5 ms·
Of course they're used for security -- VPNs are a hassle for users and admins, it'd be easier for everyone (except security!) if all internal apps were just pub
by lwf 7y ago
Of course they're used for security -- VPNs are a hassle for users and admins, it'd be easier for everyone (except security!) if all internal apps were just public on the internet.
VPNs are a band-aid / work-around for "we don't have strong authentication and authorization on all services". That's fine, not everyone can do the latter, and they can provide some safety v.s. the anonymous attacker case. But too often they lure IT environments into a false sense of security.
- kirbypineapple 7y agoYou're ignoring the reality that most enterprise software is a tire fire (from a security standpoint) and that it's not feasible to secure hundreds (or even dozens!) of enterprise apps. VPN's are the enabler that ensures status quo remains.
- stjohnswarts 7y agoCan you propose an alternative solution?
- lwf 7y agoI agree — band-aids aren't per-se a bad thing. However, a VPN isn't the ideal end state. Even if you can't modify the underlying application, the goal should be "wrap in a reverse-proxy that handles authn / some-amount-of-authz so you can minimise the risk". VPNs handle network security, but don't protect you against an attacker able to compromise an endpoint in your corporate environment.
- morpheuskafka 7y agoSome protocols/services are designed with a local network in mind and would require modifications to work on the internet. A VPN is invisible to the apps and can easily save a lot of work in a large IT environment with numerous internal services.
- generatorguy 7y agoHow is a local network different from the internet, presuming there is no firewall or nat between the client and the server ?
- cwyers 7y agoOn a local network, you make the assumption that there are only authorized users.
- bayindirh 7y agoUh oh, that assumption is a big no no.
- gsich 7y agodepends
- bayindirh 7y agoCan you elaborate? Honestly asking.
- labawi 7y agoI wouldn't recommend it with PCs, notebooks, phones, random crapware, but: When you control¹ all the devices on the network, the network is small enough and the danger from the non-authenticated protocols isn't too high, then I would say it is reasonable to assume being present in the network is sufficient authentication. Not saying it could not be improved, but there are probably many more pressing concerns. ¹ you don't fully control anything anymore, but you're not going to fix that either.
- bayindirh 7y agoThanks a lot. That gave some perspective. I'll keep that in mind.
- fulafel 7y agoYep, using VPNs makes the organisation lazy in security. But insecure apps in a "company internal network" is still not ok IMO. In the exceptional cases that you can't fix, the way to go is separate dedicated environments for the risky apps, and disconnected from central services.