Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Um... How about NO.

Um... How about NO.

Scheduled Pinned Locked Moved Uncategorized
11 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • kajer@infosec.exchangeK kajer@infosec.exchange

    Um... How about NO.

    WTF?

    Link Preview Image
    kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchangeK This user is from outside of this forum
    kajer@infosec.exchange
    wrote last edited by
    #2

    I'll just have to take comfort in knowing 300+ of my users allow this

    fritzadalis@infosec.exchangeF 1 Reply Last reply
    0
    • kajer@infosec.exchangeK kajer@infosec.exchange

      I'll just have to take comfort in knowing 300+ of my users allow this

      fritzadalis@infosec.exchangeF This user is from outside of this forum
      fritzadalis@infosec.exchangeF This user is from outside of this forum
      fritzadalis@infosec.exchange
      wrote last edited by
      #3

      @kajer
      You're right @Sempf, we need to get rid of browsers.

      sempf@infosec.exchangeS 1 Reply Last reply
      0
      • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

        @kajer
        You're right @Sempf, we need to get rid of browsers.

        sempf@infosec.exchangeS This user is from outside of this forum
        sempf@infosec.exchangeS This user is from outside of this forum
        sempf@infosec.exchange
        wrote last edited by
        #4

        @FritzAdalis @kajer you know I'm not saying. I'm just saying.

        1 Reply Last reply
        0
        • kajer@infosec.exchangeK kajer@infosec.exchange

          Um... How about NO.

          WTF?

          Link Preview Image
          jesstheunstill@infosec.exchangeJ This user is from outside of this forum
          jesstheunstill@infosec.exchangeJ This user is from outside of this forum
          jesstheunstill@infosec.exchange
          wrote last edited by
          #5

          @kajer I have seen a case where that is required. Basically, your loopback address is also your local network. So if it's talking to an endpoint agent or local service for some reason, it needs those permissions in order to talk via loopback. It freaked us out with Okta a while back.

          kajer@infosec.exchangeK 1 Reply Last reply
          0
          • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

            @kajer I have seen a case where that is required. Basically, your loopback address is also your local network. So if it's talking to an endpoint agent or local service for some reason, it needs those permissions in order to talk via loopback. It freaked us out with Okta a while back.

            kajer@infosec.exchangeK This user is from outside of this forum
            kajer@infosec.exchangeK This user is from outside of this forum
            kajer@infosec.exchange
            wrote last edited by
            #6

            @JessTheUnstill I have seen that behavior in things like DUO device health, where the DUO MFA page connects to the localhost instance to pull the device posture json file...

            I have NEVER seen GMAIL ask for that. Point is, denied.

            jesstheunstill@infosec.exchangeJ 1 Reply Last reply
            0
            • kajer@infosec.exchangeK kajer@infosec.exchange

              @JessTheUnstill I have seen that behavior in things like DUO device health, where the DUO MFA page connects to the localhost instance to pull the device posture json file...

              I have NEVER seen GMAIL ask for that. Point is, denied.

              jesstheunstill@infosec.exchangeJ This user is from outside of this forum
              jesstheunstill@infosec.exchangeJ This user is from outside of this forum
              jesstheunstill@infosec.exchange
              wrote last edited by
              #7

              @kajer Yeah certainly. I suppose it could also be the Google workspace MDM? https://workspace.google.com/intl/en_uk/products/admin/endpoint/

              kajer@infosec.exchangeK 1 Reply Last reply
              0
              • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

                @kajer Yeah certainly. I suppose it could also be the Google workspace MDM? https://workspace.google.com/intl/en_uk/products/admin/endpoint/

                kajer@infosec.exchangeK This user is from outside of this forum
                kajer@infosec.exchangeK This user is from outside of this forum
                kajer@infosec.exchange
                wrote last edited by
                #8

                @JessTheUnstill Maybe?

                There are two possibilities if it is.

                1. Chrome did an update that may have added a new permission dialog.
                2. Workspace MDM added a new "feature."

                Our org has used workspace based mdm for YEARS and never once has that dialog popped for me until today.

                jesstheunstill@infosec.exchangeJ 1 Reply Last reply
                0
                • kajer@infosec.exchangeK kajer@infosec.exchange

                  @JessTheUnstill Maybe?

                  There are two possibilities if it is.

                  1. Chrome did an update that may have added a new permission dialog.
                  2. Workspace MDM added a new "feature."

                  Our org has used workspace based mdm for YEARS and never once has that dialog popped for me until today.

                  jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                  jesstheunstill@infosec.exchangeJ This user is from outside of this forum
                  jesstheunstill@infosec.exchange
                  wrote last edited by
                  #9

                  @kajer both possible.

                  kajer@infosec.exchangeK 1 Reply Last reply
                  0
                  • jesstheunstill@infosec.exchangeJ jesstheunstill@infosec.exchange

                    @kajer both possible.

                    kajer@infosec.exchangeK This user is from outside of this forum
                    kajer@infosec.exchangeK This user is from outside of this forum
                    kajer@infosec.exchange
                    wrote last edited by
                    #10

                    @JessTheUnstill looks like the permission flag was added later 2025, so chances are a mail I got had an internal IP address or something... or my DNS filters resolved a name to a local address (internal domain stuff possible)

                    huh

                    1 Reply Last reply
                    0
                    • kajer@infosec.exchangeK kajer@infosec.exchange

                      Um... How about NO.

                      WTF?

                      Link Preview Image
                      charlesh@infosec.exchangeC This user is from outside of this forum
                      charlesh@infosec.exchangeC This user is from outside of this forum
                      charlesh@infosec.exchange
                      wrote last edited by
                      #11

                      @kajer I’ve been seeing that in Edge at work, but not at home. It is a bit frightening not knowing why… Figured it must be related to device management and calling home to tattle about TLS page content, but not sure. Around the same time I started getting browser toasts from Microsoft Purview when I pasted text in websites…

                      1 Reply Last reply
                      1
                      0
                      • R relay@relay.infosec.exchange shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups