Live data from Hacker News

Ask HN: Is your Firefox blocked by Cloudflare in recent weeks? (e.g., Gitlab)

news.ycombinator.com

11–20 of 37 posts

Re: Ask HN: Is your Firefox blocked by Cloudflare in recent weeks? (e.g., Gitlab)

#11
I don't use GitLab but I do use Firefox for almost all my home and work browsing[1] and haven't had this problem with other sites which use cloudflare. I do use both ublock origin and advanced tracking protection always so I'm going to say the problem is with some configuration gitlab is doing rather than with cloudflare.

[1] Exceptions being mobile, if I am specifically testing something and certain work situations where I am currently testing a locked-down web browser called "island"[2] which seems to be a chrome fork which gives Enterprise IT control over a bunch of stuff.

[2] https://www.island.io/

Re: Ask HN: Is your Firefox blocked by Cloudflare in recent weeks? (e.g., Gitlab)

#14

I don't use GitLab but I do use Firefox for almost all my home and work browsing[1] and haven't had this problem with other sites which use cloudflare. I do use both ublock origin and advanced tracking protection always so I'm going to say the problem is with some configuration gitlab is doing rather than with cloudflare. [1] Exceptions being mobile, if I am specifically testing something and certain work situations…

Sorry for going off topic, but what exactly is an "Enterprise Browser"? Does it limit what sites can be accessed, what extensions can be installed if any, and what features are available to used by the websites?

I guess it will provide capabilities to add AD's group policy object like mechanisms to the browser.

Re: Ask HN: Is your Firefox blocked by Cloudflare in recent weeks? (e.g., Gitlab)

#17
post #14

I don't use GitLab but I do use Firefox for almost all my home and work browsing[1] and haven't had this problem with other sites which use cloudflare. I do use both ublock origin and advanced tracking protection always so I'm going to say the problem is with some configuration gitlab is doing rather than with cloudflare. [1] Exceptions being mobile, if I am specifically testing something and certain work situations…

Sorry for going off topic, but what exactly is an "Enterprise Browser"? Does it limit what sites can be accessed, what extensions can be installed if any, and what features are available to used by the websites? I guess it will provide capabilities to add AD's group policy object like mechanisms to the browser.

Yes. I think in this particular case it gives a central infosec team the ability to allow/deny certain sites, set proxy and other network settings, control which extensions are allowed and do a few other similar things. The point in this scenario is to ensure that where Saas and similar things are used in particularly sensitive applications (think: logging in to a bank portal for a corporate treasury account for instance) the browser environment is tightly controlled and a well-intentioned employee can't accidentally compromise things by using a browser that includes a malicious extension or similar.

I don't think the threat model is it's expected to prevent intentional attacks by a hostile, skilled, priviledged insider put it that way.

I'm not recommending it or anything but so far the browser doesn't seem terrible. It seems to work just like chrome, and I haven't had any problems or noticeable examples of it stopping me from doing anything fwvliw. I'm not trying to circumvent anything or do anything that I'm not actually expected to do as part of my work though so I wouldn't expect problems.

Re: Ask HN: Is your Firefox blocked by Cloudflare in recent weeks? (e.g., Gitlab)

#19
post #14

Earlier quoted context omitted.

Sorry for going off topic, but what exactly is an "Enterprise Browser"? Does it limit what sites can be accessed, what extensions can be installed if any, and what features are available to used by the websites? I guess it will provide capabilities to add AD's group policy object like mechanisms to the browser.

Yes. I think in this particular case it gives a central infosec team the ability to allow/deny certain sites, set proxy and other network settings, control which extensions are allowed and do a few other similar things. The point in this scenario is to ensure that where Saas and similar things are used in particularly sensitive applications (think: logging in to a bank portal for a corporate treasury account for inst…

that makes sense, thanks for elaborating
Post reply on HN