Google workspace threatening to block Firefox access
141–150 of 194 posts
Re: Google workspace threatening to block Firefox access
#142Earlier quoted context omitted.
You don’t have to use managed chrome to use gsuite
I mean the issue here is Google using its dominant power to push for a specific browser within a security software they control. This is a difference between America and Europe in mentality towards this.
Re: Google workspace threatening to block Firefox access
#143Earlier quoted context omitted.
It is a security feature. In a corporate environment, you generally don't want users installing their own software. If it's a remote access thing from a personal device, you still generally want to be able to establish some kind of baseline. I don't like Chrome - not even a little bit - but I will admit that they have a pretty damn good security track record. I'd rather my remote users be on there than some crusty Fi…
Literally the only reason they can argue Chrome is more secure than Firefox in that kind of setting is because they can Google can push Google Chrome profiles via Google Workspaces but they’ve never working with Mozilla to create an interop for Firefox. When Microsoft did this with Windows, AD, and Internet Explore, it was deemed a breach of anti-trust laws. The question is whether such laws apply to Google given the…
Almost nobody outside of the minority of internet users fighting against chromium hegemony cares about Firefox. Firefox lost its casual users years ago. Hell, even most of those people sticking with it out of principle are doing it while gritting their teeth. It's been a subpar browser for a long time and the Mozilla organization kinda sucks.
Why would any for-profit enterprise waste their time or money on Firefox?
Re: Google workspace threatening to block Firefox access
#144Re: Google workspace threatening to block Firefox access
#145Re: Google workspace threatening to block Firefox access
#146Earlier quoted context omitted.
> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.
My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification. I find this incredibly amusing, and at a different point in my life I'd already be gone. When you outsource IT, there are many, many misaligned incentives.
Same here, but only on Chrome. Firefox works fine.
Re: Google workspace threatening to block Firefox access
#147Earlier quoted context omitted.
> I find this incredibly amusing, and at a different point in my life I'd already be gone. How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.
99% of security experts I know use ad blockers. When there are unpatched browser vulnerabilities, attackers will use ad networks to inject attack code into reputable-but-ad-laden websites. And even when there aren't unpatched vulnerabilities out there, many ad networks will happily accept scam ads, ads that trick people into downloading malware, fake download buttons and suchlike.
But if they all use Chrome, wouldn't those be really weak ad blockers?
Re: Google workspace threatening to block Firefox access
#148Earlier quoted context omitted.
While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…
This is the correct answer. Having your users run multiple browsers by default (instead of with whitelisted exceptions) is now multiple attack surfaces the org has to manage.
And if your company has any web presence or apps, you usually can't cherry pick which browsers your customers can use. That means some portion of your company will need access to other browsers for QA purposes.
Re: Google workspace threatening to block Firefox access
#149Earlier quoted context omitted.
Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?
Google offers "Managed Chrome" as a service. What would you like them to do, offer "Managed Firefox"? Should AWS offer "Managed GCP"?
Re: Google workspace threatening to block Firefox access
#150Earlier quoted context omitted.
> Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? Allowing users running who knows what version of Firefox (or any "non-validated"/unmanaged browser, not necessarily just Firefox) browser running who knows what extensions can be pretty unsafe. There are lots of malicious extensions out there that are stupid simple to install. In the Workspace world,…
I'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions). If you don't want your user to run whatever version with whatever extension you can do that.
But how many companies are running Workspace + Windows with on-prem AD? I suspect that number is shrinking pretty rapidly. You can do it with InTune as well, but it starts to get real messy if your users aren't on Windows or you have non-windows endpoints.
If you're a mac shop, on google workspace, and using something like JamF (or even Intune+EntraID), you are stuck deploying .plist files to each endpoint, you don't get compliance reporting back, and you lose a ton of visibility.
These are all things that don't matter to each individual user, but are hugely important to IT/security in the company, and Firefox unfortunately just doesn't have any centralized management platform for it.