Live data from Hacker News

Google workspace threatening to block Firefox access

tales.fromprod.com

91–100 of 194 posts

Re: Google workspace threatening to block Firefox access

#91

Earlier quoted context omitted.

You don't have to have a monopoly to be monopolistic.

The Sherman Act says that any action by an individual, or conspiracy of a group of individuals, to "restrain trade" or seek a monopoly is illegal. Monopolies aren't a prerequisite for antitrust action, they're the failure state when you should have acted sooner.

Taco Bell is a monopoly because they restrain the trade of tacos because they ask me to take my taco truck elsewhere when I park in their parking lot to sell tacos. Never mind there are other places I can set up my truck, never mind there are tons of other taco shops, Taco Bell is a monopoly as now I need to go find a different corner to sell my tacos, they're restraining the trade of tacos.

Everything is a monopoly these days. Its practically meaningless in these conversations.

Re: Google workspace threatening to block Firefox access

#92
post #18
post #11

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch of things.

Those are real, practical reasons. Not just "if I do this I get to check another box".

Yes. I know. It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's. Supporting more browsers to the same standard that I just described would take engineering resources, of which I do not have an infinite supply. And the priority goes to keeping the company secure.

Re: Google workspace threatening to block Firefox access

#93
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

Well, it could als also be argued that Chrome _is_ more secure, for example because it uses app-bound encryption using Windows DPAPI system, for cookies, so that it at least tries to protect cookies from malicious applications running on the device. Firefox does not do this: https://security.stackexchange.com/questions/279629/are-cook... If course the reverse can also be argued, for example that Firefox supports prop…

Unfortunately the malicious actor I want to protect my cookies from is Google.

Re: Google workspace threatening to block Firefox access

#94
post #81

Earlier quoted context omitted.

If the argument is that Google has built a product that encourages use of Google products, of course. The question is whether that's some sort of trickery or odd or bad. "Google offers Managed Chrome as a service" hardly seems controversial to me.

Google offering managed chrome as a service is a completely sensible thing. The problem is that they are nearly a browser monopoly, and making Google Workspace work in such a way with Google Chrome feels to me like anti-competitive practices. If we didn't have one giant megacorp that did both things, it would be different. Of course, so far the only workable model for web browsers is having a giant megacorp fund thei…

I'm not sure what the alternative is. Is there will from Firefox to support a "standard browser config", at which point GSuite could add support for managed Firefox config? If you want managed Firefox, Mozilla could offer that as well (they have something but it's different enough).

Re: Google workspace threatening to block Firefox access

#95
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

while valid points, my company uses Microsoft products and they are pretty abysmal in whatever domain they have products in. Edge for example being one of the weaker browser options. (though better than it was in the IE era).

Being forced to use various tools for compliance is frustrating, doubly so if it helps create a stronger monopoly position, because a monopoly position creates stagnation, which makes worse products.

But those worse products are forced on users, even when better ones start to come about.

This is the crux of my issue, Microsoft is the king of this behaviour, and they are using this a lot which is squeezing the metaphorical testicles of almost all companies in Europe.

Re: Google workspace threatening to block Firefox access

#96
post #92
post #18

Earlier quoted context omitted.

it shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

If you run a SaaS, large parts of your orgs should be on all major browsers regularly.

Re: Google workspace threatening to block Firefox access

#97

Earlier quoted context omitted.

Well, it could als also be argued that Chrome _is_ more secure, for example because it uses app-bound encryption using Windows DPAPI system, for cookies, so that it at least tries to protect cookies from malicious applications running on the device. Firefox does not do this: https://security.stackexchange.com/questions/279629/are-cook... If course the reverse can also be argued, for example that Firefox supports prop…

Unfortunately the malicious actor I want to protect my cookies from is Google.

Not really a serious argument when you are accessing a Google product. Sure, don't want to interact with Google? Don't interact with Google, but logging into Google workspaces with Firefox definitely isn't protecting your data from Google.

Re: Google workspace threatening to block Firefox access

#99
post #9

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

> The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

can you put a restriction to ban Chrome and force Firefox then?

Re: Google workspace threatening to block Firefox access

#100
post #92

Earlier quoted context omitted.

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch o…

If you run a SaaS, large parts of your orgs should be on all major browsers regularly.

I have a handful of endpoints, used by staff that represent a low level of risk, that use Firefox for that precise reason.

But really, we have a couple of million enterprise end-users, some of which surely using Edge. If we as much as move a button without telling them about it three months in advance, it's the end of the world. In 10 years time, no customer has raised it.

Post reply on HN