Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

101–110 of 194 posts

Re: Google workspace threatening to block Firefox access

#101
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

> Because Google has more resources to secure their browser

They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

Re: Google workspace threatening to block Firefox access

#102
post #81

Earlier quoted context omitted.

Google offering managed chrome as a service is a completely sensible thing. The problem is that they are nearly a browser monopoly, and making Google Workspace work in such a way with Google Chrome feels to me like anti-competitive practices. If we didn't have one giant megacorp that did both things, it would be different. Of course, so far the only workable model for web browsers is having a giant megacorp fund thei…

I'm not sure what the alternative is. Is there will from Firefox to support a "standard browser config", at which point GSuite could add support for managed Firefox config? If you want managed Firefox, Mozilla could offer that as well (they have something but it's different enough).

The alternative that we've used for the past 100+ years is to force such companies apart. Is Google Docs allowed to offer a "managed chrome" policy? Sure. Is Google Chrome allowed to be a browser? Absolutely!

But if either side is close to a monopoly, both cannot be part of the same company, even if that means breaking an existing company up.

Re: Google workspace threatening to block Firefox access

#103
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

Do people get pwned by anything besides spearphishing or ads nowadays? I think ad->phish or targeted phish emails is the only shady thing I've been exposed to in like 10 years

Re: Google workspace threatening to block Firefox access

#104
post #3

It states something about "your organisation's security requirements", do they document what requirements cause this rejection page? Some kind if changed default perhaps?

No, this is easily the biggest flaw in CAA - there is no way to discover which policy broke your access. I have reported this to Google multiple times, even sent this directly to a Google SecEng (a well known one) to route internally. The issue persists and makes configuring CAA extremely painful and error prone.

I am convinced there's someone who thinks debuggable security policies are a security risk and deliberately designs security APIs to be as inscrutable as possible.

Re: Google workspace threatening to block Firefox access

#105
post #101
post #92

Earlier quoted context omitted.

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification.

I find this incredibly amusing, and at a different point in my life I'd already be gone.

When you outsource IT, there are many, many misaligned incentives.

Re: Google workspace threatening to block Firefox access

#106
post #18
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

"it shouldn’t be an option."

What? Are you serious? An organization has EVERY right to enforce whatever controls they deem appropriate for their environment. Period.

Re: Google workspace threatening to block Firefox access

#107
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

having soon-to-be-nonfunctional adblocking will be far more dangerous to org than any extra security those options might provide

Re: Google workspace threatening to block Firefox access

#108
post #75

Earlier quoted context omitted.

> It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? > It's a paid product, they are actually allowed to do this. If that were the only metric, then no monopoly would ever be broken up for any…

> Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? Allowing users running who knows what version of Firefox (or any "non-validated"/unmanaged browser, not necessarily just Firefox) browser running who knows what extensions can be pretty unsafe. There are lots of malicious extensions out there that are stupid simple to install. In the Workspace world,…

I'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions).

If you don't want your user to run whatever version with whatever extension you can do that.

Re: Google workspace threatening to block Firefox access

#109
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

> But it's not your laptop. It's the company's.

Sure, which is why you should lock down the laptop. Blocking Firefox in Google Workspace seems like entirely the wrong layer for this.

Re: Google workspace threatening to block Firefox access

#110
post #70

Earlier quoted context omitted.

I haven't dug into the native helper to see how much it checks, I can believe that ChromeOS does full remote attestation. If it's anything like Android Play Integrity, there's not a lot of flexibility without hardware exploits. But who outside of Google is running exclusively ChromeOS? My impression from looking at the JS part is that it's mostly obfuscation, with the possible exception of ChromeOS. I feel like the s…

My point was that CAA's threat model is flexible based on your requirements. If your requirement is "an attacker with the ability to make arbitrary network requests from the host can not pretend to be Chrome", CAA does not work unless you have OS/Hardware support (which ChromeOS provides). I just don't think that matters much. CAA is policy enforcement, it is not a full MDM solution, nor is it antimalware.

If it can't prove what it purports to prove, then it is not policy enforcement, because it is not anything enforcement.

But someone thinks it is, which is harmful to them on top of being an annoyance to everyone else.

Post reply on HN