Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

191–194 of 194 posts

Re: Google workspace threatening to block Firefox access

#191
post #177
post #147

Earlier quoted context omitted.

> 99% of security experts I know use ad blockers. But if they all use Chrome, wouldn't those be really weak ad blockers?

This is a common myth. I've used uBlock Origin Lite for months (a year?) and still see zero ads. I'm extremely intolerant to ads, so I would leave Chrome if ad blocking stopped working.

Adblocking is an arms race. Google is handicapping adblocking progressively the fact that it doesn't take one day to achieve absolutely doesn't make it a myth. Adblocking is technically worse and the more locked down our environments are the easier it will be to kill or drastically reduce it.

If everyone had the same attitude this would probably already be the case.

Re: Google workspace threatening to block Firefox access

#192
post #18
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

Why?

We do conditional access at the Azure level, and a device that doesn't meet some compliance policies on their machine (Windows, macOS, Linux) is unable to access their corporate account until they remediate that.

Re: Google workspace threatening to block Firefox access

#193
post #148

Earlier quoted context omitted.

This is the correct answer. Having your users run multiple browsers by default (instead of with whitelisted exceptions) is now multiple attack surfaces the org has to manage.

Very curious how you avoid supporting multiple browsers. Apple, Google, and Microsoft each require users on their platforms to use their native browsers for secure connections. And if your company has any web presence or apps, you usually can't cherry pick which browsers your customers can use. That means some portion of your company will need access to other browsers for QA purposes.

At the minimum I might say you only allow Chrome to access Google Workspace/SSO, which is needed to access like 95% of company resources. This is, in fact, the topic of the OP.

You can do additional device management to lock down the rest of the machine. You can force Chrome and restrict Safari/Firefox/etc on Mac just fine. Same for Windows.

Re: Google workspace threatening to block Firefox access

#194

Earlier quoted context omitted.

They didn’t take a decade plus to implement per-domain process isolation, for starters…

You can downvote the truth, but can’t reply to it. Typical modern Mozilla fans, really.

Typical Hacker News posters.
Post reply on HN