• FreedomAdvocate@lemmy.net.au
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Why are the immich teams internal deployments available to anyone on the open web? If you go to one of their links, like they provide in the article, they have an invalid SSL certificate, which google rightly flags as being a security risk, warns you about it, and stops you from going there without manual intervention. This is standard behaviour and no-one should want google to stop doing this.

    I was going to install linux on an old NUC to run immich some time soon, but think I might have to have a look to see if it has been audited by some legit security companies first. How do they not see this issue of their own doing?

    • yeehaw@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      You could just host it inside your network and do an always on VPN. That’s what I do.

      • RheumatoidArthritis@mander.xyz
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        1 month ago

        Now imagine you’re running a successful open source project developed in the open, where it’s expected that people outside your core team review and comment on changes.