Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

181–190 of 194 posts

Re: Google workspace threatening to block Firefox access

#181

Earlier quoted context omitted.

No, this is easily the biggest flaw in CAA - there is no way to discover which policy broke your access. I have reported this to Google multiple times, even sent this directly to a Google SecEng (a well known one) to route internally. The issue persists and makes configuring CAA extremely painful and error prone.

I am convinced there's someone who thinks debuggable security policies are a security risk and deliberately designs security APIs to be as inscrutable as possible.

It's possible but I suspect it's just Google being a rather incompetent organization.

Re: Google workspace threatening to block Firefox access

#182
post #102

Earlier quoted context omitted.

The alternative that we've used for the past 100+ years is to force such companies apart. Is Google Docs allowed to offer a "managed chrome" policy? Sure. Is Google Chrome allowed to be a browser? Absolutely! But if either side is close to a monopoly, both cannot be part of the same company, even if that means breaking an existing company up.

I think it's fine to advocate that Google should be split up but I don't think that CAA is a good example of a company abusing power.

There's really nothing particularly wrong with the Chrome feature itself. There is a bit of a problem with the way it inherently results in browser vendor lock-in (regardless of whether it is a stated goal) with Google Workspace, which is by the same company. That's the main problem.

I may be missing something because I feel like this specific point has been reiterated a few times in this thread but I haven't seen it actually rebuked directly.

Re: Google workspace threatening to block Firefox access

#183
post #121

Earlier quoted context omitted.

> I find this incredibly amusing, and at a different point in my life I'd already be gone. How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.

99% of security experts I know use ad blockers. When there are unpatched browser vulnerabilities, attackers will use ad networks to inject attack code into reputable-but-ad-laden websites. And even when there aren't unpatched vulnerabilities out there, many ad networks will happily accept scam ads, ads that trick people into downloading malware, fake download buttons and suchlike.

> 99% of security experts I know use ad blockers.

100% of security experts I know find ads annoying and know ad blockers reduce how many they see.

Re: Google workspace threatening to block Firefox access

#184
post #182

Earlier quoted context omitted.

I think it's fine to advocate that Google should be split up but I don't think that CAA is a good example of a company abusing power.

There's really nothing particularly wrong with the Chrome feature itself. There is a bit of a problem with the way it inherently results in browser vendor lock-in (regardless of whether it is a stated goal) with Google Workspace, which is by the same company. That's the main problem. I may be missing something because I feel like this specific point has been reiterated a few times in this thread but I haven't seen it…

There is no Chrome feature here? We must be talking past each other, yes.

Re: Google workspace threatening to block Firefox access

#185
post #182

Earlier quoted context omitted.

There's really nothing particularly wrong with the Chrome feature itself. There is a bit of a problem with the way it inherently results in browser vendor lock-in (regardless of whether it is a stated goal) with Google Workspace, which is by the same company. That's the main problem. I may be missing something because I feel like this specific point has been reiterated a few times in this thread but I haven't seen it…

There is no Chrome feature here? We must be talking past each other, yes.

The Chrome feature is the support for Endpoint Verification that is used by CAA. That is quite literally the reason for this HN post.

Re: Google workspace threatening to block Firefox access

#186
post #185

Earlier quoted context omitted.

There is no Chrome feature here? We must be talking past each other, yes.

The Chrome feature is the support for Endpoint Verification that is used by CAA. That is quite literally the reason for this HN post.

Endpoint Verification is not a Chrome feature, nor is CAA. Endpoint Verification is an extension, CAA is a GSuite feature.

Re: Google workspace threatening to block Firefox access

#187
post #185

Earlier quoted context omitted.

The Chrome feature is the support for Endpoint Verification that is used by CAA. That is quite literally the reason for this HN post.

Endpoint Verification is not a Chrome feature, nor is CAA. Endpoint Verification is an extension, CAA is a GSuite feature.

Look man, this is absolutely getting into the semantics phase. I know you're not stupid, don't treat me like I am.

Firstly, some Chrome features (like Chrome Remote Desktop) are delivered partly as extensions. This does not make them not features of Chrome. It makes them features that happen to be delivered in some part as extensions.

Doesn't matter. Let's say Endpoint Verification is not a Chrome feature. Thankfully, we don't actually need that for our argument. The crux of this argument is simple:

- Google Workspace depends on proprietary Chrome features,

- Chrome has specific proprietary features designed to support Google Workspace (and other proprietary Google offerings.)

What is the proprietary features I am referring to? Well, I'd just say "Endpoint Verification", but we can go a layer deeper. In order to implement Endpoint Verification, we need privileged, private extension APIs. These APIs are not for use with non-Google extensions, and Endpoint Verification uses enterprise.reportingPrivate.

You can disagree that it is a problem that Google Chrome and Google Workspace are developing proprietary integrations with each-other, that's your prerogative, but I'm not humoring this gaslighting attempt.

Re: Google workspace threatening to block Firefox access

#188
post #108

Earlier quoted context omitted.

I'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions). If you don't want your user to run whatever version with whatever extension you can do that.

Sure. But there's generally no standardized function ensuring they're actually only using that specifically configured browser when logging in. What happens when they try to log in from some other device? What happens when they manage to load a browser on to that machine? This feature supposedly ensures (or at least pushes users to) only the approved browsers running approved configurations are allowed to log in to t…

Does it?

What if a company decides that their preferred browser is Firefox. Can you use this feature to only enable logins from Firefox? Or is it only for Chrome?

Re: Google workspace threatening to block Firefox access

#189
post #187

Earlier quoted context omitted.

Endpoint Verification is not a Chrome feature, nor is CAA. Endpoint Verification is an extension, CAA is a GSuite feature.

Look man, this is absolutely getting into the semantics phase. I know you're not stupid, don't treat me like I am. Firstly, some Chrome features (like Chrome Remote Desktop) are delivered partly as extensions. This does not make them not features of Chrome. It makes them features that happen to be delivered in some part as extensions. Doesn't matter. Let's say Endpoint Verification is not a Chrome feature. Thankfully…

I'm not trying to treat you like you're stupid or to gaslight you. There is a "slice" of this that is absolutely a native, Chrome-only interface, but I just don't think that this is particularly exceptional. These sorts of Firefox-only APIs exist as well in order to support Mozilla's goals, and this is quite normal - you wouldn't expect every single aspect of the browser to be built in lockstep with every other browser.

For the most part, Mozilla could build out Endpoint Verification (and it supports a subset of the APIs anyways). Similarly, there could be a web proposal for device attestation APIs that are more generalized, etc, which I think would be great.

Re: Google workspace threatening to block Firefox access

#190
post #188

Earlier quoted context omitted.

Sure. But there's generally no standardized function ensuring they're actually only using that specifically configured browser when logging in. What happens when they try to log in from some other device? What happens when they manage to load a browser on to that machine? This feature supposedly ensures (or at least pushes users to) only the approved browsers running approved configurations are allowed to log in to t…

Does it? What if a company decides that their preferred browser is Firefox. Can you use this feature to only enable logins from Firefox? Or is it only for Chrome?

They can't use this feature to enforce only Firefox. Firefox doesn't have support for this feature, they really don't offer anything like Chrome Enterprise. Its just as much a feature of Chrome Enterprise that Workspace leverages rather than only a feature of Workspace that leverages Chrome.

You can still use Firefox with Workspace though, but if you want the management features of Chrome Enterprise you need to use Chrome Enterprise. Firefox itself just doesn't even begin to offer the same kind of endpoint verification.

With Firefox today, how would a web app have any serious clue the client was running approved versions of Firefox configured in approved ways on approved hardware with approved OS configurations? It wouldn't, and I take it Firefox wouldn't bother implementing that kind of technology. Which is fine, but if the customer wants to be able to ensure a certain kind of policy compliance that's just not possible when using Firefox. And that's just as much if not more of the ball being in Firefox's court as it is Google Workspace's. There's nothing for Workspace to even interface with at all from the Firefox side to ensure policy compliance.

Its like asking "can I print on this printer with this app?" when the app itself doesn't even have a concept of printing things. The basic underlying feature set just doesn't even exist, before we're even talking about some form of platform compatibility.

Post reply on HN