue they had was being marked as phishing, not the SSL certificate warning page.

        Have you seen what browsers say when you have a look at the SSL certificate warning page?

        It is for pull requests. A user makes a change to the documentation, they want to be able to see the changes on a web page.

        Why is a user made PR publishing a branch to Immich’s domain for the user to see?

        • BCsven@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          I thought that was how pull requests worked, its a branch if you’veade a departure to edit code, you have the pull request and ask them to merge into the main branch. It should be visible to everyone so everyone can review the change.

      • Nibodhika@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        2 days ago

        It is for pull requests. A user makes a change to the documentation, they want to be able to see the changes on a web page.

        So? What that has to do with SSL certificates? Do you think GitHub loses SSL when viewing PRs?

        If you don’t have them on the open web, developers and pull request authors can’t see the previews.

        You can have them in the open, but without SSL you can’t be sure what you’re accessing, i.e. it’s trivial to make a malicious site to take it’s place an MitM whoever tries to access the real one.

        The issue they had was being marked as phishing, not the SSL certificate warning page.

        Yes, a website without SSL is very likely a phishing attack, it means someone might be impersonating the real website and so it shouldn’t be trusted. Even if by a fluke of chance you hit the right site, all of your communication with it is unencrypted, so anyone in the path can see it clearly.

        • Count042@lemmy.ml
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          2 days ago

          Yes, a website without SSL is very likely a phishing attack, it means someone might be impersonating the real website and so it shouldn’t be trusted. Even if by a fluke of chance you hit the right site, all of your communication with it is unencrypted, so anyone in the path can see it clearly.

          No, Google has hit me with this multiple times for sub domains where the subdomain is the name of the product and has a login page.

          So, for example, if I have emby running at emby.domain.com they’ll mark it as a phishing site. You have to add your domain to their web console and dispute the finding which is probably automated. I’ve had to do this at least three times now.

          All my certs were valid.

          • Nibodhika@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 days ago

            Yes, Google has miss reported my websites in the past, all of which were valid, but the person I’m replying to seemed to assume no-SSL is a requirement of the feature, and he doesn’t understand that a wrong/missing SSL is indistinguishable from a Phishing attack, and that the SSL error page is the one that warns you about phishing (with reason).

    • yeehaw@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 days ago

      You could just host it inside your network and do an always on VPN. That’s what I do.

      • RheumatoidArthritis@mander.xyz
        link
        fedilink
        English
        arrow-up
        8
        ·
        2 days ago

        Now imagine you’re running a successful open source project developed in the open, where it’s expected that people outside your core team review and comment on changes.

      • chaospatterns@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        How would that work? The use case is for previews for pull requests. Somebody submits a change to the website. This creates a preview domain that reviewers and authors can see their proposed changes in a clean environment.

        CloudFlare pages gives this behavior out of the box.

    • Vex_Detrause@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      I knew it was too good to be true when they give away free pic storage for their pixel phones. I just didn’t listen to my gut.

  • 𝘋𝘪𝘳𝘬@lemmy.ml
    link
    fedilink
    English
    arrow-up
    53
    ·
    2 days ago

    The URLs mentioned in their blog article all have a wrong certificate (different host name).

    I am sure if they fix it Google’s system would reclassify the sites as safe.

    • RheumatoidArthritis@mander.xyz
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Yeah, sure, 5 years after google flagged one of the sites i hosted, some firewalls (including isp-level blocks) mark the domain as unsafe. Google removed the block after more than a week but the stink continues until today.

      It was also a development domain and we were forced to change it.

    • porcoesphino@mander.xyz
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      2 days ago

      I think that marking things as “safe” could have more complications than this depending on their definition but I think you’re right that’s probably all this issue is. This is almost the only sane comment here. Everyone else seems to be frothing at the mouth and I’m guessing its a decent mix of not understanding much of how these systems work (and blindly running tutorials for those that do self host) and blind ideology (big companies are bad / any practice that restricts my personal freedom in any way is bad)

      • Rooty@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        24 hours ago

        any practice that restricts my personal freedom in any way is bad

        Yes? I don’t want to live in a world where giant companies decide what I can and cannot see. And big companies are bad, they act as pseudo governments that aren’t accountable to anyone, we used to break them apart before they started buying up politicians and political power.

        • porcoesphino@mander.xyz
          link
          fedilink
          English
          arrow-up
          1
          ·
          23 hours ago

          Agreed after the yes.

          I’m not sure how what you said either: justifies the comments not fitting that label; justifies that “any practice that restricts my personal freedom in any way is bad” is a practical ideology; or even establishes much a link between what you’ve quoted and what you’ve said. And I think you need to be doing one of those to be making a counter argument

      • anyhow2503@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        I don’t blame people for thinking that something is off after reading the linked blog post. This wouldn’t be the first time Google does something like this to OSS that poses some kind of potential threat to their business model (this is also mentioned in the post).

  • Darkcoffee@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    37
    arrow-down
    4
    ·
    2 days ago

    They’ve also started warning against android apps from outside repos. Basically they want to force people to use their ai-filled bullshit apps.

  • WhyJiffie@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    jellyfin had a similar issue too for a long time for servers exposed to the internet. google would always reblock the domains soon after unblocking them. I think they solved it in the latest update. Basically it’s that google’s scraping bots think that all jellyfin servers are a scam that imitate a “real” website.

  • A_norny_mousse@feddit.org
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    edit-2
    2 days ago

    Same when you try to deviate from the approved path of email providers or, dog forbid, even self-host email.

    This is why I always switch off that “block potentially dangerous sites” setting in my browser - it means Google’s blacklists. This is how Google influences the web beyond its own products.

    edit: it’s much more complex than simple blocklists with email

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      3
      ·
      edit-2
      2 days ago

      I wouldn’t recommend turning off safe browsing

      If a page is blocked it is very easy to bypass. However, the warning page will make you take a step back.

      For instance, someone could create a fake Lemmy instance at fedit.org to harvest credentials.