3 ms·
Actually, Google professes in their "BeyondCorp" security model a zero-trust architecture. You shouldn't be assuming that just because your instance isn't publ
by coleca 7y ago
Actually, Google professes in their "BeyondCorp" security model a zero-trust architecture. You shouldn't be assuming that just because your instance isn't publicly accessible that it is secure. (See: https://cloud.google.com/beyondcorp/ https://cloud.google.com/beyondcorp/)
Which makes this move even more surprising, because GCP reference architectures have traditionally been focused around public facing Internet access. Unless, it is a sign that GCP is getting more traction and Google is running out of public IPs to be handing out like candy. This could be an economic incentive to encourage people to conserve these IPs.
- nixgeek 7y agoZero-trust architecture seem nice idea, and one you can implement when you’re Google and probably spend more on security than the gross revenue of most other companies reading your whitepaper. I think the notion most infrastructure is not publicly addressed is prevalent, even in Google, i.e. you can’t SSH to the hypervisor hosting customer instances in GCP directly, it doesn’t have SSH sat on the public internet. Public addresses are readily available on the secondary market but a /12 probably runs somewhere around $20MM. Charging for IPv4 seems like a move designed to make all the smallest customers who care about $3/mo leave, GCP ends up with less customers and ARPU goes up probably significantly.
- theptip 7y agoIf you use IAP (Google's BeyondCorp secure proxy product) then your instances don't have a public IP; they are behind a firewall rule. Also there is a big difference between BeyondCorp's "all internal services are on the public internet" and "all instances are on the internet". You don't want to put your DB server on the internet, for example.
- nodesecurity 7y agoThis is not what BeyondCorp means. It doesn't mean everything is publicly accessible. It means you don't make trust decisions based on "approved networks", but instead at the device level. It DOES NOT mean that you don't segment services, restrict access to systems that don't need public access, or follow any of the other appropriate security guidelines. > You shouldn't be assuming that just because your instance isn't publicly accessible that it is secure No one thinks this, and no one said anything of the sort. But likewise, making everything public because Google has a site called BeyondCorp, doesn't make it secure. There is a lot of effort to adopt a BeyondCorp model. None of which includes "make everything publicly routable".