Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

71–80 of 194 posts

Re: Google workspace threatening to block Firefox access

#71

Earlier quoted context omitted.

We don't know. The author doesn't mention how current the Firefox browser is/was. If the organization is indeed enabling a specific check for Chrome that seems a little over the top but they're the ones supporting their users and if they want to make their life easier by only dealing with one browser that's their decision to make. It's like saying that everyone has to use Windows, or a specific line of laptops, or an…

It's not clear to me that Context-Aware Access is as configurable as you're implying. At a glance, the docs seem to suggest that Chrome is the only browser you can force standardization on, which IMO does push this towards being Google's fault.

That's correct, there is no way to say "only allow Firefox" in CAA because the attestations are either browser agnostic or chrome specific (as part of the managed Chrome offering that GSuite supports).

Re: Google workspace threatening to block Firefox access

#72

Earlier quoted context omitted.

That's not entirely true. For example, on ChromeOS CAA is hardware backed. But obviously CAA is not intended to be our entire MDM solution, an attacker in a position to spoof your entire browser can bypass some of the policies on some operating systems. Similarly, attackers in that same position can bypass TLS. An attacker who owns the kernel can bypass much of your MDM. An attacker who owns the hardware can bypass j…

Understand that, in this conversation, your use of "attacker" is referring to "end user of the hardware". Which might be part of the Chrome team's definition, or might not, but gosh it would be nice to cater to the folks who are using the dang computer.

We're talking about a device managed by a corporation. I have no idea what your point is.

Re: Google workspace threatening to block Firefox access

#73

Earlier quoted context omitted.

The problem is Google appears to label this as a security feature. I'm fine with the feature existing, but it should say something like "require Chrome" or "block Firefox" not "require a secure browser (wink wink we actually mean Chrome)"

The wording here is bad, but basically CAA supports non browser specific policy and, in some cases, browser specific policy (GSuite offers a "Managed Chrome" policy). Firefox users can leverage much of the non browser specific policy, they obviously can not be a part of the "Managed Chrome" offering.

There's no contradiction here; it's totally possible for a company to make a feature configurable so that it doesn't block their competitors but also intentionally design and market it in a way that's misleading in ways that will lead to their competitors getting blocked. When we're talking about a company as large as Google and a product with as much market share as Chrome, I don't think it's that crazy to think that things like this add up to encouraging even more hegemony, and when that happens to align perfectly with the incentives of the company making said product decisions, I also don't think it's crazy to think it's unlikely to be a coincidence.

Re: Google workspace threatening to block Firefox access

#74
post #70

Earlier quoted context omitted.

That's not entirely true. For example, on ChromeOS CAA is hardware backed. But obviously CAA is not intended to be our entire MDM solution, an attacker in a position to spoof your entire browser can bypass some of the policies on some operating systems. Similarly, attackers in that same position can bypass TLS. An attacker who owns the kernel can bypass much of your MDM. An attacker who owns the hardware can bypass j…

I haven't dug into the native helper to see how much it checks, I can believe that ChromeOS does full remote attestation. If it's anything like Android Play Integrity, there's not a lot of flexibility without hardware exploits. But who outside of Google is running exclusively ChromeOS? My impression from looking at the JS part is that it's mostly obfuscation, with the possible exception of ChromeOS. I feel like the s…

My point was that CAA's threat model is flexible based on your requirements. If your requirement is "an attacker with the ability to make arbitrary network requests from the host can not pretend to be Chrome", CAA does not work unless you have OS/Hardware support (which ChromeOS provides).

I just don't think that matters much. CAA is policy enforcement, it is not a full MDM solution, nor is it antimalware.

Re: Google workspace threatening to block Firefox access

#75
post #64
post #46

Earlier quoted context omitted.

Google and Microsoft shouldn’t be giving levers that bake you more into their ecosystem regardless. Your corporate serfdom is not in question, but I disagree with that notion too.

It's a paid product, they are actually allowed to do this. Google is obviously going to focus on security testing with their own browser. It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. There is zero problem here guys.

> It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default.

Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces?

> It's a paid product, they are actually allowed to do this.

If that were the only metric, then no monopoly would ever be broken up for any reason (which I guess is the way regulation seems to work nowadays, but at least in theory it's supposed to be possible for it to happen sometimes). The idea that using market pressure from one product a company sells to squeeze out competition in another is totally fine as long as the first product is paid is not a premise I agree with.

Re: Google workspace threatening to block Firefox access

#76
They wont stop it. They will just slow down a bit if people get ruffled. That's how alphabet has handled everything else. They learned that if they can make changes slowly enough, they can do whatever the hell they want to.

As we all know we can even pay 10x more for items and get next to no raise in our wages, but because it was done slowly in an "official" and "professional" manner, most folks didn't even complain, they just screamed into the giant pillow we call "the internet".

Corporations of the 2020s love the internet's digital pillow and its magical crowd-quieting capabilities. If only the ancient roman empire had invented the internet they would be ruling the entire planet by now and we could watch gladiators on youtube :P provided we don't stand out too much (then we would be said gladiators)

Re: Google workspace threatening to block Firefox access

#77
post #73

Earlier quoted context omitted.

The wording here is bad, but basically CAA supports non browser specific policy and, in some cases, browser specific policy (GSuite offers a "Managed Chrome" policy). Firefox users can leverage much of the non browser specific policy, they obviously can not be a part of the "Managed Chrome" offering.

There's no contradiction here; it's totally possible for a company to make a feature configurable so that it doesn't block their competitors but also intentionally design and market it in a way that's misleading in ways that will lead to their competitors getting blocked. When we're talking about a company as large as Google and a product with as much market share as Chrome, I don't think it's that crazy to think tha…

If the argument is that Google has built a product that encourages use of Google products, of course. The question is whether that's some sort of trickery or odd or bad. "Google offers Managed Chrome as a service" hardly seems controversial to me.

Re: Google workspace threatening to block Firefox access

#78
Reading the news of EU countries leaving American cloud providers for local cloud solutions including mobile office, it's surprising to see Google doing this.

It will only accelerate moves towards location of data, self-hosting, etc. The technologies to make this possible are much easier than they ever have been.

Re: Google workspace threatening to block Firefox access

#79
post #70

Earlier quoted context omitted.

That's not entirely true. For example, on ChromeOS CAA is hardware backed. But obviously CAA is not intended to be our entire MDM solution, an attacker in a position to spoof your entire browser can bypass some of the policies on some operating systems. Similarly, attackers in that same position can bypass TLS. An attacker who owns the kernel can bypass much of your MDM. An attacker who owns the hardware can bypass j…

I haven't dug into the native helper to see how much it checks, I can believe that ChromeOS does full remote attestation. If it's anything like Android Play Integrity, there's not a lot of flexibility without hardware exploits. But who outside of Google is running exclusively ChromeOS? My impression from looking at the JS part is that it's mostly obfuscation, with the possible exception of ChromeOS. I feel like the s…

> But who outside of Google is running exclusively ChromeOS?

I think Chromebooks are pretty common in school settings

Re: Google workspace threatening to block Firefox access

#80
post #49

Earlier quoted context omitted.

you’d probably say something different if it were microsoft. I don’t see why I should give affordances of good will to Google here. They’re not stupid, they know that this is an effective lever to further cement full-fat chrome as the default browser for the internet.

Chrome was created because Google felt that the IE monopoly was hindering the advancement of web standards and improved browser capabilities. I suppose you could argue that was a different Google at a different time, but at one point they did feel that browser diversity was a good thing.

I mean, they claimed to be for browser diversity when it was not them on top lol. Underdogs want the race to tighten up, 85% market leaders want to stay out in front.
Post reply on HN