6 ms·
> Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them. Blocking this domain definitely isn't commo
by profmonocle 5y ago
> Which is to say, the problem is organizations using storage.googleapis.com URLs, not organizations blocking them.
Blocking this domain definitely isn't common, at least not in large organizations. Several of my company's B2B apps use Google Cloud Storage (it's just Google Cloud's version of S3) and have always used storage.googleapis.com/bucketname rather than bucketname.storage.googleapis.com. (AFAIK it was the default URL format shown in their documentation when I last looked at it years ago.)
We've had to deal with overzealous corporate web filters now and then - comes with the territory of B2B apps - but I've never heard of storage.googleapis.com being blocked. It'd be pretty straightforward for us to change it if a customer had trouble, but we'd probably gently push back and ask them to whitelist the domain before doing so.
- ocdtrekkie 5y agoI would say in my professional experience, I've only once seen someone legitimately directly need to pull content through storage.googleapis.com (whether bucketname.storage.googleapis.com or not). My assumption is public-facing entities tend to serve content via their own domains to end user clients. I'd be comfortable whitelisting a bucket subdomain, but as I said, it's only come up once, so we worked around it the one time. And I've blocked a lot of phishing sites this way. I'd highly recommend large organizations follow suit. :)