70 karma · joined July 28, 2017
My experience has been that most desktop IT teams don't have the resources to fine-tune browser configs on endpoints around things like corporate web filtering proxies so they just jam the cert in the OS store and call it a day. You can use Chrome, IE, or Firefox if you know how to get and import the cert (which most users do not). Sometimes users would submit tickets saying they wanted to use Firefox but couldn't get to any web pages, to which the IT team would reply "We don't support Firefox, use Chrome or IE" and that was that.
People can disagree all they want about SSL interception in a corporate environment (for good reason), but it's here to stay. When a corporate user downloads Firefox, tries to simply go to Google and gets a cert error page, they're just going to go back to Chrome because the process of exporting your company's CA cert and then importing it into Firefox so you can use the browser is just simply not feasible for most users.
I follow some of the executives of the company I work at (we have an open office) and they are constantly posting pictures of "teamwork and collaboration" that just have a bunch of people standing around each others desks talking. They see all the movement and noise and they love that it seems like everybody is hard at work, collaborating and discussing problems etc. But if you look a little closer, the people doing actual work are hunched over their desks with huge headphones on, and everybody standing around are either not talking about anything related to work or they are rehashing discussions that have already happened over IM/email/meetings. I expressed to my manager that I had a hard time working in this environment and would like the chance to work from home a more often but was dismissed because he "likes the open office" and our management has the view that if you are working from home you probably aren't working.
The other big thing to note is that a lot of companies have security teams solely to meet audit requirements. If you find yourself on a team like that, you'll be spending a lot of time just gathering evidence for audits, remediating findings and writing policy. I really loved security intellectually, but in practice, the blue-team side of things wasn't my cup of tea.