28 ms·
How to use BeyondCorp to ditch VPN, improve security and go to the cloud
- metalliqaz 9y agoInteresting. This will never happen at my big company, though. Seems hard to imagine most companies being able to manage the complexity.
- wmf 9y agoYou never know. SaaS is kind of a gateway drug to BeyondCorp since SaaS isn't inside the firewall to begin with. The next step is to start applying a SaaS mindset to your own internal apps and then you're mostly there.
- fulafel 9y agoTrying to secure a traditional corporate "intranet" while enabling productive work is much harder. This is just branded common sense end to end security.
- cosarara97 9y agoSo google bought the .google TLD!
- hamandcheese 9y agoThis is not news: https://news.ycombinator.com/from?site=blog.google https://news.ycombinator.com/from?site=blog.google
- cosarara97 9y agoOh well, no way to delete my comment now.
- yegle 9y agoMy ex-manager who left Google to another well established company once said the most missed thing from Google was the ability to work remotely right away on corp laptop with BeyondCorp. Disclaimer I work for Google not related to BeyondCorp.
- izacus 9y agoI thought Google doesn't allow remote work?
- michaelbuckbee 9y agoRemote meaning on the Google Bus on the way to the office.
- mikejmoffitt 9y agoI don't know why people are negatively marking your post, because this is a thing a lot of people do and it does feel like there is a bit of a stigma to do so.
- matttproud 9y agoOr working on the boat, as we at Google Zürich do: http://goo.gl/P9CA69 http://goo.gl/P9CA69 Or working on the train: http://goo.gl/mPZKcc http://goo.gl/mPZKcc
- sumitgt 9y agoWell, even if you don't work remotely, you routinely need to access corp resources from outside office.
- wsetchell 9y agoOn my team (and most other teams) it is cool to work from home or a different office occasionally.
- Kurtz79 9y agoRemote work can be intended also as in "you are at a customer facility and need to access the corporate intranet to get a document or access the SW repository".
- deleted 9y ago[deleted]
- devoply 9y agoYes turn keys over to Google. I am sure if you are an American Fortune 500 company you have no problem with this. Not so if you are a non-American company. Though a lot of people will jump on board despite the huge security implications of doing something like this and turning over all your security over to Google. Meanwhile nation states are exploring how to use quantum encryption to prevent eaves dropping others are being coerced to simply hand over security to a third party that you hardly trust with any sense of privacy.
- magicalist 9y agoIt seems from the article this is only being offered as a product to people already using Google Cloud services, specifically for accessing those services? Otherwise it's just a series of papers describing the system.
- briffle 9y agoMuch like 'bigtable' was a google internal product, and only published a set of papers describing the system, and now we have hbase.. Or how 'mapreduce' was a google internal product, and now we have hadoop, etc.
- wmf 9y agoCalling it "Google BeyondCorp" makes it sound like a product; maybe if they called it something like "BeyondCorp architecture" it would be clearer what they're talking about.
- maxsaltonstall 9y agoYou're right, the initial version of Identity-Aware Proxy (IAP) is for Cloud applications, but that's not the end of the story, and we're learning from BeyondCorp's 7 year journey to inform the direction of IAP going forward. [I work at Google, and helped make these papers, and blog post, happen]
- fortyfivan 9y agoThanks for sharing through the papers and posts, they've been incredibly informative. Keep up the good work!
- JoshMnem 9y agoYesterday, I saw an article[1] about Amazon's plans to block websites in their stores (a very bad thing) and was wondering when a company like Google was going to launch a VPN service. I wonder if these things will meet in the long term. If companies that control the network try to limit access to information about their competitors, then their competitors might try to liberate that information. [1] http://gizmodo.com/just-in-time-amazon-patents-method-to-prevent-comparis-1796195563 http://gizmodo.com/just-in-time-amazon-patents-method-to-pre...
- oh_sigh 9y agoThat's a patent, there is no indication Amazon has any plans to do such a thing.
- JoshMnem 9y agoI know -- that's why I used the phrase "long-term". :) I probably shouldn't have used the word "plans" though, since I don't know for sure if they will implement it.
- Aloha 9y agoThey very well could have patented it to prevent anyone else from doing it - which seems more likely.
- akl 9y agoAmazon employees are encouraged to patent basically anything, at least in AWS. Validity of content or relevance to future business plans isn't really a factor.
- JoshMnem 9y agoIt's probably a combination of defensive and opportunistic. Companies stake out positions and then watch how the winds blow.
- deleted 9y ago[deleted]
- fortyfivan 9y agoGreat to see them continue this series, and glad that this one touches on what it takes for other companies to achieve something similar. I talk about BeyondCorp a lot as evidence that the Zero Trust model works, and that employees will love it. The most common feedback I get is that it seems like too much of a stretch for companies that don’t operate at Google scale. That may be true if looking at the system as a whole, but the principles behind the architecture should attract anyone’s attention - remove trust from the network by authenticating and authorizing every request based on what’s known about the user and connecting device at the time of the request. Disclaimer: I work for ScaleFT, a provider of Zero Trust access management solutions. Edit: If folks are interested in hearing more about how other companies can achieve something similar, here's video of a talk I gave at Heavybit a few months ago on the subject: https://www.heavybit.com/library/blog/beyondcorp-meetup-google-security-for-everyone-else/ https://www.heavybit.com/library/blog/beyondcorp-meetup-goog...
- api 9y agoThe major barrier is really for companies that lack a lot of internal IT expertise. It's really dangerous for people who don't understand security and networking to just open up like this, since most enterprise software is grotesquely insecure out of the box. Everyone assumes LAN = safe = no need to worry about security. This is always false, but it's especially false if you're devolving away from LAN.
- fortyfivan 9y agoVery true... the "ditch your VPN" sure is a nice soundbite, but in reality it's the last thing you should be doing. I mean that literally... as in it's the last step. Better know what you're doing before getting there. The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and understanding the traffic. But the real point they make is that Internet != safe = very much worry about security.
- johnmaguire2013 9y ago
- madjam002 9y agoHow is this different or more secure than let's say TLS client authentication with the private key on a smart card / Yubikey?
- DorothySim 9y agoThey also take into account the state of the machine you're working on. So locked bootloader and probably a client cert in TPM-like component, plus "device health". Client certs alone are good for authentication (don't work in HTTP/2 though) but they want to reach even better target - no malicious software running on your computer. That's from reading old papers, I don't know if anything changed now.
- maxsaltonstall 9y agoThat's correct. Previous papers touch on the inventory data pipeline and machine health, though without as much detail as I might like in your shoes. Our agents track a wide variety of things on client machines, and we use that inventory data to determine how trustworthy a machine could be. [I work at Google, and helped make these papers, and blog post, happen]
- DorothySim 9y agoInteresting design. As far as I understood from old papers client certificates are used only to identify the device while user authentication is handled differently. Could you elaborate on the technical details on user authentication? (If that's not top-super-secret) I guess it's just like accounts.google.com for Enterprise with mandatory 2FA (username+password+U2F key?). Does it work the same on mobile/Android (U2F via NFC or codes)?
- weeks 9y agoAndroid supports U2F via NFC and Bluetooth now, which is used for user authentication on Android devices. We've also released an (experimental?) iOS app to support U2F over Bluetooth. https://itunes.apple.com/us/app/google-smart-lock/id1152066360 https://itunes.apple.com/us/app/google-smart-lock/id11520663...
- com2kid 9y agoWith productivity apps being cloud hosted (Office 365, Google Docs, Tableau, PowerBI, etc) and with source code and team management services being hosted (Github, Visual Studio Online, Gitlab, etc) huge percent of people's day to day work can seemingly happens without a VPN. The largest notable exceptions seem to be internal file shares, and remote connections to machines that need to be behind a firewall. I guess the overall point I have is that with the data files for both productivity and source code being stored cloud side, that VPNs become less and less necessary for a large % of workers.
- dylz 9y agoGH/Gitlab are usually behind VPN for non-startups
- sooper 9y ago"The largest notable exceptions seem to be internal file shares, and remote connections to machines that need to be behind a firewall." Office 365 / OneDrive and Google Drive are even doing away with the requirement for internal fileshares. We used the former heavily at my previous job and I use the latter in my current role. Both have been pretty good alternatives.
- whyagaindavid 9y agoI am looking for ideas to control hardware connrcted to PC. We use vnc-viewer now. Can beyondcorp help here?
- api 9y agoThis is really awesome. My own venture ZeroTier (www.zerotier.com) was strongly influenced by the original BeyondCorp paper. Our vision is a little different in that we do network virtualization that treats the whole world like one data center. Instead of eliminating the LAN you make it fully virtual and mobile and replace the physical perimeter with a cryptographic one. Here's a somewhat over-simplified TL;DR on Google's approach: Make everything in your company a SaaS app that lives on the Internet via cloud hosting or a proxy. Nice but not always readily do-able.
- AnthonBerg 9y agoZeroTier is amazing. I tell everyone about it.
- rkrzr 9y agoThank you for creating ZeroTier. It is really awesome. It's so much simpler to setup than e.g. OpenVPN and the peer-to-peer architecture also makes a lot more sense to me.
- coverband 9y agoIs there a link to the actual (fourth) paper? I only see the abstract.
- maxsaltonstall 9y agoWorking on that now, I think I messed up on my end with our internal tool, hope to have the full PDF download from research.google.com in a day or two, maybe next week if I epic failed. [I work at Google, and helped make these papers, and blog post, happen]
- medina 9y ago& add cross-link to things like google/huproxy ?
- manigandham 9y agoThis seems so completely obvious that it's surprising how common intranets and internal services locked only by network rules are. Also highly recommend https://www.scaleft.com/ https://www.scaleft.com/ for anyone who wants beyondcorp-style access to infrastructure.
- mtgx 9y agoDuo Security seems to be offering a BeyondCorp-like third-party solution for client companies: https://duo.com/pricing/duo-beyond https://duo.com/pricing/duo-beyond
- johnmaguire2013 9y agoI work for Duo Security, which this year launched the first major commercial implementation of BeyondCorp as a part of our product offering. Using it to jump on to the wiki, for diff reviews, and other internal resources has been excellent. In addition to simple primary and second factor, you can design policies for MDM-controlled devices only (i.e. designing endpoints that are trusted for remote access), geolocation, and software versions on a per-application basis, for example. I think save for a few use cases (SSH into your datacenter, e.g.), VPNs will be dead before we know it.
- thomashabets2 9y agoVPNs will remain because of SSH, eh? https://github.com/google/huproxy https://github.com/google/huproxy
- johnmaguire2013 9y agoI think you misunderstood. My point is that you will still need direct access into the network in order to work on the BeyondCorp servers themselves, for example -- not that SSH shouldn't, or couldn't, be covered under the zero trust model as well.
- thomashabets2 9y agoMaybe. Are you saying that "the bootstraps" (panic access) is VPN? Why isn't the first level just an open SSH port? I'm not sure why "when all else fails" is better left a VPN port than an SSH port. I'd say SSH infrastructure (a server with only pubkey login, maybe behind TCP-MD5 and/or heavily filtered source addresses) is probably more reliable and safer than a VPN.
- johnmaguire2013 9y agoWith a VPN you have two security layers -- one into the network, and a second one into each individual server. They aren't mutually exclusive. Sure, you can leave SSH open publicly on WAN. I wouldn't for anything mission-critical.
- rayvd 9y agoDumb question - is the 4th article in the series only available via ;login;[1]? The other articles in the series have PDF links, but not the latest one. I'm assuming it will eventually... [1] https://www.usenix.org/publications/login/summer2017/peck https://www.usenix.org/publications/login/summer2017/peck
- maxsaltonstall 9y agoI think that was my mistake, the PDF is in the pipeline, expect it live within a week.
- maxsaltonstall 9y agoBlog post now links to downloadable PDF
- zxv 9y agoPart 3 [0] discusses "Wrapping SSH traffic in HTTP over TLS." Can one comfortably do coding over a good cellular (LTE) connection over this? I ask because, I find it relatively comfortable to do coding on a chromebook over a 'mosh' session over LTE. [0] https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/45728.pdf https://static.googleusercontent.com/media/research.google.c...
- londons_explore 9y agoTo get good performance, one would need a BeyondCorp enabled mosh proxy. With plain SSH over HTTP over TLS, performance is satisfactory but not great. 4G is just about usable for vim, but you'd probably be best off using sshfs over http over tls and running vim locally, then compiling and running remotely.
- e12e 9y agoGit/mercurial over ssh and preform actions on push?
- brandon 9y agoThe actual framing is WebSockets over TLS once the session is established and the latency is no worse than SSH over VPN practically speaking. The protocol also supports session resumption in case your connection to the relays is briefly interrupted, but client support is buggy so it's been disabled for years (with few complaints)
- obstinate 9y agoYes, although I tend to use SSHFS and a local editor. Even a cellular quality connection is not required. It works fine from an airplane.
- ransom1538 9y agoSorry this will come off as a super dumb question. I use ssh. I can login, edit, develop, run, basically anything. What am I missing? I thought VPNs are for 'admin' types that need access to a MS Excel file.
- justabystander 9y agoThe VPN changes your network route. This can get you around geographic locks (services that only work in certain areas). It can also get you around traffic issues, if your ISP has technical/political routing issues. Like with Comcast/Verizon refusing to add additional peering because they wanted to double-bill netflix traffic. Some VPN services also advertise additional privacy or anonymity, but trusting a stranger to not sell you out to their local government isn't usually a good idea. From a business standpoint, you may want web and network services without exposing them to the wider internet. So they're only accessible on IPs in local subnets. VPNs will get you inside the wall.
- deleted 9y ago[deleted]
- rsync 9y ago"I use ssh. I can login, edit, develop, run, basically anything. What am I missing?" You're not missing anything and you have an extremely efficient and secure workflow that runs laps around any of this. The tradeoff is you work in a terminal and understand SSH, etc., which is too much to ask of many non-technical users. If you wanted to obfuscate your traffic or the direct path to your remote host was blocked for some reason, a VPN might get you there, but you'd still run SSH over that VPN and your workflow should remain unaltered (albeit, higher latency). To address a sibling posts comment, you can enjoy this very same workflow without exposing your sshd to the global Internet by placing it behind a "knock" with knockd. Highly recommended.
- gerdesj 9y agossh can be used as a VPN - you can proxy ports and tunnel all sorts of things through it. You can easily drill a connection through to say an "internal" Windows or NFS file server and grab docs off it. There is file transfer built in as well eg sftp and scp, with easy rsync integration. It doesn't really matter whether you use ssh, RDP or whatever for remote system access but you should be aware of the capabilities of your methods and the strengths and weaknesses of them. If your username and password are reasonably hard to guess, and ideally you use passwordless logins, and you keep your system regularly patched, and you definitely don't allow remote root logins, and you cycle your passwords say 90 days or so, then you should be fine. Do not bother changing port 22 to say 2222 or requiring 20+ char passwords. You may want to disable some of sshd's functionality if you don't use it but that might be a step too far. Also, reset your sshd's keys occasionally and get them into your local ~/.ssh/known_hosts as soon as possible and read up and understand why ssh warns you when the keys and names look odd - that could save you a MitM attack from a bored techy in a hotel with wifi or whatever. To sum up: a well handled sshd and client can be a fairly decent VPN and remote access solution. However, a separate VPN eg OpenVPN and then ssh over that is better and need not be inconvenient. You pays your money .... 8)
- pamatthe 9y agoStumbled across beyondcorp.com a few months ago. Great to see google, scaleft, and others pushing the envelope here.
- brianhama 9y agoThis sounds a lot like Microsoft's DirectAccess which has been in the Enterprise version of Windows since Windows 8. Please correct me if I'm wrong though.
- brazzledazzle 9y agoKind of. Microsoft sold it more as an always-on VPN. They weren't selling a radically different philosophy for securing your network with it. But regardless of the differences Microsoft really hamstrung themselves by making it so Windows centric.
- Spivak 9y agoAt the present moment Cisco is getting our money rather than MS for our VPN specifically because our Linux users couldn't leverage DA.
- maxsaltonstall 9y agoLink the blog post now points to a downloadable PDF thanks to Google Drive.
- karlgrz 9y agoStill not seeing that.
- jgsec 9y agoI commend the Google team for not only deploying an effective and innovative security solution, but also for contributing to security community through this series of informative articles. Enterprises need to know that while BeyondCorp is Google-specific, there are similar types of open architectures that they can deploy today, most notably the Software-Defined Perimeter (SDP). SDP is an open architecture from the Cloud Security Alliance, and with it security teams can ensure that: . All users are authenticated and authorized BEFORE they can access network resources . Network resources are inaccessible to unauthorized users, dramatically reducing the attack surface . Fine-grained policies control access for all users – remote and on-premises – to all resources , whether physical, virtual, or cloud . All network traffic is encrypted, even if the underlying protocol is insecure Here’s a video of me presenting on Software-Defined Perimeter at the CSA Summit at the 2017 RSA Conference https://www.youtube.com/watch?v=ysi_9c5fmBg https://www.youtube.com/watch?v=ysi_9c5fmBg and a brief overview from our corporate site https://www.cryptzone.com/products/appgate/why-a-software-defined-perimeter https://www.cryptzone.com/products/appgate/why-a-software-de... Disclaimer: I led the CSA’s Software-Defined Perimeter working group publication of SDP-for-IaaS, and am leading the current effort to create an SDP Architecture Guide. I also work at Cryptzone, an SDP platform vendor.
- troymc 9y ago"Over the course of the migration we’ve discovered [Google] services that we thought were long dead..." Maybe some Google employees were still using Google Reader?
- macawfish 9y ago"We discovered services we thought were long dead..."
- libeclipse 9y agoWhat's wrong with VPN?
- rocqua 9y agoJust doing VPN reinforces the wrong notion that LAN == Safe.
- libeclipse 9y agoWait, that's the massive problem? Jesus. I'll stick with a VPN.
- tempodox 9y agoGoogle wants my traffic for themselves and calls it “more secure”. Ha ha, nice try.
- VectorLock 9y agoAnywhere we can read the publication without being a subscriber to LOGIN?
- angry_octet 9y agoIt almost seems like this could be described as dynamically building a per-user VPN, via inbound proxies for admission control and traffic src/dst filtering, and services hosted behind multiprotocol terminating proxies. Some extra client analysis (practically effective, even if no theoretically valid remote attestation), tedious but necessary work to understand the access patterns for all the internal services, etc. It seems there can still be lateral re-infection via difficult to patch shared services (finance/procurement/obscure wikis). The examples in one of the papers (delivery people not needing access to financial systems) is completely bogus -- sometimes the worst engineered, most xss-y, mission critical apps have to be accessed by everyone, have insanely hand coded 'business logic', and no docs. Content aware behavioral profiling would seem to have a role in managing that risk.
- ddalex 9y agoLlllklklll
- ddalex 9y agoI n k
- talles 9y agooff topic: I never noticed that there's a .google TLD...