5 ms·
It's their organization. They are allowed to make decisions about what software their employees use. I'm a die-hard Mozilla fan, but I don't find this unreasona
by ktm5j 4mo ago
It's their organization. They are allowed to make decisions about what software their employees use. I'm a die-hard Mozilla fan, but I don't find this unreasonable.
- dijit 4mo agoGoogle and Microsoft shouldn’t be giving levers that bake you more into their ecosystem regardless. Your corporate serfdom is not in question, but I disagree with that notion too.
- lern_too_spel 4mo agoIf a corporation with my data allowed access to its internal tools using any browser running any arbitrary and possibly compromised third party extensions, that's a data leak and class action lawsuit waiting to happen.
- ktm5j 4mo agoIt's a paid product, they are actually allowed to do this. Google is obviously going to focus on security testing with their own browser. It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. There is zero problem here guys.
- saghm 4mo ago> It's understandable that organizations want to require chrome for their employees to access their workspace in the interest of security, but it's not the default. Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? > It's a paid product, they are actually allowed to do this. If that were the only metric, then no monopoly would ever be broken up for any reason (which I guess is the way regulation seems to work nowadays, but at least in theory it's supposed to be possible for it to happen sometimes). The idea that using market pressure from one product a company sells to squeeze out competition in another is totally fine as long as the first product is paid is not a premise I agree with.
- vel0city 4mo ago> Can you elaborate on why you think that Firefox is inherently insecure in some way for accessing Google workspaces? Allowing users running who knows what version of Firefox (or any "non-validated"/unmanaged browser, not necessarily just Firefox) browser running who knows what extensions can be pretty unsafe. There are lots of malicious extensions out there that are stupid simple to install. In the Workspace world, Chrome can be configured and enforced to have certain kinds of settings applied. Only allowing certain extensions. Ensure certain version ranges. That sort of thing.
- dminik 4mo agoI'm pretty sure Firefox is configurable using AD. So is automatically updating (not sure about freezing versions). If you don't want your user to run whatever version with whatever extension you can do that.
- vel0city 4mo agoSure. But there's generally no standardized function ensuring they're actually only using that specifically configured browser when logging in. What happens when they try to log in from some other device? What happens when they manage to load a browser on to that machine? This feature supposedly ensures (or at least pushes users to) only the approved browsers running approved configurations are allowed to log in to the company's instances of Workspace.
- dminik 4mo agoDoes it? What if a company decides that their preferred browser is Firefox. Can you use this feature to only enable logins from Firefox? Or is it only for Chrome?
- vel0city 4mo agoThey can't use this feature to enforce only Firefox. Firefox doesn't have support for this feature, they really don't offer anything like Chrome Enterprise. Its just as much a feature of Chrome Enterprise that Workspace leverages rather than only a feature of Workspace that leverages Chrome. You can still use Firefox with Workspace though, but if you want the management features of Chrome Enterprise you need to use Chrome Enterprise. Firefox itself just doesn't even begin to offer the same kind of endpoint verification. With Firefox today, how would a web app have any serious clue the client was running approved versions of Firefox configured in approved ways on approved hardware with approved OS configurations? It wouldn't, and I take it Firefox wouldn't bother implementing that kind of technology. Which is fine, but if the customer wants to be able to ensure a certain kind of policy compliance that's just not possible when using Firefox. And that's just as much if not more of the ball being in Firefox's court as it is Google Workspace's. There's nothing for Workspace to even interface with at all from the Firefox side to ensure policy compliance. Its like asking "can I print on this printer with this app?" when the app itself doesn't even have a concept of printing things. The basic underlying feature set just doesn't even exist, before we're even talking about some form of platform compatibility.
- cmeacham98 4mo agoThe problem is Google appears to label this as a security feature. I'm fine with the feature existing, but it should say something like "require Chrome" or "block Firefox" not "require a secure browser (wink wink we actually mean Chrome)"
- insanitybit 4mo agoThe wording here is bad, but basically CAA supports non browser specific policy and, in some cases, browser specific policy (GSuite offers a "Managed Chrome" policy). Firefox users can leverage much of the non browser specific policy, they obviously can not be a part of the "Managed Chrome" offering.
- saghm 4mo agoThere's no contradiction here; it's totally possible for a company to make a feature configurable so that it doesn't block their competitors but also intentionally design and market it in a way that's misleading in ways that will lead to their competitors getting blocked. When we're talking about a company as large as Google and a product with as much market share as Chrome, I don't think it's that crazy to think that things like this add up to encouraging even more hegemony, and when that happens to align perfectly with the incentives of the company making said product decisions, I also don't think it's crazy to think it's unlikely to be a coincidence.
- insanitybit 4mo agoIf the argument is that Google has built a product that encourages use of Google products, of course. The question is whether that's some sort of trickery or odd or bad. "Google offers Managed Chrome as a service" hardly seems controversial to me.
- jchw 4mo agoGoogle offering managed chrome as a service is a completely sensible thing. The problem is that they are nearly a browser monopoly, and making Google Workspace work in such a way with Google Chrome feels to me like anti-competitive practices. If we didn't have one giant megacorp that did both things, it would be different. Of course, so far the only workable model for web browsers is having a giant megacorp fund their development and maintenance. Which is a huge issue, and we will do basically nothing about it. (Don't get me wrong. I have high hopes for Ladybird and even Servo, but they may come too late if effectively-proprietary features force most users to stick to Chrome anyways.)
- wslh 4mo agoI would say it's common to find dark patterns that involves ambiguity like the discussion we are having here. We can't know for sure but Google can increase the probability of being on their ecosystem.
- jchw 4mo agoNote that making lock-in features like this effectively proprietary to the Chrome browser is only possible because of the fact that it's the same company making Google Workspace and Google Chrome. I absolutely see many problems with this and you really ought to as well.
- charcircuit 4mo ago>only possible Two different companies can partner together and release features in both of the company's interests.
- jchw 4mo agoI didn't mean it would be physically impossible, which is hopefully implied, I mean, it would be de-facto impossible. Absent the perverse forces of anticompetitive behavior, browsers don't really have a good incentive to diminish the open nature of web standards by doing partnerships that bypass standards altogether. If you are not affiliated with Google and there is a healthy ecosystem of browsers, you just simply can tell them to bug off if they want some web feature you feel wouldn't be good for the health of the web. The interaction between browser vendors and certificate authorities has traditionally been a great example of how things can work out between different entities in an ecosystem, though outside Mozilla I am guessing most of the browser vendors are also CAs (but still have very little to no incentive to compromise or weaken the system.) Meanwhile, in our current reality, both Google and Apple have or currently are shoehorning platform level attestation into the web in various different ways, something they are mostly able to do because they have so much control over multiple major ecosystems (among platforms, browsers, web services.) Mostly, even making them "standards", which would be hilarious if it wasn't literally evil. (Apple's approach to sneaking this in is innovative, in that it technically is a hardware platform attestation mechanism, but it was sold and initially implemented as a convenience feature. That and the underlying PAT technology can be used in strictly non-evil ways, like Kagi's rather clever application.) It's a lot of words to say that I didn't mean literally impossible, but if we're going to get pedantic then a lot of words it is.
- 4mo ago
- abyssin 4mo agoIt’s a good reminder of the fact that capitalist companies aren’t democratic places, despite how much time and energy is spent there by workers.