8 ms·
This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct th
by bgc 3mo ago
This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.
- dijit 3mo agoit shouldn’t be an option. Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour. A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists
- SoftTalker 3mo agoUsing a maintained and up-to-date browser is a reasonable requirement for an IT department (should be for anyone really). Would you suggest they should be allowing IE6 just because a user might prefer it? Of course Google is going to suggest using Chrome, if they detect that the browser might be out of date.
- dijit 3mo agoIs the implication that Firefox is not maintained or? The issue presented doesn’t seem to be “an up to date browser check” it seems to be a “is it latest chrome” check, which is a very different thing.
- SoftTalker 3mo agoWe don't know. The author doesn't mention how current the Firefox browser is/was. If the organization is indeed enabling a specific check for Chrome that seems a little over the top but they're the ones supporting their users and if they want to make their life easier by only dealing with one browser that's their decision to make. It's like saying that everyone has to use Windows, or a specific line of laptops, or any other standardization to simplify the support workload.
- SpicyLemonZest 3mo agoIt's not clear to me that Context-Aware Access is as configurable as you're implying. At a glance, the docs seem to suggest that Chrome is the only browser you can force standardization on, which IMO does push this towards being Google's fault.
- insanitybit 3mo agoThat's correct, there is no way to say "only allow Firefox" in CAA because the attestations are either browser agnostic or chrome specific (as part of the managed Chrome offering that GSuite supports).
- michaelmrose 3mo agoIt's not a little over the top its an antitrust issue and clearly and obviously wrong.
- kolinko 3mo agoNot a little over the top, it is anticompetitive behavior.
- inquirerGeneral 3mo ago[dead]
- rpdillon 3mo ago> This was for a Google Workspace Business Plus account and workspace, from an up to date browser and OS.
- jstummbillig 3mo agoIf we are meant to believe that this is a Chrome-invasion-move, it's the least effective lever of all times. Most of the time the more plausible explanations are just the likely ones.
- dijit 3mo agoyou’d probably say something different if it were microsoft. I don’t see why I should give affordances of good will to Google here. They’re not stupid, they know that this is an effective lever to further cement full-fat chrome as the default browser for the internet.
- SoftTalker 3mo agoChrome was created because Google felt that the IE monopoly was hindering the advancement of web standards and improved browser capabilities. I suppose you could argue that was a different Google at a different time, but at one point they did feel that browser diversity was a good thing.
- recursivecaveat 3mo agoI mean, they claimed to be for browser diversity when it was not them on top lol. Underdogs want the race to tighten up, 85% market leaders want to stay out in front.
- ibejoeb 3mo agoNo, not at all. The implication is that the organization is dictating the software that employees are to use. There's nothing unusual about this.
- subscribed 3mo agoStrawman argument. Firefox is maintained and up to date browser. Why did you even compare it to IE6, out of the curiosity?
- Karliss 3mo agoIf that's a the goal, then IT department should start by blocking user ability to install Firefox or other unapproved software not by blocking access to google workspace. Blocking access to google workspace using Firefox doesn't prevent using it for everything else. It's not like the google services are going to exploit a vulnerability in Firefox, everything else might.
- insanitybit 3mo agoCAA is one of the most powerful security features you can enable in an org. You can manage browser extensions, device password policy, encryption, configuration, cookie attestation, etc.
- tux3 3mo agoCAA is completely based on trust, it's not one of the most powerful security feature. It's completely voluntary reporting by the browser, and any attacker who cares can just lie without issues. You can make Firefox pass CAA if you want. You take the Chrome "SecureConnect Reporting" (Context-Aware Access) plugin, port it to Firefox with some light changes, and you can report whatever you want to CAA.
- insanitybit 3mo agoThat's not entirely true. For example, on ChromeOS CAA is hardware backed. But obviously CAA is not intended to be our entire MDM solution, an attacker in a position to spoof your entire browser can bypass some of the policies on some operating systems. Similarly, attackers in that same position can bypass TLS. An attacker who owns the kernel can bypass much of your MDM. An attacker who owns the hardware can bypass just about anything.
- tadfisher 3mo agoUnderstand that, in this conversation, your use of "attacker" is referring to "end user of the hardware". Which might be part of the Chrome team's definition, or might not, but gosh it would be nice to cater to the folks who are using the dang computer.
- insanitybit 3mo agoWe're talking about a device managed by a corporation. I have no idea what your point is.
- tux3 3mo ago
- ktm5j 3mo agoIt's their organization. They are allowed to make decisions about what software their employees use. I'm a die-hard Mozilla fan, but I don't find this unreasonable.
- dijit 3mo agoGoogle and Microsoft shouldn’t be giving levers that bake you more into their ecosystem regardless. Your corporate serfdom is not in question, but I disagree with that notion too.
- lern_too_spel 3mo agoIf a corporation with my data allowed access to its internal tools using any browser running any arbitrary and possibly compromised third party extensions, that's a data leak and class action lawsuit waiting to happen.
- ktm5j 3mo agoIt's a paid product, they are actually allowed to do this. Google is obviously going to focus on security testing with their own browser. It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. There is zero problem here guys.
- saghm 3mo ago> It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? > It's a paid product, they are actually allowed to do this. If that were the only metric, then no monopoly would ever be broken up for any reason (which I guess is the way regulation seems to work nowadays, but at least in theory it's supposed to be possible for it to happen sometimes). The idea that using market pressure from one product a company sells to squeeze out competition in another is totally fine as long as the first product is paid is not a premise I agree with.
- farbklang 3mo agoWell - it does make sense. If an organisation that contracts me has to chose between a) BYOD - but restrict downloads, etc, enforce export control, directly in the browser - I happily take that, vs getting a Windows laptop that is locked down and forced to work with that.
- Doohickey-d 3mo agoWell, it could als also be argued that Chrome _is_ more secure, for example because it uses app-bound encryption using Windows DPAPI system, for cookies, so that it at least tries to protect cookies from malicious applications running on the device. Firefox does not do this: https://security.stackexchange.com/questions/279629/are-cookies-stored-with-encryption-and-and-how-do-browsers-protect-them https://security.stackexchange.com/questions/279629/are-cook... If course the reverse can also be argued, for example that Firefox supports proper adblocking.
- AlexandrB 3mo agoUnfortunately the malicious actor I want to protect my cookies from is Google.
- zchrykng 3mo agoNot really a serious argument when you are accessing a Google product. Sure, don't want to interact with Google? Don't interact with Google, but logging into Google workspaces with Firefox definitely isn't protecting your data from Google.
- sandeepkd 3mo agoIts a normal choice, given a checkbox on page which advertises that checking it would make your security posture more safe. The IT person is safeguarding their own job. Other way to look at it is, the company is paying for everything, and they get to make decisions based on what suits their security needs.
- ArnoVW 3mo agoWhile this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch of things. Those are real, practical reasons. Not just "if I do this I get to check another box". Yes. I know. It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's. Supporting more browsers to the same standard that I just described would take engineering resources, of which I do not have an infinite supply. And the priority goes to keeping the company secure.
- dijit 3mo agowhile valid points, my company uses Microsoft products and they are pretty abysmal in whatever domain they have products in. Edge for example being one of the weaker browser options. (though better than it was in the IE era). Being forced to use various tools for compliance is frustrating, doubly so if it helps create a stronger monopoly position, because a monopoly position creates stagnation, which makes worse products. But those worse products are forced on users, even when better ones start to come about. This is the crux of my issue, Microsoft is the king of this behaviour, and they are using this a lot which is squeezing the metaphorical testicles of almost all companies in Europe.
- chinathrow 3mo agoIf you run a SaaS, large parts of your orgs should be on all major browsers regularly.
- ArnoVW 3mo agoI have a handful of endpoints, used by staff that represent a low level of risk, that use Firefox for that precise reason. But really, we have a couple of million enterprise end-users, some of which surely using Edge. If we as much as move a button without telling them about it three months in advance, it's the end of the world. In 10 years time, no customer has raised it.
- sgalbincea 3mo ago"it shouldn’t be an option." What? Are you serious? An organization has EVERY right to enforce whatever controls they deem appropriate for their environment. Period.
- m-p-3 3mo agoWhy? We do conditional access at the Azure level, and a device that doesn't meet some compliance policies on their machine (Windows, macOS, Linux) is unable to access their corporate account until they remediate that.
- RichardoC 3mo agoHi there, original author here. Can confirm we're not using IAP for this workspace, or anything I was trying to access
- lelandfe 3mo agoPsst, you have a merge conflict in your text
- dvfjsdhgfv 3mo agoBut they explicitly negate this: > We haven’t configured, and don’t use IAP (Identity Aware Proxy) - I’ve used this before and yes that is Chrome only due to how it does device verification > This isn’t because of “Context Aware Access” this is an enterprise only feature, and we’re on Google Workspace Business Plus