3 ms·
Does it though? Using a VPN for access to internal infrastructure doesn't mean said internal infrastructure is insecure or authless itself. As in, defense in la
by w7 6y ago
Does it though? Using a VPN for access to internal infrastructure doesn't mean said internal infrastructure is insecure or authless itself. As in, defense in layers.
- hnzix 6y agoExactly, assume zero trust but VPN with MFA provides another layer of security. Given the weekly volume of package vulns Github notifies me about I don't want to miss a 0day and get scanned. Perimeterless is fine if you're only using SaaS or you have an army of SecOps, but I don't want an internal app rumbled.
- VectorLock 6y agoIs a VPN a suitable replacement for good security hygiene and vulnerability management?
- hnzix 6y agoNobody is saying VPN is a replacement. Users should still have to authenticate against an IDP once they're inside the perimeter. VPN + MFA protects apps from drive-by attacks while they're waiting to be patched. Yes, in a perfect world everyone would have an army of SecOps ninjas pentesting and patching all systems 24/7, but this is the Real World™ Defence in depth.