Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

171–180 of 194 posts

Re: Google workspace threatening to block Firefox access

#171
post #121
post #105

Earlier quoted context omitted.

My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification. I find this incredibly amusing, and at a different point in my life I'd already be gone. When you outsource IT, there are many, many misaligned incentives.

> I find this incredibly amusing, and at a different point in my life I'd already be gone. How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.

[deleted]

Re: Google workspace threatening to block Firefox access

#172

Earlier quoted context omitted.

Let's say you earn a million dollars a year (most of us earn far less). At quite a few companies, a 50% decrease in your productivity (and changing browsers is nowhere near that) would cost the company significantly less than dealing with the fallout of any of the following: * A user intentionally leaking sensitive documents outside the corporate network * A user installing an infected browser extension that gives at…

All of what you listed is preventable at a mild labor cost to the same degree as other browsers.

That's not obvious at all. The feature sets and tooling are very different. The person you replied to said as much.

You (and I) aren't that special. People who are actually irreplaceable are astonishingly rare, and unless you're one of them, employees who will gripe about things like what web browser they use are often not worth the trouble at scale.

Re: Google workspace threatening to block Firefox access

#173

Earlier quoted context omitted.

I would actually be pretty concerned if Taco Bell bought Ford and would only allow Ford cars to use their drive-through or parking lot. Imagine a world where 95% of grocery stores insist on you driving a Ford car.

What if it was they bought a car brand and added a transponder to the car so owners of taco bell cars could be auto-identified and had their favorite orders already ordered for them while all other models of cars were still free to use the normal drive through process? Would that be a "monopoly" somehow? Isn't that more of what's going on here? An optional feature people can use if they choose to use the holistic pla…

Sorry, how is "blocking Firefox" not forcing people to choose Chrome?

I suppose you can argue the admin is doing it and Google is merely facilitating it, but the article title is "block Firefox access"

Re: Google workspace threatening to block Firefox access

#174

Earlier quoted context omitted.

What if it was they bought a car brand and added a transponder to the car so owners of taco bell cars could be auto-identified and had their favorite orders already ordered for them while all other models of cars were still free to use the normal drive through process? Would that be a "monopoly" somehow? Isn't that more of what's going on here? An optional feature people can use if they choose to use the holistic pla…

Sorry, how is "blocking Firefox" not forcing people to choose Chrome? I suppose you can argue the admin is doing it and Google is merely facilitating it, but the article title is "block Firefox access"

> the article title is

The article isn't accurate. One could say they're uninformed, one could say maybe they're ignorant, but it's not reality.

This is a security feature a Workspace customer can choose to enable or not. If the workspace customer wants to use Firefox they're free to not enable this security feature that isn't supported by Firefox.

It's not a requirement at all to use Workspace, it's an optional feature. You can still use Firefox or any other browser for that matter with Workspace, if the manager of that Workspace wants you to. Which it's the company's software suite, they should be able to configure it how they wish shouldn't they?

If Google actually started banning all non-Chrome browsers maybe I'd agree that's harmful to the browser market. It was a bad thing when they blocked Windows Phone from accessing Google services back in the day, for example.

Re: Google workspace threatening to block Firefox access

#175
post #101

Earlier quoted context omitted.

> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

They didn’t take a decade plus to implement per-domain process isolation, for starters…

You can downvote the truth, but can’t reply to it.

Typical modern Mozilla fans, really.

Re: Google workspace threatening to block Firefox access

#176

Earlier quoted context omitted.

My point was that CAA's threat model is flexible based on your requirements. If your requirement is "an attacker with the ability to make arbitrary network requests from the host can not pretend to be Chrome", CAA does not work unless you have OS/Hardware support (which ChromeOS provides). I just don't think that matters much. CAA is policy enforcement, it is not a full MDM solution, nor is it antimalware.

If it can't prove what it purports to prove, then it is not policy enforcement, because it is not anything enforcement. But someone thinks it is, which is harmful to them on top of being an annoyance to everyone else.

That's just a misunderstanding of the threat model. It's like saying "if someone can just mitm TLS it's pointless" when that "someone" is in the position to run arbitrary code on the client. Mitigations map to specific attacker positions.

Re: Google workspace threatening to block Firefox access

#177
post #147

Earlier quoted context omitted.

99% of security experts I know use ad blockers. When there are unpatched browser vulnerabilities, attackers will use ad networks to inject attack code into reputable-but-ad-laden websites. And even when there aren't unpatched vulnerabilities out there, many ad networks will happily accept scam ads, ads that trick people into downloading malware, fake download buttons and suchlike.

> 99% of security experts I know use ad blockers. But if they all use Chrome, wouldn't those be really weak ad blockers?

This is a common myth. I've used uBlock Origin Lite for months (a year?) and still see zero ads.

I'm extremely intolerant to ads, so I would leave Chrome if ad blocking stopped working.

Re: Google workspace threatening to block Firefox access

#178
post #101
post #92

Earlier quoted context omitted.

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

> Because Google has more resources to secure their browser They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

Extensions are a much greater security risk than ads.

Re: Google workspace threatening to block Firefox access

#179

Earlier quoted context omitted.

All of what you listed is preventable at a mild labor cost to the same degree as other browsers.

That's not obvious at all. The feature sets and tooling are very different. The person you replied to said as much. You (and I) aren't that special. People who are actually irreplaceable are astonishingly rare, and unless you're one of them, employees who will gripe about things like what web browser they use are often not worth the trouble at scale.

employees who will gripe about things like what web browser they use are often not worth the trouble at scale.

Firms who enforce homogeneity through policy are not worth the trouble at scale.

Re: Google workspace threatening to block Firefox access

#180
post #102

Earlier quoted context omitted.

I'm not sure what the alternative is. Is there will from Firefox to support a "standard browser config", at which point GSuite could add support for managed Firefox config? If you want managed Firefox, Mozilla could offer that as well (they have something but it's different enough).

The alternative that we've used for the past 100+ years is to force such companies apart. Is Google Docs allowed to offer a "managed chrome" policy? Sure. Is Google Chrome allowed to be a browser? Absolutely! But if either side is close to a monopoly, both cannot be part of the same company, even if that means breaking an existing company up.

I think it's fine to advocate that Google should be split up but I don't think that CAA is a good example of a company abusing power.
Post reply on HN