4 ms·
Partially agree, but the world is a big place. Lots of random internal resources do exist, even at big companies. Internal resources are owned by many separat
by pquerna 9y ago
Partially agree, but the world is a big place. Lots of random internal resources do exist, even at big companies.
Internal resources are owned by many separate teams. They implement AuthN / AuthZ on their own. Resources might prompt for a username & password and then do an LDAP Bind with them, or they might have a local database, or they might use an SSO/SAML, or any other number of mechanisms.
Resource owners want to move fast, they want new internal apps. Central IT/Security wants to add WAFs, 2FA, centralized logging, and all kinds of other controls.
The BeyondCorp model moves these responsibility to an easier to deploy model. It's now centralized as a service, rather than each internal app needing to buy 5 security appliances that they are required to put in their rack.
- dboreham 9y agoNo disagreement on all that. More layers of security are generally better. The places I worked generally had a centralized SSO service and a strong security team that would hunt down and kill services deployed without authentication.