3 ms·
Having spent a lot of time in this domain, you have to (and most seem to be coming to the same conclusion) just assume that everything that connects to your net
by windowsworkstoo 11y ago
Having spent a lot of time in this domain, you have to (and most seem to be coming to the same conclusion) just assume that everything that connects to your network is untrusted and likely owned and work inwards from there for your threat modelling.
You have to really forget about trying to secure the client (and this includes campus supplied gear) and up your monitoring game.
ISTR that Google has also taken a similar approach with its employees access to their LAN.
- jesseendahl 11y ago+1 to not trusting your network (or any network), but that doesn't mean you should give up on securing your clients if you have control over them (e.g. in a corporate environment). FWIW Google certainly does not ignore client security. They do assume that all networks are untrusted. "Google’s BeyondCorp initiative is moving to a new model that dispenses with a privileged corporate network. Instead, access depends solely on device and user credentials, regardless of a user’s network location—be it an enterprise location, a home network, or a hotel or coffee shop." "BeyondCorp uses the concept of a “managed device,” which is a device that is procured and actively managed by the enterprise. Only managed devices can access corporate applications." http://static.googleusercontent.com/media/research.google.com/en//pubs/archive/43231.pdf http://static.googleusercontent.com/media/research.google.co...
- windowsworkstoo 11y agoSure, BeyondCorp is what I was thinking of. And yes, there are a subset of devices that are managed and can be used to access higher levels of "security" but these are deliberately limited so they can be managed closely. But the underlying point was that the default position is untrusted network, untrusted clients - even for the vast majority of clients that you would otherwise consider "managed" - eg classroom computers, laptop trolleys etc