Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

31–40 of 194 posts

Re: Google workspace threatening to block Firefox access

#32
post #27

Earlier quoted context omitted.

Using a maintained and up-to-date browser is a reasonable requirement for an IT department (should be for anyone really). Would you suggest they should be allowing IE6 just because a user might prefer it? Of course Google is going to suggest using Chrome, if they detect that the browser might be out of date.

Is the implication that Firefox is not maintained or? The issue presented doesn’t seem to be “an up to date browser check” it seems to be a “is it latest chrome” check, which is a very different thing.

We don't know. The author doesn't mention how current the Firefox browser is/was.

If the organization is indeed enabling a specific check for Chrome that seems a little over the top but they're the ones supporting their users and if they want to make their life easier by only dealing with one browser that's their decision to make. It's like saying that everyone has to use Windows, or a specific line of laptops, or any other standardization to simplify the support workload.

Re: Google workspace threatening to block Firefox access

#33
post #27

Earlier quoted context omitted.

Is the implication that Firefox is not maintained or? The issue presented doesn’t seem to be “an up to date browser check” it seems to be a “is it latest chrome” check, which is a very different thing.

We don't know. The author doesn't mention how current the Firefox browser is/was. If the organization is indeed enabling a specific check for Chrome that seems a little over the top but they're the ones supporting their users and if they want to make their life easier by only dealing with one browser that's their decision to make. It's like saying that everyone has to use Windows, or a specific line of laptops, or an…

It's not clear to me that Context-Aware Access is as configurable as you're implying. At a glance, the docs seem to suggest that Chrome is the only browser you can force standardization on, which IMO does push this towards being Google's fault.

Re: Google workspace threatening to block Firefox access

#34

Seems like a monopolistic move.

Google doesn’t have a monopoly in workspace applications.

I doubt Microsoft would qualify as a monopoly under present-day excuses being made for Google yet here we are with Internet Explorer Part Deux.

Re: Google workspace threatening to block Firefox access

#35
Sounds like you have a device policy configured and you should talk to your internal IT/Security team?

edit: This title is just incredibly misleading. OP seems to have made a mistake here in thinking that this is something that Google has done when it's just that their corporate IT/ Sec team now enforces using Chrome.

Re: Google workspace threatening to block Firefox access

#36
post #9

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?

[deleted]

Re: Google workspace threatening to block Firefox access

#37
post #3

It states something about "your organisation's security requirements", do they document what requirements cause this rejection page? Some kind if changed default perhaps?

No, this is easily the biggest flaw in CAA - there is no way to discover which policy broke your access. I have reported this to Google multiple times, even sent this directly to a Google SecEng (a well known one) to route internally. The issue persists and makes configuring CAA extremely painful and error prone.

Re: Google workspace threatening to block Firefox access

#38
post #18
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

CAA is one of the most powerful security features you can enable in an org. You can manage browser extensions, device password policy, encryption, configuration, cookie attestation, etc.

Re: Google workspace threatening to block Firefox access

#39
post #9

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?

Google offers "Managed Chrome" as a service. What would you like them to do, offer "Managed Firefox"? Should AWS offer "Managed GCP"?

Re: Google workspace threatening to block Firefox access

#40
post #9

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?

Because Google is able to configure Chrome to the admin's liking.
Post reply on HN