5 ms·
> Also what the threat model is, and how ziti solves it. Your service (anything that accepts incoming connections) is never exposed to open internet. any incom
by ekoby 4y ago
> Also what the threat model is, and how ziti solves it.
Your service (anything that accepts incoming connections) is never exposed to open internet. any incoming connections are guaranteed to be from authenticated and authorized clients.
> I assume it does little to thwart traffic analysis?
It does -- the traffic is routed throw OpenZiti fabric.
> Does it suffer from tcp-over-tcp problems?
OpenZiti is not a VPN and it does not forward network packets. In application embedded cases payload is end-to-end encrypted and forwarded on overlay network.
> Would be fair to say it's similar to a private Tor network with hidden services - but without anonymity and (probably much) higher throughput?
I believe that is a fair comparison, except anonymity is replaced with strong identity support to allow configuration of authorization policies.
- e12e 4y agoThank you! > OpenZiti is not a VPN and it does not forward network packets. In application embedded cases payload is end-to-end encrypted and forwarded on overlay network. Ok, but messages/RPC calls go over the network - can i return a 1gb video file/stream/fragment - or send real-time audio - or is it limited to more of a "secure RPC"?
- ekoby 4y agoAbsolutely, from your application's view it is just a socket that can live and be used to send/receive data indefinitely
- e12e 4y agoI more meant: what is the network transport like - does it offer tcp-like guarantees and re-submissions, along with poor suitability for real-time streams? How does it cross firewalls (that increasingly filter by protocol)?
- ekoby 4y agoat this time OpenZiti connection are guaranteed-delivery (like TCP). We are evaluating offering lossy connections in the future. At the edges connection are always outbound and are seen as mTLS to the firewalls. the application payloads are end-to-end encrypted (using libsodium) an d transferred inside mTLS channels
- deleted 4y ago[deleted]