# Deceptive site ahead for my node-red sites

**URL:** <https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925>\
**Category:** General\
**Created:** [25 April 2023 15:25 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925 "2023-04-25T15:25:35Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![makerstorage](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/makerstorage/32/57594_2.png) [@makerstorage](https://discourse.nodered.org/u/makerstorage)\
**Post date:** [25 April 2023 15:25 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/1 "2023-04-25T15:25:35Z")

</div>

Hi,

Chrome is showing red Deceptive site ahead when I visit my node-red site.  
I have 3 websites running node-red and all stared to give this warning. Any idea on how to get rid of it.

Regards,  
Nuri

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [25 April 2023 15:33 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/2 "2023-04-25T15:33:52Z")

</div>

Sounds like you have a virus or something. Is your node-red instance connected to the internet ?

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [25 April 2023 17:52 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/3 "2023-04-25T17:52:31Z")

</div>

What, exactly, is it saying? Post a screenshot.

Usually there is a 'more details' option somewhere ...

Are you using HTTP or HTTPS ?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 April 2023 11:51 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/4 "2023-04-26T11:51:53Z")

</div>

> [@makerstorage](#):
>
> Chrome is showing red Deceptive site ahead when I visit my node-red site.  
> I have 3 websites running node-red and all stared to give this warning. Any idea on how to get rid of it.

Assuming you are using HTTPS, your certificate is invalid. Has it expired? Or does it have the wrong domain?

Bottom line is that you need to fix the certificate.

---

<div class="post-metadata">

**Author:** ![makerstorage](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/makerstorage/32/57594_2.png) [@makerstorage](https://discourse.nodered.org/u/makerstorage)\
**Post date:** [26 April 2023 16:15 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/5 "2023-04-26T16:15:21Z")

</div>

![Screenshot 2023-04-26 at 19.13.46](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/2/9/2957ceee2e1f319540390d25532d08d15bebe02a.jpeg)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 April 2023 17:42 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/6 "2023-04-26T17:42:16Z")

</div>

Ah, interesting. That implies that there is something about `3dmetri.com` that your browser finds unpleasant.

This scan doesn't seem to object: [nodered.3dmetri.com - SiteCheck (sucuri.net)](https://sitecheck.sucuri.net/results/https/nodered.3dmetri.com)

And my Edge browser is quite happy too.

Do you have any other anti-malware software running?

Try accessing from an in-private browser session too (so no extensions loaded).

---

<div class="post-metadata">

**Author:** ![awneil](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@awneil](https://discourse.nodered.org/u/awneil)\
**Post date:** [27 April 2023 07:43 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/7 "2023-04-27T07:43:54Z")

</div>

So what does it say if you click 'Learn more' ?

---

<div class="post-metadata">

**Author:** ![aderici](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/aderici/32/37279_2.png) [@aderici](https://discourse.nodered.org/u/aderici)\
**Post date:** [17 May 2023 11:39 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/8 "2023-05-17T11:39:09Z")

</div>

This is a serious problem. I'm having the same here. All my node red web sites being flagged the same for both chrome and safari browsers. Deceptive site means phishing and google doesnt reveal the algorithm. Any help is apreciated

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [17 May 2023 11:49 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/9 "2023-05-17T11:49:55Z")

</div>

Various people tried to help @makerstorage by asking questions about their Node-red site.  
Because they didn't report back we can only assume that they resolved their problem.

So bearing that in mind, is there any more information you think might help us help you?

---

<div class="post-metadata">

**Author:** ![aderici](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/aderici/32/37279_2.png) [@aderici](https://discourse.nodered.org/u/aderici)\
**Post date:** [17 May 2023 12:39 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/10 "2023-05-17T12:39:01Z")

</div>

This is the error message that i'm seeing. This is one of the many possible similar messages shared by "safe browsing". Deceptive site refers to "phishing" meaning a site that tries to steal your passwords etc.

I masked the site address but i see this on many of my node reds.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/a/aaeaa718478a7321fb7cf1c1bb3c9e5b500437b5.png)

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [17 May 2023 12:52 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/11 "2023-05-17T12:52:09Z")

</div>

This is a Node-red instance in the cloud then?  
I don't personally have much knowledge of cloud hosting and HTTPS but for sure other forum contributors do.

---

<div class="post-metadata">

**Author:** ![aderici](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/aderici/32/37279_2.png) [@aderici](https://discourse.nodered.org/u/aderici)\
**Post date:** [17 May 2023 12:57 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/12 "2023-05-17T12:57:24Z")

</div>

This is hosted in the Azure cloud yes. This has nothing to do with https. All certificates valid. Site is technically secure.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [17 May 2023 13:12 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/13 "2023-05-17T13:12:13Z")

</div>

I see it on that site too, so it is something specific to your flows or the way it is hosted.  
If you run the site locally do you see it?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 May 2023 13:25 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/14 "2023-05-17T13:25:07Z")

</div>

> [@aderici](#):
>
> This is hosted in the Azure cloud yes

Is it in your own Azure tenancy or a shared one? If your own, I recommend giving your URL to one or two of the sites that explicitly check for security issues - hopefully that will highlight the problem Google has with it.

A few to try:

- [https://cspvalidator.org](https://cspvalidator.org)
- [https://webxray.org/](https://webxray.org/)
- [https://observatory.mozilla.org](https://observatory.mozilla.org)
- [https://webhint.io/scanner/](https://webhint.io/scanner/)
- [Blacklight – The Markup](https://themarkup.org/blacklight)

* * *

Of course, there is also a better, easier and more private way of avoiding this - stop using Google Chrome.

---

<div class="post-metadata">

**Author:** ![aderici](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/aderici/32/37279_2.png) [@aderici](https://discourse.nodered.org/u/aderici)\
**Post date:** [17 May 2023 15:04 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/15 "2023-05-17T15:04:23Z")

</div>

Same with safari.

---

<div class="post-metadata">

**Author:** ![aderici](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/aderici/32/37279_2.png) [@aderici](https://discourse.nodered.org/u/aderici)\
**Post date:** [17 May 2023 15:07 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/16 "2023-05-17T15:07:01Z")

</div>

they do a periodic scan of the sites. I don't think it is about the way this is hosted. Your local instance will not get a chance to get scanned by google. This is like indexing, they detect and save the results for your site and browsers would rely on these.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [17 May 2023 16:49 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/17 "2023-05-17T16:49:29Z")

</div>

> [@aderici](#):
>
> Same with safari.

Really - does Safari use Google's "Safe" browsing list? ~~Feels unlikely.~~ And yet Bing chat tells me otherwise! Brave, Chrome, GNOME Web, Firefox, Safari and Vivaldi all use it.

> [@aderici](#):
>
> browsers would rely on these

I don't believe that all browsers rely on the Google list. As mentioned earlier in this thread when the original site was blocked in Chrome, it was not blocked in Edge. Microsoft maintain their own security lists.

* * *

It seems as though you CAN turn off the safe browsing feature - at least in Safari.

There is also a process for getting your site re-classified.

> If your website has been flagged by Google as dangerous or harmful, you can request a review to have it removed from the blocklist. To do this, you will need a verified Google Search Console account. Sign in to your account and select the “Manual Actions” tab. [If Google has detected a security issue with your website, it will be listed there](https://fixmysite.com/website-blacklist-removal/)

PS: Thanks Bing! (never thought I'd be saying that! 🤣)

---

<div class="post-metadata">

**Author:** ![bakman2](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/bakman2/32/6207_2.png) [@bakman2](https://discourse.nodered.org/u/bakman2)\
**Post date:** [18 May 2023 03:52 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/18 "2023-05-18T03:52:07Z")

</div>

> [@TotallyInformation](#):
>
> There is also a process for getting your site re-classified.

The google search console will apparently [also indicate](https://support.google.com/webmasters/answer/34592) the reasons why it has been flagged as deceptive. Sounds like a [good starting point](https://search.google.com/search-console/not-verified).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 July 2023 03:52 UTC](https://discourse.nodered.org/t/deceptive-site-ahead-for-my-node-red-sites/77925/19 "2023-07-17T03:52:24Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
