4 ms·
In the simplest terms, it's an application embedded VPN (on both client and server) The SDK allows you to integrate OpenZiti directly into your applications so
by ekoby 4y ago
In the simplest terms, it's an application embedded VPN (on both client and server)
The SDK allows you to integrate OpenZiti directly into your applications so that it can access network resources securely from anywhere in the world. This is based on strong identity so that the overlay cannot be access by untrusted endpoints. This is ensuring your application has zero trust in the network, WAN, LAN and even host OS - in fact, your app does not even need to know the IP and port to communicate with on the underlying host.
Comparing to traditional VPNs this solution is a lot more secure -- instead giving you access to internal network, OpenZiti gives you access to specific service endpoints.
- e12e 4y agoThank you. It was entirely opaque for me from the "about" page what it allowed me to have "zero trust" in. Also what the threat model is, and how ziti solves it. I assume it does little to thwart traffic analysis? Does it suffer from tcp-over-tcp problems? Would be fair to say it's similar to a private Tor network with hidden services - but without anonymity and (probably much) higher throughput?
- ekoby 4y ago> Also what the threat model is, and how ziti solves it. Your service (anything that accepts incoming connections) is never exposed to open internet. any incoming connections are guaranteed to be from authenticated and authorized clients. > I assume it does little to thwart traffic analysis? It does -- the traffic is routed throw OpenZiti fabric. > Does it suffer from tcp-over-tcp problems? OpenZiti is not a VPN and it does not forward network packets. In application embedded cases payload is end-to-end encrypted and forwarded on overlay network. > Would be fair to say it's similar to a private Tor network with hidden services - but without anonymity and (probably much) higher throughput? I believe that is a fair comparison, except anonymity is replaced with strong identity support to allow configuration of authorization policies.
- e12e 4y agoThank you! > OpenZiti is not a VPN and it does not forward network packets. In application embedded cases payload is end-to-end encrypted and forwarded on overlay network. Ok, but messages/RPC calls go over the network - can i return a 1gb video file/stream/fragment - or send real-time audio - or is it limited to more of a "secure RPC"?
- ekoby 4y agoAbsolutely, from your application's view it is just a socket that can live and be used to send/receive data indefinitely
- e12e 4y agoI more meant: what is the network transport like - does it offer tcp-like guarantees and re-submissions, along with poor suitability for real-time streams? How does it cross firewalls (that increasingly filter by protocol)?
- ekoby 4y agoat this time OpenZiti connection are guaranteed-delivery (like TCP). We are evaluating offering lossy connections in the future. At the edges connection are always outbound and are seen as mTLS to the firewalls. the application payloads are end-to-end encrypted (using libsodium) an d transferred inside mTLS channels
- deleted 4y ago[deleted]