Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Um... How about NO.

Um... How about NO.

Scheduled Pinned Locked Moved Uncategorized
11 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchange
    wrote last edited by
    #1

    Um... How about NO.

    WTF?

    Link Preview Image
    kajer@infosec.exchangeK jesstheunstill@infosec.exchangeJ charlesh@infosec.exchangeC 3 Replies Last reply
    0
    • kajer@infosec.exchangeK kajer@infosec.exchange

      Um... How about NO.

      WTF?

      Link Preview Image
      kajer@infosec.exchangeK This user is from outside of this forum
      kajer@infosec.exchangeK This user is from outside of this forum
      kajer@infosec.exchange
      wrote last edited by
      #2

      I'll just have to take comfort in knowing 300+ of my users allow this

      fritzadalis@infosec.exchangeF 1 Reply Last reply
      0
      • kajer@infosec.exchangeK kajer@infosec.exchange

        I'll just have to take comfort in knowing 300+ of my users allow this

        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchange
        wrote last edited by
        #3

        @kajer
        You're right @Sempf, we need to get rid of browsers.

        sempf@infosec.exchangeS 1 Reply Last reply
        0
        • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

          @kajer
          You're right @Sempf, we need to get rid of browsers.

          sempf@infosec.exchangeS This user is from outside of this forum
          sempf@infosec.exchangeS This user is from outside of this forum
          sempf@infosec.exchange
          wrote last edited by
          #4

          @FritzAdalis @kajer you know I'm not saying. I'm just saying.

          1 Reply Last reply
          0
          • kajer@infosec.exchangeK kajer@infosec.exchange

            Um... How about NO.

            WTF?

            Link Preview Image
            jesstheunstill@infosec.exchangeJ This user is from outside of this forum
            jesstheunstill@infosec.exchangeJ This user is from outside of this forum
            jesstheunstill@infosec.exchange
            wrote last edited by
            #5

            @kajer I have seen a case where that is required. Basically, your loopback address is also your local network. So if it's talking to an endpoint agent or local service for some reason, it needs those permissions in order to talk via loopback. It freaked us out with Okta a while back.

            kajer@infosec.exchangeK 1 Reply Last reply
            0
            • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

              @kajer I have seen a case where that is required. Basically, your loopback address is also your local network. So if it's talking to an endpoint agent or local service for some reason, it needs those permissions in order to talk via loopback. It freaked us out with Okta a while back.

              kajer@infosec.exchangeK This user is from outside of this forum
              kajer@infosec.exchangeK This user is from outside of this forum
              kajer@infosec.exchange
              wrote last edited by
              #6

              @JessTheUnstill I have seen that behavior in things like DUO device health, where the DUO MFA page connects to the localhost instance to pull the device posture json file...

              I have NEVER seen GMAIL ask for that. Point is, denied.

              jesstheunstill@infosec.exchangeJ 1 Reply Last reply
              0
              • kajer@infosec.exchangeK kajer@infosec.exchange

                @JessTheUnstill I have seen that behavior in things like DUO device health, where the DUO MFA page connects to the localhost instance to pull the device posture json file...

                I have NEVER seen GMAIL ask for that. Point is, denied.

                jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                jesstheunstill@infosec.exchange
                wrote last edited by
                #7

                @kajer Yeah certainly. I suppose it could also be the Google workspace MDM? https://workspace.google.com/intl/en_uk/products/admin/endpoint/

                kajer@infosec.exchangeK 1 Reply Last reply
                0
                • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

                  @kajer Yeah certainly. I suppose it could also be the Google workspace MDM? https://workspace.google.com/intl/en_uk/products/admin/endpoint/

                  kajer@infosec.exchangeK This user is from outside of this forum
                  kajer@infosec.exchangeK This user is from outside of this forum
                  kajer@infosec.exchange
                  wrote last edited by
                  #8

                  @JessTheUnstill Maybe?

                  There are two possibilities if it is.

                  1. Chrome did an update that may have added a new permission dialog.
                  2. Workspace MDM added a new "feature."

                  Our org has used workspace based mdm for YEARS and never once has that dialog popped for me until today.

                  jesstheunstill@infosec.exchangeJ 1 Reply Last reply
                  0
                  • kajer@infosec.exchangeK kajer@infosec.exchange

                    @JessTheUnstill Maybe?

                    There are two possibilities if it is.

                    1. Chrome did an update that may have added a new permission dialog.
                    2. Workspace MDM added a new "feature."

                    Our org has used workspace based mdm for YEARS and never once has that dialog popped for me until today.

                    jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                    jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                    jesstheunstill@infosec.exchange
                    wrote last edited by
                    #9

                    @kajer both possible.

                    kajer@infosec.exchangeK 1 Reply Last reply
                    0
                    • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

                      @kajer both possible.

                      kajer@infosec.exchangeK This user is from outside of this forum
                      kajer@infosec.exchangeK This user is from outside of this forum
                      kajer@infosec.exchange
                      wrote last edited by
                      #10

                      @JessTheUnstill looks like the permission flag was added later 2025, so chances are a mail I got had an internal IP address or something... or my DNS filters resolved a name to a local address (internal domain stuff possible)

                      huh

                      1 Reply Last reply
                      0
                      • kajer@infosec.exchangeK kajer@infosec.exchange

                        Um... How about NO.

                        WTF?

                        Link Preview Image
                        charlesh@infosec.exchangeC This user is from outside of this forum
                        charlesh@infosec.exchangeC This user is from outside of this forum
                        charlesh@infosec.exchange
                        wrote last edited by
                        #11

                        @kajer I’ve been seeing that in Edge at work, but not at home. It is a bit frightening not knowing why… Figured it must be related to device management and calling home to tattle about TLS page content, but not sure. Around the same time I started getting browser toasts from Microsoft Purview when I pasted text in websites…

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.infosec.exchange shared this topic
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups