4 ms·
I think there’s two points of view here. On the one hand yes, if someone gets into your castle then they may have a lot of access you don’t want to give them. H
by code4tee 9y ago
I think there’s two points of view here. On the one hand yes, if someone gets into your castle then they may have a lot of access you don’t want to give them. However that assumes that things inside these walls are also not secured, which is often not the case.
The other point of view is that the castle wall gives you added protection against unknown unknowns that could mean there are security issues with your now public facing infrastructure. By just exposing everything publicly you create this potential big risk. Google’s preaching here glosses over this fact.
- nkassis 9y agoIt's not quite removing the walls, think of it more as a ton of tiny castles dotting the landscape with equally good walls instead of one giant wall around the kingdom and some unprotected wooden huts inside. By doing this they want to force those managing internal apps to put up protection on the level they would for any other external service. Overall it's leading to better security (at least that's what they argue).
- Florin_Andrei 9y ago> that assumes that things inside these walls are also not secured, which is often not the case I've operated under the old castle doctrine for many years. It is my experience that in the vast majority of places, once the wall of VPN / packet filtering has gone up, people suddenly relax and forget about internal patches. There are exceptions, but they are uncommon.