<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: skatsubo</title><link>https://news.ycombinator.com/user?id=skatsubo</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 20 May 2026 10:25:36 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=skatsubo" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by skatsubo in "Google flags Immich sites as dangerous"]]></title><description><![CDATA[
<p>> This allows any member of the public with a GitHub account to deploy any arbitrary code to that subdomain without any review or approval from the Immich team.<p>This part is not correct: the "preview" label can be set only by collaborators.<p>> a subdomain of a domain that they also use for production traffic<p>To clarify this part: the only production traffic that immich.cloud serves are static map tiles (tiles.immich.cloud)<p>Overall, I share your concerns, and as you already mentioned, a dedicated "immich.build" domain is the way to go.</p>
]]></description><pubDate>Thu, 23 Oct 2025 08:51:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45679705</link><dc:creator>skatsubo</dc:creator><comments>https://news.ycombinator.com/item?id=45679705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45679705</guid></item><item><title><![CDATA[New comment by skatsubo in "Google flags Immich sites as dangerous"]]></title><description><![CDATA[
<p>G would flag _some_ instances.<p>Possible scenario:<p>- A self-hosted project has a demo instance with a default login page (demo.immich.app, demo.jellyfin.org, demo1.nextcloud.com) that is classified as "primary" by google's algorithms<p>- Any self-hosted instance with the same login page (branding, title, logo, meta html) becomes a candidate for deceptive/phishing by their algorithm. And immich.cloud has a lot of preview envs falling in that category.<p>BUT in Immich case its _demo_ login page has its own big banner, so it is already quite different from others.
Maybe there's no "original" at all. The algorithm/AI just got lost among thousands of identically looking login pages and now considers every other instance as deceptive...</p>
]]></description><pubDate>Thu, 23 Oct 2025 08:41:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=45679645</link><dc:creator>skatsubo</dc:creator><comments>https://news.ycombinator.com/item?id=45679645</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45679645</guid></item><item><title><![CDATA[New comment by skatsubo in "Google flags Immich sites as dangerous"]]></title><description><![CDATA[
<p>Add a custom "welcome message" in Server Settings (<a href="https://my.immich.app/admin/system-settings?isOpen=server" rel="nofollow">https://my.immich.app/admin/system-settings?isOpen=server</a>) to make your login page look different compared to all other default Immich login pages.
This is probably the easiest non-intrusive tweak to work around the repeated flagging by Safe Browsing, still no 100% guarantee.  
I agree that strict access blocking (with extra auth or IP ACL) can work better. Though I've seen in this thread <a href="https://news.ycombinator.com/item?id=45676712">https://news.ycombinator.com/item?id=45676712</a> and over the Internet that purely internal/private domains get flagged too. Can it be some Chrome + G Safe Browsing integration, e.g. reporting hashes of visited pages?<p>Btw, folks in the Jellyfin thread tried blocking specifically Google bot / IP ranges (ASNs?) <a href="https://github.com/jellyfin/jellyfin-web/issues/4076#issuecomment-1506148340" rel="nofollow">https://github.com/jellyfin/jellyfin-web/issues/4076#issueco...</a> with varying success.<p>And go through your domain registration/re-review in G Search Console of course.</p>
]]></description><pubDate>Thu, 23 Oct 2025 08:21:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=45679498</link><dc:creator>skatsubo</dc:creator><comments>https://news.ycombinator.com/item?id=45679498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45679498</guid></item></channel></rss>