4 ms·
This may be a stupid question, but isn't it standard practice to require that employees use VPN? Why would they expose servers to the internet?
by valvar 6y ago
This may be a stupid question, but isn't it standard practice to require that employees use VPN? Why would they expose servers to the internet?
- vmception 6y agoAn employee could have got hacked, or defected They’re the ones getting screwed over the most here imo
- wokwokwok 6y agoPerhaps, but I’d say it’s quite hard to do this effectively when you’re using sass products. Even if you’re self hosting, and have dozens or hundreds of WFH employees, what’s the alternative? No access for anyone while you scale your VPN? Just wait while everyone pulls and pushes gigs of data over the VPN to perforce, you didn’t need that video meeting after all? You’ll get a big fat nope to that when you try to do it; this is a pretty tough challenge you’re trivialising here. Google “zero trust” as an alternative; clearly they didn’t do that properly either, but I can at least understand why they didn’t just demand everyone use a VPN. Trivial VPN use cases like people who d/l source code and have then occasional 5 person video meeting and this use case are not the same thing.
- yakubin 6y agoI've worked at two companies so far and at both SaaS things like mail, chat, videoconferencing were accessible without a VPN, but git repos, CI, development servers, basically anything self-hosted is behind a VPN. So you won't stream video for your video calls over the VPN, but the source code, logs, builds, etc. are protected by VPN.
- msh 6y agoA lot of places are skipping that because they dont have self hosted servers but is allready hosting everything in "the cloud". Like for a simplified example, if you are using google docs + gmail it does not really make sense to force the employees throught a VPN first. The companies that do it well implement something like google's beyondcorp, the bad just uses direct authentication.
- weinzierl 6y agoAt least not unusual for many companies but there are proponents of a different philosophy [1]. The idea is that drawing a clear line between outside and inside became futile and you are much better off with an approach that recognizes that fact. Their somewhat provocative slogan is: "The perimeter is dead". For those working at FAANG: Do you have a corporate VPN? Do you use it? Do you need it for your daily work? [1] https://www.usenix.org/system/files/login/articles/login_dec14_02_ward.pdf https://www.usenix.org/system/files/login/articles/login_dec...
- Arainach 6y agoAt Google: No. https://cloud.google.com/beyondcorp/ https://cloud.google.com/beyondcorp/ When I was at Microsoft, you still needed a VPN to connect to your dev machine and write code, but more and more internal services were moving to a zero-trust model that didn't require a VPN. Not sure if they've gotten there 100%, but it felt like the clear direction.
- valleyer 6y agoApple uses a VPN. Most stuff needed to get work done (version control, e-mail, bug tracker) is behind it.
- Daho0n 6y agoWell, Apple is not exactly know for being first movers in tech. I'm sure they'll refine the approach in a few years.
- ryandrake 6y agoYea, your threat model needs to include machines that have legitimate access to your corporate network, either by being on it physically or through VPN. If you only have defense at the perimeter, you are vulnerable to insiders, such as employees who are about to rage quit and want to do damage on the way out.