4 ms·
> It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly. See https://cloud.google.com/
by pathseeker 6y ago
> It is my impression that modern companies that care about security assume that all networks are compromised and act accordingly. See https://cloud.google.com/beyondcorp https://cloud.google.com/beyondcorp as an example.
No, you assume the network can be compromised like any other device in the system. You still defend the network and add in layers of access control. Employees of Google still use VPNs to connect into sensitive networks.
With the prevalence of 0-days and demonstration of usage by nation-state actors, you have to have multiple layers of defense to try to have any reasonable chance of preventing a compromise.
- taldo 6y ago> Employees of Google still use VPNs to connect into sensitive networks. Not really. Maybe the people that keep BeyondCorp-related systems running, if at all. There are VPNs, obviously, but not directly accessed by 99.9% of employees.
- panopticon 6y ago> There are VPNs, obviously, but not directly accessed by 99.9% of employees. Requesting VPN access is trivial, and it's used heavily in some large teams for pretty banal engineering workflows (i.e., not maintaining BeyondCorp or anything).
- sukilot 6y agoBeyondCorp is essentially a VPN but a different structure. That puts security on all the machine nodes. It's more secure than a VPN because it doesn't have a gooey center being a single entry point.
- thephyber 6y agoCalling it a VPN muddies the point you are tying to make. People think of a VPN as a secure perimeter (like a thick ship's hull), but BeyondCorp is layered security (like the many smaller compartments within a ship that can be isolated in case of a hull breach).