Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

111–120 of 194 posts

Re: Google workspace threatening to block Firefox access

#111
post #101
post #92

Earlier quoted context omitted.

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

They didn’t take a decade plus to implement per-domain process isolation, for starters…

Re: Google workspace threatening to block Firefox access

#112
post #100

Earlier quoted context omitted.

If you run a SaaS, large parts of your orgs should be on all major browsers regularly.

I have a handful of endpoints, used by staff that represent a low level of risk, that use Firefox for that precise reason. But really, we have a couple of million enterprise end-users, some of which surely using Edge. If we as much as move a button without telling them about it three months in advance, it's the end of the world. In 10 years time, no customer has raised it.

Edge: Chromium with Google Chrome-like data collection, but with data going to Microsoft instead.

Re: Google workspace threatening to block Firefox access

#113
post #108

Earlier quoted context omitted.

> Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? Allowing users running who knows what version of Firefox (or any "non-validated"/unmanaged browser, not necessarily just Firefox) browser running who knows what extensions can be pretty unsafe. There are lots of malicious extensions out there that are stupid simple to install. In the Workspace world,…

I'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions). If you don't want your user to run whatever version with whatever extension you can do that.

Sure. But there's generally no standardized function ensuring they're actually only using that specifically configured browser when logging in. What happens when they try to log in from some other device? What happens when they manage to load a browser on to that machine?

This feature supposedly ensures (or at least pushes users to) only the approved browsers running approved configurations are allowed to log in to the company's instances of Workspace.

Re: Google workspace threatening to block Firefox access

#114
It is probably Chrome Enterprise which lets you lock down, for example, what extensions people are allowed to install. There is a legit reason for organizations to want to standardize on one browser and to lock it down (as browser extensions are a major source of infiltration these days).

Re: Google workspace threatening to block Firefox access

#115

It is probably Chrome Enterprise which lets you lock down, for example, what extensions people are allowed to install. There is a legit reason for organizations to want to standardize on one browser and to lock it down (as browser extensions are a major source of infiltration these days).

Firefox supports locking down like that as well so that sounds like lazy IT.

Re: Google workspace threatening to block Firefox access

#117
post #60

Earlier quoted context omitted.

Note that making lock-in features like this effectively proprietary to the Chrome browser is only possible because of the fact that it's the same company making Google Workspace and Google Chrome. I absolutely see many problems with this and you really ought to as well.

>only possible Two different companies can partner together and release features in both of the company's interests.

I didn't mean it would be physically impossible, which is hopefully implied, I mean, it would be de-facto impossible. Absent the perverse forces of anticompetitive behavior, browsers don't really have a good incentive to diminish the open nature of web standards by doing partnerships that bypass standards altogether. If you are not affiliated with Google and there is a healthy ecosystem of browsers, you just simply can tell them to bug off if they want some web feature you feel wouldn't be good for the health of the web. The interaction between browser vendors and certificate authorities has traditionally been a great example of how things can work out between different entities in an ecosystem, though outside Mozilla I am guessing most of the browser vendors are also CAs (but still have very little to no incentive to compromise or weaken the system.)

Meanwhile, in our current reality, both Google and Apple have or currently are shoehorning platform level attestation into the web in various different ways, something they are mostly able to do because they have so much control over multiple major ecosystems (among platforms, browsers, web services.) Mostly, even making them "standards", which would be hilarious if it wasn't literally evil. (Apple's approach to sneaking this in is innovative, in that it technically is a hardware platform attestation mechanism, but it was sold and initially implemented as a convenience feature. That and the underlying PAT technology can be used in strictly non-evil ways, like Kagi's rather clever application.)

It's a lot of words to say that I didn't mean literally impossible, but if we're going to get pedantic then a lot of words it is.

Re: Google workspace threatening to block Firefox access

#118
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

Using a maintained and up-to-date browser is a reasonable requirement for an IT department (should be for anyone really). Would you suggest they should be allowing IE6 just because a user might prefer it? Of course Google is going to suggest using Chrome, if they detect that the browser might be out of date.

If that's a the goal, then IT department should start by blocking user ability to install Firefox or other unapproved software not by blocking access to google workspace. Blocking access to google workspace using Firefox doesn't prevent using it for everything else. It's not like the google services are going to exploit a vulnerability in Firefox, everything else might.

Re: Google workspace threatening to block Firefox access

#119

Earlier quoted context omitted.

Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?

Google offers "Managed Chrome" as a service. What would you like them to do, offer "Managed Firefox"? Should AWS offer "Managed GCP"?

Organization admins may roll out hardened Firefox settings via their MDM solution, and then based on that want to restrict usage to Firefox.

Re: Google workspace threatening to block Firefox access

#120
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

This feels like the whole IE6 dance coming back.

People know how it ended, but don't seem to remember how it started, which is a shame.

Post reply on HN