Earlier quoted context omitted.
While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…
> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.
Google workspace threatening to block Firefox access
111–120 of 194 posts
Re: Google workspace threatening to block Firefox access
#112Earlier quoted context omitted.
If you run a SaaS, large parts of your orgs should be on all major browsers regularly.
I have a handful of endpoints, used by staff that represent a low level of risk, that use Firefox for that precise reason. But really, we have a couple of million enterprise end-users, some of which surely using Edge. If we as much as move a button without telling them about it three months in advance, it's the end of the world. In 10 years time, no customer has raised it.
Re: Google workspace threatening to block Firefox access
#113Earlier quoted context omitted.
> Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? Allowing users running who knows what version of Firefox (or any "non-validated"/unmanaged browser, not necessarily just Firefox) browser running who knows what extensions can be pretty unsafe. There are lots of malicious extensions out there that are stupid simple to install. In the Workspace world,…
I'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions). If you don't want your user to run whatever version with whatever extension you can do that.
This feature supposedly ensures (or at least pushes users to) only the approved browsers running approved configurations are allowed to log in to the company's instances of Workspace.
Re: Google workspace threatening to block Firefox access
#114Re: Google workspace threatening to block Firefox access
#115It is probably Chrome Enterprise which lets you lock down, for example, what extensions people are allowed to install. There is a legit reason for organizations to want to standardize on one browser and to lock it down (as browser extensions are a major source of infiltration these days).
Re: Google workspace threatening to block Firefox access
#116> https://knowledge.workspace.google.com/admin/security/contex...
In particular "Allow access to devices using Chrome browser with security requirements" would present this message.
Re: Google workspace threatening to block Firefox access
#117Earlier quoted context omitted.
Note that making lock-in features like this effectively proprietary to the Chrome browser is only possible because of the fact that it's the same company making Google Workspace and Google Chrome. I absolutely see many problems with this and you really ought to as well.
>only possible Two different companies can partner together and release features in both of the company's interests.
Meanwhile, in our current reality, both Google and Apple have or currently are shoehorning platform level attestation into the web in various different ways, something they are mostly able to do because they have so much control over multiple major ecosystems (among platforms, browsers, web services.) Mostly, even making them "standards", which would be hilarious if it wasn't literally evil. (Apple's approach to sneaking this in is innovative, in that it technically is a hardware platform attestation mechanism, but it was sold and initially implemented as a convenience feature. That and the underlying PAT technology can be used in strictly non-evil ways, like Kagi's rather clever application.)
It's a lot of words to say that I didn't mean literally impossible, but if we're going to get pedantic then a lot of words it is.
Re: Google workspace threatening to block Firefox access
#118Earlier quoted context omitted.
it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists
Using a maintained and up-to-date browser is a reasonable requirement for an IT department (should be for anyone really). Would you suggest they should be allowing IE6 just because a user might prefer it? Of course Google is going to suggest using Chrome, if they detect that the browser might be out of date.
Re: Google workspace threatening to block Firefox access
#119Earlier quoted context omitted.
Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?
Google offers "Managed Chrome" as a service. What would you like them to do, offer "Managed Firefox"? Should AWS offer "Managed GCP"?
Re: Google workspace threatening to block Firefox access
#120Earlier quoted context omitted.
it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists
While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…
People know how it ended, but don't seem to remember how it started, which is a shame.