3 ms·
Yes turn keys over to Google. I am sure if you are an American Fortune 500 company you have no problem with this. Not so if you are a non-American company. Thou
by devoply 9y ago
Yes turn keys over to Google. I am sure if you are an American Fortune 500 company you have no problem with this. Not so if you are a non-American company. Though a lot of people will jump on board despite the huge security implications of doing something like this and turning over all your security over to Google. Meanwhile nation states are exploring how to use quantum encryption to prevent eaves dropping others are being coerced to simply hand over security to a third party that you hardly trust with any sense of privacy.
- magicalist 9y agoIt seems from the article this is only being offered as a product to people already using Google Cloud services, specifically for accessing those services? Otherwise it's just a series of papers describing the system.
- briffle 9y agoMuch like 'bigtable' was a google internal product, and only published a set of papers describing the system, and now we have hbase.. Or how 'mapreduce' was a google internal product, and now we have hadoop, etc.
- wmf 9y agoCalling it "Google BeyondCorp" makes it sound like a product; maybe if they called it something like "BeyondCorp architecture" it would be clearer what they're talking about.
- maxsaltonstall 9y agoYou're right, the initial version of Identity-Aware Proxy (IAP) is for Cloud applications, but that's not the end of the story, and we're learning from BeyondCorp's 7 year journey to inform the direction of IAP going forward. [I work at Google, and helped make these papers, and blog post, happen]
- fortyfivan 9y agoThanks for sharing through the papers and posts, they've been incredibly informative. Keep up the good work!
- mikecb 9y agoWhen are we going to hear about further contextual auth capabilities coming to IAP? It's awesome.
- puzzle 9y agoHow do you use IAP with GKE?
- mikecb 9y agoHaven't tried yet myself, but since the ingress resource is just an https load balancer, enable IAP on that. Like so: https://medium.com/@DazWilkin/google-cloud-iap-and-gke-c773da56c3cf https://medium.com/@DazWilkin/google-cloud-iap-and-gke-c773d... Edit more direct: https://cloud.google.com/iap/docs/container-engine-quickstart https://cloud.google.com/iap/docs/container-engine-quickstar...
- manigandham 9y agoIt's a way of doing things, nothing specific to Google. Use any authentication/identity service and publish all internal services as public apps, consolidating access, increasing security, and simplifying maintenance.