Hacker Newsnew | past | comments | ask | show | jobs | submit | ArnoVW's commentslogin

They live closer by? So less miles travelled, and in many cases travelled by train? Depending on how you generate electricity that works out quite differently.

Went to Venice by night train 15 years ago, would definitely recommend.

Conversely, however, perhaps we should question Europeans massively going to Phuket.


They dont put it on the ballot because it woulndnt work. Those fortunes are not liquid, but stuck in stocks.

There is no market to buy all of Amazon, or all of Tesla. Not at the current valuation.

You can take their fortune, but you cant spend it. Not in 4 years.


I can pretend to be someone with authority? (bank, policy, whatever) If the system becomes unavailable, then that's a huge issue?

Any system that is that widely anchored in society is a valuable target.


my layman understanding, a real statistician will surely intervene.

standard deviation is a measure that informs about the distribution. A high standard deviation means a "wide bell curve". A low standard deviation means that all values are closely clustered around the middle of the curve.

So if your value is 2 x standard deviation (for example) that means it is a relatively rare outlier, since 2 x standard deviation covers 95% of the bell curve. In particle physics I believe they require 5 standard deviations to confirm an observation.


While this is true, allow me to give another POV. I run corporate security and internal IT for a 100 person SaaS. I "nudge" our users towards Chrome. Why? Because I can manage Chrome using the config infrastructure provided by Google. Because Google has more resources to secure their browser. Because my observability and DLP stuff works with Chrome and not with Firefox. And I'm probably still missing out on a bunch of things.

Those are real, practical reasons. Not just "if I do this I get to check another box".

Yes. I know. It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's. Supporting more browsers to the same standard that I just described would take engineering resources, of which I do not have an infinite supply. And the priority goes to keeping the company secure.


> Because Google has more resources to secure their browser

They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.


My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification.

I find this incredibly amusing, and at a different point in my life I'd already be gone.

When you outsource IT, there are many, many misaligned incentives.


> I find this incredibly amusing, and at a different point in my life I'd already be gone.

How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.


99% of security experts I know use ad blockers.

When there are unpatched browser vulnerabilities, attackers will use ad networks to inject attack code into reputable-but-ad-laden websites. And even when there aren't unpatched vulnerabilities out there, many ad networks will happily accept scam ads, ads that trick people into downloading malware, fake download buttons and suchlike.


> 99% of security experts I know use ad blockers.

But if they all use Chrome, wouldn't those be really weak ad blockers?


This is a common myth. I've used uBlock Origin Lite for months (a year?) and still see zero ads.

I'm extremely intolerant to ads, so I would leave Chrome if ad blocking stopped working.


Adblocking is an arms race. Google is handicapping adblocking progressively the fact that it doesn't take one day to achieve absolutely doesn't make it a myth. Adblocking is technically worse and the more locked down our environments are the easier it will be to kill or drastically reduce it.

If everyone had the same attitude this would probably already be the case.


> 99% of security experts I know use ad blockers.

100% of security experts I know find ads annoying and know ad blockers reduce how many they see.


Not GP, but I think the point was that no extensions => no ad blockers => major malware vehicle unlockable, short of disabling JS


Bingo.

I figure they had a switch they could toggle and they thought no further about the tradeoffs. Because their primary concern is their own liability, not what's best for the org their contract is with.


> My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification.

Same here, but only on Chrome. Firefox works fine.


Have they blocked vscode? I think any organisation that lets people use vscode, might just as well people do whatever they want.


Nope :)


Brave has ad-blocking built in and policies can be used to disable any unwanted features. With Chrome going user-hostile, it's a pretty great option.


Extensions are a much greater security risk than ads.


They didn’t take a decade plus to implement per-domain process isolation, for starters…


You can downvote the truth, but can’t reply to it.

Typical modern Mozilla fans, really.


Typical Hacker News posters.


while valid points, my company uses Microsoft products and they are pretty abysmal in whatever domain they have products in. Edge for example being one of the weaker browser options. (though better than it was in the IE era).

Being forced to use various tools for compliance is frustrating, doubly so if it helps create a stronger monopoly position, because a monopoly position creates stagnation, which makes worse products.

But those worse products are forced on users, even when better ones start to come about.

This is the crux of my issue, Microsoft is the king of this behaviour, and they are using this a lot which is squeezing the metaphorical testicles of almost all companies in Europe.


> I can manage Chrome using the config infrastructure provided by Google

https://mozilla.github.io/policy-templates/


It's a pain that when you cannot do what you want to do. But it's not your laptop. It's the company's.

But it is my craft, and to be limited to what tools I can use in my craft can decrease the value of my work, and in doing so decrease the company's productivity.


Let's say you earn a million dollars a year (most of us earn far less). At quite a few companies, a 50% decrease in your productivity (and changing browsers is nowhere near that) would cost the company significantly less than dealing with the fallout of any of the following:

* A user intentionally leaking sensitive documents outside the corporate network

* A user installing an infected browser extension that gives attackers access to corporate resources

* A user accessing malware or ransomware which infects corporate resources.

That's on top of the cost of having the IT department having to debug issues among users with bespoke tool sets which can often interact in unintuitive ways.

There are many stupid ways that companies "optimize" costs that cost them more in the end. Standardizing the browser and extension set for data loss protection is not one of them.


All of what you listed is preventable at a mild labor cost to the same degree as other browsers.


That's not obvious at all. The feature sets and tooling are very different. The person you replied to said as much.

You (and I) aren't that special. People who are actually irreplaceable are astonishingly rare, and unless you're one of them, employees who will gripe about things like what web browser they use are often not worth the trouble at scale.


employees who will gripe about things like what web browser they use are often not worth the trouble at scale.

Firms who enforce homogeneity through policy are not worth the trouble at scale.


> But it is my craft

Then go work for yourself.

If you want the security of a regular salary, you need to jump through the hoops of your employer and not expect to be able to do 'your craft' however you see fit.


I don't think using a popular web browser is that unreasonable an accomodation.


If you run a SaaS, large parts of your orgs should be on all major browsers regularly.


I have a handful of endpoints, used by staff that represent a low level of risk, that use Firefox for that precise reason.

But really, we have a couple of million enterprise end-users, some of which surely using Edge. If we as much as move a button without telling them about it three months in advance, it's the end of the world. In 10 years time, no customer has raised it.


Edge: Chromium with Google Chrome-like data collection, but with data going to Microsoft instead.


This is the correct answer. Having your users run multiple browsers by default (instead of with whitelisted exceptions) is now multiple attack surfaces the org has to manage.


Very curious how you avoid supporting multiple browsers. Apple, Google, and Microsoft each require users on their platforms to use their native browsers for secure connections.

And if your company has any web presence or apps, you usually can't cherry pick which browsers your customers can use. That means some portion of your company will need access to other browsers for QA purposes.


At the minimum I might say you only allow Chrome to access Google Workspace/SSO, which is needed to access like 95% of company resources. This is, in fact, the topic of the OP.

You can do additional device management to lock down the rest of the machine. You can force Chrome and restrict Safari/Firefox/etc on Mac just fine. Same for Windows.


Do people get pwned by anything besides spearphishing or ads nowadays? I think ad->phish or targeted phish emails is the only shady thing I've been exposed to in like 10 years


Running npm install is a good way to get compromised.


This feels like the whole IE6 dance coming back.

People know how it ended, but don't seem to remember how it started, which is a shame.


Google has the resources to do it, but do they actually do it? By the looks of it I'd say "no".

See the whole thing with libxml2 for example, or how they started boringssl to "fix" the issues with openssl, but they run it as an internal project you cannot depend on.


having soon-to-be-nonfunctional adblocking will be far more dangerous to org than any extra security those options might provide


Ubo lite is plenty functional. It's not as full-featured as ubo, but... I don't see ads. At all. What sites doesn't it work well on?


> But it's not your laptop. It's the company's.

Sure, which is why you should lock down the laptop. Blocking Firefox in Google Workspace seems like entirely the wrong layer for this.


Yes. Or at least that is what I understood from the Radiolab episode on “how do aesthetics work”

https://radiolab.org/podcast/anesthesia


The day they introduced non smoking (late nineties?) a friend of mine found out as the aeroport. He made a big stink, canceled his ticket and booked a new flight for Amsterdam - NYC with the only company still allowing smoking: Aeroflot.

He spent the better part of a day, flying via Moscow.

The next time he had to fly he grudgingly accepted it.

Sometimes even Shaw's unreasonable man has to come to terms with defeat.


Without thinking too hard I can name a few?

The rise of authoritarianism? Inequality? Revival of geopolitical "realism"? Decrease in empathy and holistic thinking? Increasing willingness of the general population to engage in political adventurism? Accelerating resource consumption (and decelerating resource stocks).

And if you consider none of those "real" problems, I know some people seem to have forgotten about it, but what about climate change? Given the half-life of CO2 and methane, that's a problem as "real" as they get.


There's also a worrying trend of education getting less effective across the first world.


agreed. The problem is, often, when you can have "for free" something that is "good enough", you stop looking for better.

40 years ago, there was a market for:

  * newspapers

  * cameras

  * navigation tools

  * HiFi equipment

  * photographers, translators, etc
.. sure, there are still people with newspaper subscriptions, or DSLR cameras. But it's become a niche market. Those things have been replaced by your phone and a "free" service.

Same thing will happen for all the other markets that AI will gradually eat. Sure, you can find a human that can do better. But that costs 90$ / hour and requires finding someone, negotiating a contract, etc. But when people can do something good enough in 30 seconds with something they already have access to, and move on with their life, then that's what they'll do.

So just raising the floor will have a big effect on society.


Well if one would get theological about it, I do believe they were given the land and then expelled by god. The Bible is quite explicit on that point.

I don’t remember seeing the memo that god gave “back” the land, so logically speaking they are acting against the will of god.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: