4 ms·
The paper's definitely worth reading, although it's worth noting that: a) This is implementation heavy b) The implementation is tied to a specific company mig
by staticassertion 5y ago
The paper's definitely worth reading, although it's worth noting that:
a) This is implementation heavy
b) The implementation is tied to a specific company migrating to this approach incrementally
I would say it's a great case study for moving to a ZTN, but if I were to explain ZTN I'd probably just propose a definition. I'm technically a vendor but the definition serves me in no way.
1. Requests are mutually authenticated and always encrypted (ex: mtls)
2. Requests are authorized; policy oriented, granular, and contextual authorization
3. Requests are monitored and audited
The paper lists a bunch of ways to accomplish those goals. SSO, device inventories, an authorizing proxy, a monitor, etc.
Of course, you're right. Vendors are horribly self serving and have already significantly degraded the term and confused people.
- tptacek 5y agoThis is the implementation that defined the movement. You can distill it down to principles, but if you're saying things that contradict it, you're talking about something other than ZTN.
- staticassertion 5y agoYeah, I'm totally with you on that. I was just trying to get across that distilling to principles is easy and effective, whereas the paper is going to describe a specific implementation. If someone is interested in ZTN they would be best presented with both imo
- tptacek 5y agoPeople land in weird places when they try to carry around just the principles. Like, "network controls are evil and should never be used". That's not at all what BeyondCorp says.
- staticassertion 5y agoPeople gonna people