7 ms·
Great to see them continue this series, and glad that this one touches on what it takes for other companies to achieve something similar. I talk about BeyondCor
by fortyfivan 9y ago
Great to see them continue this series, and glad that this one touches on what it takes for other companies to achieve something similar. I talk about BeyondCorp a lot as evidence that the Zero Trust model works, and that employees will love it.
The most common feedback I get is that it seems like too much of a stretch for companies that don’t operate at Google scale. That may be true if looking at the system as a whole, but the principles behind the architecture should attract anyone’s attention - remove trust from the network by authenticating and authorizing every request based on what’s known about the user and connecting device at the time of the request.
Disclaimer: I work for ScaleFT, a provider of Zero Trust access management solutions.
Edit: If folks are interested in hearing more about how other companies can achieve something similar, here's video of a talk I gave at Heavybit a few months ago on the subject: https://www.heavybit.com/library/blog/beyondcorp-meetup-google-security-for-everyone-else/ https://www.heavybit.com/library/blog/beyondcorp-meetup-goog...
- api 9y agoThe major barrier is really for companies that lack a lot of internal IT expertise. It's really dangerous for people who don't understand security and networking to just open up like this, since most enterprise software is grotesquely insecure out of the box. Everyone assumes LAN = safe = no need to worry about security. This is always false, but it's especially false if you're devolving away from LAN.
- fortyfivan 9y agoVery true... the "ditch your VPN" sure is a nice soundbite, but in reality it's the last thing you should be doing. I mean that literally... as in it's the last step. Better know what you're doing before getting there. The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and understanding the traffic. But the real point they make is that Internet != safe = very much worry about security.
- johnmaguire2013 9y agoI'm not sure I understand the argument you're making here. A VPN offers you direct access to all the servers within your internal network. The BeyondCorp model offers you proxied access to only particular applications that have been opened up based on a wide variety of checks on the user and device accessing the application. How is the latter going to be less secure than opening up your entire LAN to everyone who needs to access a single resource?
- fortyfivan 9y agoThe point was that fundamentally the Internet is not safe, so companies will do the right things to secure their resources. So yes, in BeyondCorp this means running a proxy service that centralizes the auth workflow through policies that check the user and connecting device against the resource at the time of the request.
- maxsaltonstall 9y agoExactly. And because you can't be sure that the intervening network is safe, you need to encrypt all the traffic, even after checking authorization and authentication. That's the BeyondCorp mission at Google. [Disclaimer: I work for Google, and worked on these papers and blog post]
- donalhunt 9y agoThere's a good video on the topic from this year's RSA conference here: https://www.rsaconference.com/events/us17/agenda/sessions/6602-How-Google-Protects-Its-Corporate-Security-Perimeter-without-Firewalls https://www.rsaconference.com/events/us17/agenda/sessions/66...
- closeparen 9y agoThe illusion that it's okay to run cleartext, unauthenticated services on an internal network is also pretty dangerous. Making it clear that the network is out in public might actually yield a better security posture overall. If an organization is doing 802.1x, competently manages its endpoints (this is a tiny, tiny fraction of "managed" Windows sites), etc then maybe a BeyondCorp-style architecture is a net loss of security. If an attacker can waltz into a conference room or exploit some salesperson's IE6 and start making requests from the "secure" network, probably best to make it obvious that there is no secure network.
- api 9y agoI've believed this for a long time, but try re-educating two generations of IT people who think firewall equals security. It's hard enough to get them to adopt IPv6 since most think NAT is essential for security. "But my address is world reachable!" Face palm...
- jdc0589 9y agooff topic: do bastion servers in scaleFTs architecture provide any interactive-session auditing capability (e.g. gravitational teleport), or do they simply act as a bastion access tunneling tier? If you have interactive session audting.....you will be hearing from me.
- deleted 9y ago[deleted]
- fortyfivan 9y agoGreat question, and not off-topic at all ;) Our first priority in developing our bastion product was to guarantee end-to-end privacy and verifiability, so the cleartext is not available on any bastion. We do have a roadmap item to support customers' desire for visibility into team activity, but we engineered for privacy first. Our current auditing is event-based - device enrolled, credential issued, ssh/rdp login, etc. Happy to discuss our roadmap further - ivan.dwyer@scaleft.com
- jsmthrowaway 9y agoIn case anyone is unfamiliar with them, ScaleFT is a leader in this space and a team of solid folks. They took the BeyondCorp paper and model and really ran with it. Worth listening.