4 ms·
I agree with the goal, but I have trouble imagining reaching it in a typical enterprise/government IT environment. I agree that VPN is a crutch. The alternative
by codeflo 5y ago
I agree with the goal, but I have trouble imagining reaching it in a typical enterprise/government IT environment. I agree that VPN is a crutch. The alternative is that every little legacy intranet application needs a fully staffed and security-aware maintenance team. That team needs to work full time to keep the technology up to date so that everything can be patched, forever. Many little internal tools wouldn't exist in such an environment. Maybe that's not entirely a bad thing, but it's very different from today's expectations.
- EthanHeilman 5y agoI think you are right. Resources spread too thin is a major reason why intranet applications are hard to secure. I'd argue that if you can't secure a legacy application figure out some way to move to a SaaS and let someone else run it for you. Only run stuff yourself that you have the resources to secure. It is why I'm bullish on Saas, it is eating the intranet.
- Jtsummers 5y agoUS gov't systems have already been pushing out the little bespoke apps for a while now anyways. They're a security nightmare with or without a VPN. Plus, the majority of them seem to cover three things: 1. Task management (JIRA clones, but worse) and coordination, possibly with external user (contractor) access which opens up a hole in the system anyways. 2. Custom workflows (BPMN-ish, but not disciplined and not, easily, connectable to each other), again with external user (contractor, citizen, applicants, whatever) access. 3. Document sharing (SharePoint, but more like a skin over a network share), again with external user access. All of those can be covered by other systems, sometimes simpler ones than presently used (3 is the core of what HTTP was meant to serve, they "just" need access control on top of a basic HTTP server which is a solved problem these days). A bigger problem with the bespoke apps is that they often have their own access control mechanisms, which don't always play well with the larger organization access control systems. They have their own user names and passwords, they may or may not connect to a CAC-authenticated backend. Or they do stupid things (had to fix one of these once) like not authenticating the CAC but using trust-on-first-use, and then the user's access had to be reset when they got a new CAC. Brilliant. These aren't good systems, they are serviceable systems. There are other rapid application development tools (see Appian and others) that can cover (1) and (2) but provide a unified backend (which means the workflows can now be composed, too). SharePoint and other document management systems can cover (3). SharePoint can also cover (1) and (2) (though I've barely tolerated it for either use, it is at least better than dropping $1 million+ a year on hardware and software licenses for a one-off product supporting a half dozen users that doesn't integrate into the rest of the system).
- closeparen 5y agoThere’s still a layer between the application and the big bad internet. It’s just that the layer is an L7 reverse proxy instead of an L3 VPN appliance. This is still a big win, because: a) You still have to go through the layer even if you’re on an office network. b) The layer knows exactly which application you’re talking to, and maybe even something about the transaction you’re attempting (URL). c) The layer can cooperate with the application, for example injecting a header about the authenticated user’s identity and groups.
- Spivak 5y agoAnd then in 20 years there will be a beyondcorp^2 because people will lean on their border gateway in exactly the same way they relied on their VPN. “Oh whatever it’s behind the proxy.” a) You just mandate that people be logged into the VPN always — “the office network” is just as untrusted as a coffee shop. b) That’s the address of the service. c) That’s the address of the client. Also apps that care what user you are basically all implement auth again against probably LDAP if it’s a corp network. I still think it’s a win because VPNs are clunky as hell but I think the security benefits are more to do with the political “rewrite” than the technical details. You can store your policy bits anywhere.
- EthanHeilman 5y ago> You can store your policy bits anywhere. You can but the application layer produces a far more legible policy and record of events. The right layer of abstraction for policy is at the application layer.
- closeparen 5y agoThat seems like either a very old-fashioned service (single permanent server) or very new-fangled one (overlay networking scheme) that you can identify simply by address.
- otabdeveloper4 5y agoVPN is a crutch?? Really? Do people not realize that for every one "internet server" there are at least 10 servers that aren't connected to the internet and are only accessible via LAN? What's their solution, just expose all this underwater glacier mass of compute to the public internet?? Lol.