back
188 comments
This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.
it shouldn’t be an option.

Some IT departments just see a “more secure” checkbox and will always check it, even if it doesn’t make sense holistically- sometimes compliance incentivises (or forces) this behaviour.

A common example is forcing intune/device enrolment for mobile devices (including ipads)- but not for the infinitely less secure laptops: because no such endpoint enforcement checkbox exists

While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch of things.

Those are real, practical reasons. Not just "if I do this I get to check another box".

Yes. I know. It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's. Supporting more browsers to the same standard that I just described would take engineering resources, of which I do not have an infinite supply. And the priority goes to keeping the company secure.

It's their organization. They are allowed to make decisions about what software their employees use. I'm a die-hard Mozilla fan, but I don't find this unreasonable.
Hi there, original author here. Can confirm we're not using IAP for this workspace, or anything I was trying to access
But they explicitly negate this:

> We haven’t configured, and don’t use IAP (Identity Aware Proxy) - I’ve used this before and yes that is Chrome only due to how it does device verification

> This isn’t because of “Context Aware Access” this is an enterprise only feature, and we’re on Google Workspace Business Plus

Is it not:

https://knowledge.workspace.google.com/admin/security/create...

The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

Unrelated to this news, but this is so rudimentary, when the correct solution instead is:

1. Make it ridiculously easy to install hardware vendor keys and register it with OS of choice. (like a standardized dialog box in UEFI and a standardized/regulated IPMI-like interface)

2. Allow for only measured boot on those devices.

3. Provided facility to verify signatures.

Do this on consumer and enterprise laptops and desktops alike and all of these weird set of conditions just go out of play and replaced by something much much simpler.

> The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

can you put a restriction to ban Chrome and force Firefox then?

"wow look at all these options available...to limit users to only use software provided by the same corp" you are missing the point entirely.
Why is there a policy to require “Chrome” and not a policy to require another browser, hmm?
Hi folks, blog author here.

Few comments based on common threads

- No we don't have, or use, IAP and haven't configured it

- Yes I'm the admin so can confirm this

- "Context aware access" is only available on enterprise, we're just on "Workspace business plus"

Happy to answer any other questions

It appears website developers desperately want to return to a world where browsers actively pretend to be another browser*.

Want to check for DBSC? Enjoy not knowing whether the browser vendor decided to just roll a simple software implementation.

Nothing good comes from browser detection over feature detection anyways. It's time to do away with user-agents and other overt identifying markers, and if we're still not in a better place, aggressively start stubbing features.

* to some degree they still are. Firefox still ships with an user-agent override list for certain websites that have outdated user-agent sniffing for feature detection (and other fixes in about:compat).

You mean the same that gave Chrome its market share, by adopting ChromeOS features, and shipping Electron apps?
What is the process to aggressively stub features? Does that mean pushing patches to Firefox and/or Ladybird and/or Servo?
Cloudflare blocked me with a chrome windows useragent on Firefox+Fedora
And yet, claiming support for a feature doesn't tell all. Different implementations can have subtle differences. Knowing the browser and version can allow a client to survive that.
It states something about "your organisation's security requirements", do they document what requirements cause this rejection page? Some kind if changed default perhaps?
No, this is easily the biggest flaw in CAA - there is no way to discover which policy broke your access. I have reported this to Google multiple times, even sent this directly to a Google SecEng (a well known one) to route internally. The issue persists and makes configuring CAA extremely painful and error prone.
Maybe not, but I have the feeling Google doesn't like that FF continues to support manifest v2.
I love that google always sends useless canned responses after basically requiring you to perform a blood sacrifice to get ahold of anyone.
At least you got a heads-up. Few months back GCP "Agent Studio - Build" failed compiling the code in sandbox with a vague error message. Spent weeks troubleshooting, spoke to google engineers and reps, sending code, step by steps, screenshots. No one had a clue, until I switched from Firefox to Chrome out of desperation and it worked without a hitch.
Seems like a monopolistic move.
Google doesn’t have a monopoly in workspace applications.
I know Google finally kicked all their employees off alternate browsers but doing it for external customers is definitely a choice
I'm not so sure that enforcing an internal digital monoculture is a productive way to achieve innovation & resilience.
They wont stop it. They will just slow down a bit if people get ruffled. That's how alphabet has handled everything else. They learned that if they can make changes slowly enough, they can do whatever the hell they want to.

As we all know we can even pay 10x more for items and get next to no raise in our wages, but because it was done slowly in an "official" and "professional" manner, most folks didn't even complain, they just screamed into the giant pillow we call "the internet".

Corporations of the 2020s love the internet's digital pillow and its magical crowd-quieting capabilities. If only the ancient roman empire had invented the internet they would be ruling the entire planet by now and we could watch gladiators on youtube :P provided we don't stand out too much (then we would be said gladiators)

Reading the news of EU countries leaving American cloud providers for local cloud solutions including mobile office, it's surprising to see Google doing this.

It will only accelerate moves towards location of data, self-hosting, etc. The technologies to make this possible are much easier than they ever have been.

Sounds like you have a device policy configured and you should talk to your internal IT/Security team?

edit: This title is just incredibly misleading. OP seems to have made a mistake here in thinking that this is something that Google has done when it's just that their corporate IT/ Sec team now enforces using Chrome.

Not defending it, but given that they use the word "secure" three times in two sentences, I'm wondering if it's shown to browsers that don't support DBSC. Google has been really pushing/overselling this as a magical solution to cookie theft.
I was thinking it could be a Context-Aware Access thing. Firefox doesn’t support Endpoint Verification plugin
That's fine. The second I stopped caring, which is the day I stopped working for a living, I stopped worrying about what Google thinks. I don't use Google for email or search. (my email addresses are with proton, iCloud, and Hey, and my search is DDG) I'm not a big video person so I never use Youtube, the few times I need to use an office product I will either use OnlyOffice, or the Apple stuff. My Phone is an iPhone (with the stuff mentioned above) My browser is Firefox with uBlock Origin, and I almost never have problems with this setup.
If people want specifics about what this is, look here:

> https://knowledge.workspace.google.com/admin/security/contex...

In particular "Allow access to devices using Chrome browser with security requirements" would present this message.

I use Google as a secondary search and as of roughly last week it gives me a captcha every time I try to do a search. That had never been the case before.
I browse over Tor for most things and most sites give me a captcha or just simply fail to load these days. I just close the window and move on to something else.
I am seeing it a lot more lately with uBlock Origin. I've used DDG for search for a while now, but the last few times I've tried Google I got a captcha within a couple of queries if not immediately.
For a few years now Google has given me a captcha whenever my VPN is on (Private Internet Access)
It is probably Chrome Enterprise which lets you lock down, for example, what extensions people are allowed to install. There is a legit reason for organizations to want to standardize on one browser and to lock it down (as browser extensions are a major source of infiltration these days).
Firefox supports locking down like that as well so that sounds like lazy IT.
Smells anticompetitive to me
We have collectively let a few companies control/centralize the internet. Then have a shocked pikachu face when these same companies do shitty things.
Unrelated to Google Workspace and Firefox, but I just noticed today that Google’s YouTube now says my iPhone’s Safari browser is incapable of playing full screen videos, which it’s not ever claimed before. I’m also getting sick of them pushing Chrome anytime I use a Google service like search or Gmail. I keep dismissing the prompts, but they are relentless. It all seems so sleezy and desperate.
Does Chromium would still work?
Just say no to Google.
antitrust
Oh look, a monopolist is making settings "more secure" by enshrining monopoly more.

And good fucking luck getting the FTC to follow monopoly law.

The sky is falling! The sky is falling!

Do your homework before yelling "Fire!".

Do it then