Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

121–130 of 194 posts

Re: Google workspace threatening to block Firefox access

#121
post #105
post #101

Earlier quoted context omitted.

> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification. I find this incredibly amusing, and at a different point in my life I'd already be gone. When you outsource IT, there are many, many misaligned incentives.

> I find this incredibly amusing, and at a different point in my life I'd already be gone.

How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.

Re: Google workspace threatening to block Firefox access

#122
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

Hi there, original author here. Can confirm we're not using IAP for this workspace, or anything I was trying to access

Re: Google workspace threatening to block Firefox access

#123

Earlier quoted context omitted.

Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?

Google offers "Managed Chrome" as a service. What would you like them to do, offer "Managed Firefox"? Should AWS offer "Managed GCP"?

Google offering "Managed Chrome" is probably the root issue.

Call me old school, but wedging an already dominant browser to be the only full fledge option in GSuite using companies reeks anti-competition.

Re: Google workspace threatening to block Firefox access

#124
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

Google has the resources to do it, but do they actually do it? By the looks of it I'd say "no".

See the whole thing with libxml2 for example, or how they started boringssl to "fix" the issues with openssl, but they run it as an internal project you cannot depend on.

Re: Google workspace threatening to block Firefox access

#125
Hi folks, blog author here.

Few comments based on common threads

- No we don't have, or use, IAP and haven't configured it

- Yes I'm the admin so can confirm this

- "Context aware access" is only available on enterprise, we're just on "Workspace business plus"

Happy to answer any other questions

Re: Google workspace threatening to block Firefox access

#126
post #9

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

> The Org admin can put all sorts of restrictions on who can do what based on the client device setup. can you put a restriction to ban Chrome and force Firefox then?

If you wanted to, yes.

Re: Google workspace threatening to block Firefox access

#127
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's.

But it is my craft, and to be limited to what tools I can use in my craft can decrease the value of my work, and in doing so decrease the company's productivity.

Re: Google workspace threatening to block Firefox access

#128
post #117

Earlier quoted context omitted.

>only possible Two different companies can partner together and release features in both of the company's interests.

I didn't mean it would be physically impossible, which is hopefully implied, I mean, it would be de-facto impossible. Absent the perverse forces of anticompetitive behavior, browsers don't really have a good incentive to diminish the open nature of web standards by doing partnerships that bypass standards altogether. If you are not affiliated with Google and there is a healthy ecosystem of browsers, you just simply c…

>browsers don't really have a good incentive

Why wouldn't money be an incentive. If businesses are willing to pay to have locked down browser access their cloud files, and the cloud file website wants to make money by charging businesses for this feature it makes sense that they may pay a browser to develop such a feature to use with their website.

Re: Google workspace threatening to block Firefox access

#129
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

Hi there, original author here. Can confirm we're not using IAP for this workspace, or anything I was trying to access

Psst, you have a merge conflict in your text

Re: Google workspace threatening to block Firefox access

#130
post #8

It appears website developers desperately want to return to a world where browsers actively pretend to be another browser*. Want to check for DBSC? Enjoy not knowing whether the browser vendor decided to just roll a simple software implementation. Nothing good comes from browser detection over feature detection anyways. It's time to do away with user-agents and other overt identifying markers, and if we're still not…

Cloudflare blocked me with a chrome windows useragent on Firefox+Fedora
Post reply on HN