Google workspace threatening to block Firefox access

birdculture 467 points 149 comments June 19, 2026
tales.fromprod.com · View on Hacker News

Discussion Highlights (19 comments)

coldfloor

Not defending it, but given that they use the word "secure" three times in two sentences, I'm wondering if it's shown to browsers that don't support DBSC. Google has been really pushing/overselling this as a magical solution to cookie theft.

jeroenhd

It states something about "your organisation's security requirements", do they document what requirements cause this rejection page? Some kind if changed default perhaps?

kjkjadksj

Smells anticompetitive to me

ferfumarma

Seems like a monopolistic move.

chmod775

It appears website developers desperately want to return to a world where browsers actively pretend to be another browser*. Want to check for DBSC? Enjoy not knowing whether the browser vendor decided to just roll a simple software implementation. Nothing good comes from browser detection over feature detection anyways. It's time to do away with user-agents and other overt identifying markers, and if we're still not in a better place, aggressively start stubbing features. * to some degree they still are. Firefox still ships with an user-agent override list for certain websites that have outdated user-agent sniffing for feature detection (and other fixes in about:compat).

lokar

Is it not: https://knowledge.workspace.google.com/admin/security/create... The Org admin can put all sorts of restrictions on who can do what based on the client device setup.

bgc

This is not a Google-wide thing… this is from Google’s Context-Aware Access product, which is configurable in Google Workspace environments. OP should direct their ire at their corporate IT or infosec team.

add-sub-mul-div

I use Google as a secondary search and as of roughly last week it gives me a captcha every time I try to do a search. That had never been the case before.

saagarjha

I know Google finally kicked all their employees off alternate browsers but doing it for external customers is definitely a choice

wwizo

At least you got a heads-up. Few months back GCP "Agent Studio - Build" failed compiling the code in sandbox with a vague error message. Spent weeks troubleshooting, spoke to google engineers and reps, sending code, step by steps, screenshots. No one had a clue, until I switched from Firefox to Chrome out of desperation and it worked without a hitch.

eikenberry

Does Chromium would still work?

insanitybit

Sounds like you have a device policy configured and you should talk to your internal IT/Security team? edit: This title is just incredibly misleading. OP seems to have made a mistake here in thinking that this is something that Google has done when it's just that their corporate IT/ Sec team now enforces using Chrome.

nekusar

Oh look, a monopolist is making settings "more secure" by enshrining monopoly more. And good fucking luck getting the FTC to follow monopoly law.

sdrawkcabsti

They wont stop it. They will just slow down a bit if people get ruffled. That's how alphabet has handled everything else. They learned that if they can make changes slowly enough, they can do whatever the hell they want to. As we all know we can even pay 10x more for items and get next to no raise in our wages, but because it was done slowly in an "official" and "professional" manner, most folks didn't even complain, they just screamed into the giant pillow we call "the internet". Corporations of the 2020s love the internet's digital pillow and its magical crowd-quieting capabilities. If only the ancient roman empire had invented the internet they would be ruling the entire planet by now and we could watch gladiators on youtube :P provided we don't stand out too much (then we would be said gladiators)

j45

Reading the news of EU countries leaving American cloud providers for local cloud solutions including mobile office, it's surprising to see Google doing this. It will only accelerate moves towards location of data, self-hosting, etc. The technologies to make this possible are much easier than they ever have been.

Bill2Lewis

The sky is falling! The sky is falling! Do your homework before yelling "Fire!".

hoomank3

It is probably Chrome Enterprise which lets you lock down, for example, what extensions people are allowed to install. There is a legit reason for organizations to want to standardize on one browser and to lock it down (as browser extensions are a major source of infiltration these days).

Someone1234

If people want specifics about what this is, look here: > https://knowledge.workspace.google.com/admin/security/contex... In particular "Allow access to devices using Chrome browser with security requirements" would present this message.

RichardoC

Hi folks, blog author here. Few comments based on common threads - No we don't have, or use, IAP and haven't configured it - Yes I'm the admin so can confirm this - "Context aware access" is only available on enterprise, we're just on "Workspace business plus" Happy to answer any other questions

Semantic search powered by Rivestack pgvector
10,996 stories · 103,478 chunks indexed