23 ms·
Zero Trust SIM
- drummer 4y agoSeeing as how Cloudflare can cancel and censor you at will and has done to others recently, you'd have to be crazy to trust them with your phone and sim.
- nanankcornering 4y agoPlease make this product available for non-enterprises too (at a cost, of course.) @jgrahamc @eastdakota
- jgrahamc 4y agoThat's kind of our playbook, right?
- nanankcornering 4y agothat's great to hear. thought it was going to be locked behind enterprise door.
- edsimpson 4y agoAs a consumer, if pricing was reasonable, I would switch to this is a heartbeat.
- chris_st 4y agoLooking forward to hearing about it -- but I really do want to be able to use it with my phone ISP (Irritating Service Provider :-) and not have to switch to some specific provider. I use MVNOs (specifically, Ting Mobile now, but I'll be switching to US Mobile soon). Also, I'd like to be able to use your DNS and NextDNS's one -- I love your security, but (particularly on mobile where I pay per byte for data!) I love that NextDNS blocks tons of ads and trackers. So much less data downloaded. So much faster internet. So much nicer too. Thanks for doing CloudFlare! I use it for my websites, would be cool to know it's (deeply) protecting my phone too.
- quinncom 4y agoYou can set up a Zero Trust policy with block lists and use it with the 1.1.1.1 Warp app on any platform, which provides not just DNS but VPN too. It's more sophisticated than NextDNS, the only downside is that because it's an enterprise offering, there are a ton of options and it's a bit complicated to set up. There are built-in blocklists for malware, suspicious domains, and much more. To block ads and trackers requires uploading custom block lists, which requires manually uploading a csv file (annoyingly, limited to a maximum of 1000 entries per file). https://developers.cloudflare.com/cloudflare-one/policies/filtering/initial-setup/dns/ https://developers.cloudflare.com/cloudflare-one/policies/fi...
- chris_st 4y agoWow, great idea... I guess I was hoping they'd do the hard work :-) but I'll look into this.
- navigate8310 4y agoAlso, countries specifically South Asia
- systemvoltage 4y agoI know you're the CTO, I just wanted to say that Cloudflare is an amazing company that recently took a couple of steps in the wrong direction. The new playbook seems like it has added a page of crayon doodles. Intellectuals understand what happened with the censorship incident on both sides of the argument, but both agree that trust is one of those things that builds over time and difficult to achieve. IMO a company such as Cloudflare needs to build trust through extreme sense of stability and guarantee. Rule book needs to be super explicit with zero ambiguity written with a precision pencil, not a spray can.
- jacooper 4y agoSo its basically a Sim with a VPN Built in?
- swyx 4y agoyeah. pretty innovative, love this kind of unconventional thinking. good “why now” as well with the iphone supporting esims first class
- ignoramous 4y agoIt is amazing that Cloudflare is going after CrowdStrike, AWS, ZScaler, Vimeo, Twilio, Netifly, Cisco, PA Networks, Tanium, Wiz all at once.
- swyx 4y agofwiw its not all sunshine and roses. have had a couple chats with recent ex employees that this has caused internal strain. nothing unexpected ofc
- death_syn 4y agoIt sounds a lot like Enterprise Google Fi to me.
- Nextgrid 4y agoVPN in the sense that it puts you on the company LAN, yes. VPN in the sense that it's private and secure, no - the carrier has full access to the traffic. (that's not a dig at Cloudflare, it is a shortcoming of the mobile protocols - the network has to have access to the traffic by design)
- mikece 4y agoGreat implementation of the wrong solution. The problem isn't that SIM security is weak but it's that we're using SIM/eSIM for identification and authorization in the first place. When we stop using SIM for authentication the need to guard against SIM Swap attacks goes away as well.
- jgrahamc 4y agoThat's one line in the announcement and is not the core of what we announced. This eSIM provide a data connection that goes directly to Cloudflare.
- deleted 4y ago[deleted]
- ayewo 4y agoHow does this data connection work in practice? Sounds like you have to become an MVNO, no?
- Nextgrid 4y agoThey will essentially be an MVNO, yes. It doesn't address security much though - the carrier's infrastructure still needs to be trusted and there is no end-to-end encryption between the mobile device and Cloudflare (you'd still need an on-device VPN for that - this is a limitation of the mobile protocols; the network is considered trusted and is given access to the traffic). The eSIMs that Cloudflare uses also need to be properly segregated away so that the carrier's customer support people can't reissue those SIMs, which they can technically do as they are still considered the issuer and their system is in control of the issuing process.
- vinay_ys 4y agoThis blog post doesn't read like rest of Cloudflare posts. It is very beating around the bush and doesn't get to the point at all. Please consider updating the blog for clarity and brevity.
- 4y ago
- mschuster91 4y agoThe only attack this is preventing is corrupt or confused mobile network customer service representatives issuing a valid SIM card to an attacker so that the attacker can intercept 2FA SMS messages, but any larger-ish company should already have a corporate phone plan with clearly established contact points to do any kind of change. So what I don't really get is, what is the actual advantage? And besides, Cloudflare will have to run as an MVNO if they're rolling their own SIM cards / eSIM keys, which almost always means lower quality of service in congested network areas - there is no requirement for equal treatment of MVNOs I'm aware of, and even here in the EU you can clearly see that providers discriminate even between premium post-paid contracts and pre-paid contracts. Switching from Telekom's own MVNO Congstar to Telekom proper was night and day.
- cr3ative 4y agoThe attack you describe (somewhat dismissively) is extremely common.
- mschuster91 4y agoAgainst private phone contracts, yes indeed - but as I said, large companies (which CF targets here) already shouldn't be vulnerable. For private phone contracts, we should kick the arses of our politicians and the regulatory agencies to finally do their job.
- staticassertion 4y ago> but as I said, large companies (which CF targets here) already shouldn't be vulnerable. Only if you're willing to trust the reset process. The whole point of this is to remove that trust. Further, as noted, this doesn't just protect against that attack. It also allows for filtering at the data layer, so you can remove malicious traffic. And it also gives SIM a stronger identity, so if you're using a heuristic for identification (as you always are) it becomes a much more powerful entry.
- vinay_ys 4y agoThe same attack can be mounted against your corp IT admin in charge of your Cloudflare account.
- formerly_proven 4y agoI honestly don't particularly get BYOD. The savings on the company side seem so marginal for a lot more uncertainty, more support issues and worse employee mental health etc.
- ben174 4y agoEmployees don't want to carry two devices.
- deleted 4y ago[deleted]
- RunSet 4y agoI would rather carry two devices than allow an employer to use my hardware without compensation. Ideally they would furnish their own data plan, too. This also permits leaving the work device at work where it belongs.
- eastdakota 4y agoThat’s the idea: the employer pays for the data you use to do your job.
- Eleison23 4y agoThe interesting thing about using personal devices for work is personal liability. Have you ever considered what happens if your company is embroiled in some sort of litigation, regulatory investigation, or suspected criminal activity, and undergoes discovery of evidence? If law enforcement or counsel suspects that you or your devices are harboring relevant data, then your devices could be seized, imaged, held as evidence, and possibly never returned to you, certainly not in one piece. So if you're mingling your personal data along with any sort of company data, or data that belongs to an organization that's outside your family unit, and said data is physically inseparable, then prepare to lose big in the future. You'll kiss all your backups goodbye, no matter where they're stored or how you've encrypted them. Of course this may also apply if you've got a company-provided device (COPE) or one running MDM, and it's stolen or lost. When you report back to the company that their data's in the wind, they're going to remote-wipe and remote-brick that device, so again, kiss your personal data bye-bye. Best practice going forward is to purchase separate devices (especially mass storage) for each individual purpose and meticulously separate out company data from personal stuff. It never pays to mingle business with pleasure, or business with personal, and I think this liability issue is something that's a well-kept secret by companies who wish to encourage workers to BYOD and downplay the repercussions, although rare, that could put those workers into a world of hurt.
- _8j50 4y agoWhy is there no opposition to this shit? SIMs were physical for a reason. As a consumer what do you get out of it? You have to go through the carriers to switch between phones now! You can't just pick up a random unlocked phone and put a sim in it. No more burner phones. I have been in situations where I changed SIM between phones multiple times a day. But it sounds like it is too late for this. It's like people who oppose cash payments out of the convenience of card/app payments. This small chipping away of a small libery adds up. I hope eveyone knows that you can't as a layman register an email address or any meaningful service you depend on without a phone number (i.e.: a sim), that is what is being regulated here even more.
- cmeacham98 4y agoNothing you say here has any relation to eSIMs. 1. This problem can exist with real SIMs too. Back many years ago Verizon used to lock your SIM to a specific IMEI and you had to call them to change it (they might have even charged a fee for changing it, I don't remember for sure?) 2. Nothing prevents a phone company from offering an anonymized eSIM. Anonymous phone numbers are drying up, but not because of eSIMs.
- awill 4y agoVerizon is a bad example as they were CDMA and always more locked down
- cmeacham98 4y agoVerizon happens to be the provider I had at the time, I wouldn't be surprised if other providers did it too.
- saghm 4y agoWhen I was on Verizon, I remember having to go into their store to get a new SIM each time I got a phone that wasn't through them. Using eSIMs after I switched to Fi was a small but noticeable quality of life improvement for me at least.
- easton 4y agoIs the idea with this that it'll be a data-only eSIM? I'm not seeing any mentions of phone service in the blog post (maybe it's just implied and I'm dumb). I think iOS and Android have support for multiple eSIMs where one is used for data service, so that would work, although I don't know if companies want to pay for everyone to have a data plan AND a SMS+phone plan.
- jgrahamc 4y agoCurrently data only.
- barathr 4y agoI think the term "zero trust" creates a bit of confusion, in this and other contexts -- not Cloudflare's fault, because the term has been used/abused quite a bit. I think it's a good idea to prevent SIM swapping attacks, and it looks like this will, like Efani does. TLDR: this will lock a corporate SIM to a device and then connect the device to the perimeterless corporate network.
- Nextgrid 4y ago> then connect the device to the perimeterless corporate network With the huge caveat that the carrier can still see all the traffic and reissue the "trusted" eSIM to a different device and take over this data connection.
- neatze 4y agoEven for basic https request, would you need certificates ?
- greenie_beans 4y agoI can't help but think of Room 641A every time they announce a new project where they're like "we'll take care of it by directing your traffic through our network" https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A edit: whoops. let me be clear that i'm a big fan of cloudflare! that's just where my brain wanders sometimes
- ezekg 4y agoYep. I'm convinced CF is government-backed mass-surveillance through a "private company." I'd love to be convinced otherwise, but it's the NSA's dream to man-in-the-middle the Internet.
- eastdakota 4y agoExcept it’d be the end of a $20B company that I have a huge stake in ensuring doesn’t end. So, so long as I’m CEO, there’s no way in hell that’ll happen. If all you believe in is my economic interest, it’s far more lucrative to be the trusted, private network over time than any alternative. And so we’ll invest like crazy to ensure, even if compelled, we wouldn’t have the ability to compromise the integrity of the data flowing through our network.
- humanistbot 4y agoIf I was the US Government / NSA, I'd pay $20 billion to secretly own cloudflare.
- eftychis 4y agoPlus premium. It would be free in practice.
- bogomipz 4y ago>"If all you believe in is my economic interest, it’s far more lucrative to be the trusted, private network over time than any alternative." And yet AT&T has proven otherwise. [1][2] [1] https://www.macrotrends.net/stocks/charts/T/at-t/stock-price-history https://www.macrotrends.net/stocks/charts/T/at-t/stock-price... [2] https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A
- 2Gkashmiri 4y agowait till clouflare decides to ban a website from their network and you suddenly cannot access them unless YOU CHANGE YOUR SIM PROVIDER, that sounds fun
- aembleton 4y agoA bit like any ISP then. You have to change ISP or use a VPN to access the pirate bay if you are on the Shell Energy ISP in the UK.
- MrBuddyCasino 4y agoWait until they block your SIM for posting wrongthink. Now you cannot access any website on your phone!
- neilv 4y ago> By integrating Cloudflare's security capabilities at the SIM-level, teams can better secure their fleets of mobile devices, especially in a world where BYOD is the norm and no longer the exception. Please consider not doing BYOD for company business. Quick summary of IMHO, from some companies where I've defined or advised on infosec policy... From the employer side, BYOD is bad for security and liability. From the employee side, BYOD is bad for privacy&security. Regarding employee's personal info on BYOD (since it's less familiar concern than company protecting IP and operations)... Whether or not there's MDM, it's a big problem for employee and company, when security team needs to investigate an incident, or when legal proceedings mandate that forensics expert clone/search a device, and that bumps into personal info. (Personal info revealed can include private personal conversations, intimate photos/videos of employee and partners, job searching, medical information, non-public sex/gender/etc. identity, protected classes for discrimination, Web history, etc., to possibly the company or some outsiders.) Also a big problem if the company needs to wipe or lock a device to secure IP, and that would wipe personal data or lock employee out of it. No work on personal devices. No personal on work devices. Being strict about this from the start is to everyone's benefit (before complicating practices set in, the wrong services are bought/deployed, etc.). For employees who actually need to carry smartphones for business (e.g., executives, marketing, sales, other non-engineers), the company should issue devices with plans, to be used exclusively for business. For work calls for people who don't get issued company smartphones, use a service from the work laptop. For rare alerting eng/ops/etc. in the off-hours, when they don't have a company-issued smartphone, alerting can be to a personal device, but the alert should convey no info other than what is the urgency to get to the company laptop. Also possible side life balance benefit of strict work and personal separation on devices, especially with WFH/hybrid and carrying a laptop home: without work on personal devices, an employee can just physically put the work device(s) in a drawer/bag for the evening, and call work over for the day, or until they're ready to take it out. (No associating their personal devices with work, no interrupting with work off-hours while people recharging and with family, no trying to use unreliable software settings correctly to suppress work messages at some times and not others, etc.)
- ignoramous 4y agoSo, a matter of time before Cloudflare acquires https://gigs.com https://gigs.com?
- HFrank 4y agoWe’re not for sale ;)
- AnonMO 4y agoAnd 1 year ago figma said they don’t want to be adobe.
- estsauver 4y agoHey, gigs looks super neat--I couldn't find any information on the markets you're in. We operate in subsaharan Africa, so don't want to take time from your sales team if that's not a good fit, but I couldn't find anything on your notion that was publicly available.
- ignoramous 4y agoNot sure about gigs, but airalo vends African eSIMs: https://www.airalo.com/africa-esim https://www.airalo.com/africa-esim
- HFrank 4y agoFeel free to submit a request on our form and our team will get back to you ASAP on that.
- lbhdc 4y agoThis is cool. I noticed a bug on your main page. The section showing off what the ui looks like shows a blank white panel on firefox.
- for1nner 4y agoIs there a reason your eng. team is EU-only while your biz/ops is EU/US?
- BrainVirus 4y agoThey want to be in front of every website, behind every DNS request and now they want to control your cellphone traffic - while bleeding money by tens of millions of dollars a year and making promises they don't intent to keep. The trajectory of this company's life is obvious in advance.
- lizardactivist 4y agoYou can say that again. Zero trust that Cloudflare, the largest man-in-the-middle of the Internet which began its life as a CIA honeypot, will not abuse this.
- rglover 4y agoBingo. Way too much centralization of communications in exchange for mild convenience. And of course, it will be dismissed with a "you're just paranoid" pat on the back until, inevitably, and predictably, they weaponize it (with the back-patters being nowhere to be found).
- INTPenis 4y agoYeah I was just thinking the same thing, zero trust except of course for CloudFlare, you have to trust them implicitly.
- beeenthusiast 4y agoI'd not heard of Cloudflare starting out as a CIA honeypot. What are the details on this?
- throwaway29812 4y agoAlso looking for a source for this claim.
- throwaway29812 4y agoAny source at all.
- jupp0r 4y ago"We have sophisticated logging set up as part of Cloudflare One, and this will extend to Cloudflare SIM. Today, Cloudflare One can be explicitly configured to log only the resources it blocks — the threats it’s protecting employees from — without logging every domain visited beyond that." So my employer can log all of my network traffic metadata, but I can take their word for it that they have some setting set that it only logs hits on their deny list that they are filtering my private internet usage with? CloudFlare needs to give more power to employees here to make sure that employers are completely unable to monitor any traffic that doesn't go to their networks. The abuse potential for this in its current form is gigantic.
- stickfigure 4y agoIf your phone service is provided by your employer, they have control. Phone service is cheap. Get your own. See also: Email.
- dathinab 4y agoYes they can also tell you they don't log anything but blocked content but then log everything anyway, you have no way to know. To top it of even just logging blocked content can be a major invasion of privacy as things like union sites and similar are sneaked onto block lists all the time.
- c8g 4y agoUnfortunately, I guess, it won't available in the most part of the of the world at a competitive price to local operator.
- lxgr 4y agoWhat's the advantage of using this vs. installing a mandatory VPN via an MDM profile? For mobile data, the outcome seems to be identical, but it would also work for Wi-Fi.
- Nextgrid 4y agoThere's no advantage from a security point of view, but much disadvantage because the VPN is end-to-end encrypted between your phone and the VPN server. This is not; the mobile network has access to the plaintext traffic. The advantages of this that I see is better/easier management, you deal with a nice web interface/API and (if needed) competent customer support people rather than monkeys.
- deleted 4y ago[deleted]
- fluidcruft 4y agoWhat even is the advantage for the person who actually owns the phone?
- jabart 4y agoLikely this is using the private network option that mobile carriers have been offering. Hologram has something similar where every SIM is in a private IP space behind a NAT. Now it seems CF can run your phones in their own private LTE/5G network, anything going to work addresses gets split directly to those endpoints and "auth'd", while personal goes out to the internet. Similar to a VPN but without an endpoint and less spam traffic since it's a private network only your authorized SIMs can get onto. You could still run a VPN but all your Zero Trust should be over HTTPS/TLS and MitM becomes a bigger lift to make happen since you now have to attack cell sites.
- ck2 4y agorandom fun cloudflare related thing I learned last week, their "private dns" address is "one.one.one.one" which is even easier to remember than "dns.google" (there is also "dns.adguard.com" and "dns.quad9.net")
- mxuribe 4y agoWow, TIL ...I had heard of the ip address 1.1.1.1 (and yes, for dns), but never knew about the spelled-out website: https://one.one.one.one/ https://one.one.one.one/
- gigel82 4y agoOh, that's disappointing, I was hoping they're entering the MVNO space with a consumer offer. Instead, it's an offer for companies to further spy on their employees :(
- tekchip 4y agoWow, eSIMs hit first in this discussion? Not the glaring nightmare of security QR codes are. I thought about providing links but there's such a vast host of writeups about it I'll leave it for the reader to search and discover. Yikes.
- yellow_lead 4y ago> What if employers could offer their employees a deal: we'll cover your monthly data costs if you agree to let us direct your work-related traffic through a network that has Zero Trust protections built right in? No thanks..What is "work-related" and what isn't? I see huge privacy implications here. If my company wants to install this potential-spyware on my phone then they should just offer a separate phone. Personally, I don't mind carrying it if I'm "on-call" one week out of the month or whatever.
- ok_dad 4y agoI wonder if it is easy enough to "swap" e-SIMs that one could load your work profile on your phone (can iOS do that? I am not sure, but Android can anyways), swap sims before work starts, do work, "go home", swap back to your personal phone profile and personal sim. Otherwise, I agree: give me a work phone if you want to snoop on it, otherwise please just text or call me on my personal. My current company pays partly for my phone (like half?) and don't expect anything in return, they just wanted to make sure if I used it to make calls for work I was paid for that (I never do anyways).
- jackson1442 4y agoiOS can swap, it's just a flag in your phone app/control center. My personal preference is expensing a phone bill. That way I maintain billing control and just save some money. Or a company phone, but I've yet to have that offered to me.
- ranger_danger 4y agoHow are they the first? MobileIron and others have been offering solutions for at least 2.5 years now.
- rasz 4y agoThat is a lot of text to say "trust us bro". First we gave cf decryption keys to most of https web traffic, now they want to own cellphones, for our privacy of course!
- wilde 4y ago> And all this is before you add in the further complication of Bring Your Own Device (BYOD) that more employees are using — you’re trying to deploy Zero Trust on a device that doesn’t belong to the company. Yeah, this is a pretty impressive technical solution to a problem created by the company. “We’re too cheap to buy equipment for our employees to use, so instead we need to spy on all of your personal data.”
- bhc 4y ago>But in recent years, nearly every modern phone shipped today has an eSIM How many phones other than iPhone, Pixel, and (very recent) Galaxy S/Z have eSIM? There aren't that many cellular IoT boards that support swappable eSIM either (some boards say eSIM, but what they mean is that the IoT vendor's SIM is soldered onto the board - thus "embedded SIM"- not that you're allowed to load eSIM of your choice).
- vl 4y agoI’m confused about what it is. It looks like it’s Cloudfare’s MVNO eSIM. What’s zero trust about it?
- judge2020 4y ago> Preventing employees from visiting phishing and malware sites: DNS requests leaving the device can automatically and implicitly use Cloudflare Gateway for DNS filtering. > Mitigating common SIM attacks: an eSIM-first approach allows us to prevent SIM-swapping or cloning attacks, and by locking SIMs to individual employee devices, bring the same protections to physical SIMs. > Enabling secure, identity-based private connectivity to cloud services, on-premise infrastructure and even other devices (think: fleets of IoT devices) via Magic WAN. Each SIM can be strongly tied to a specific employee, and treated as an identity signal in conjunction with other device posture signals already supported by WARP.
- softfalcon 4y agoI'm seeing a lot of people advocating for either eSIM or standard SIM slot. I feel like the real question should be "why not both?" I know there are economics, control, tracking, or whatever at play. Regardless, I think the phone should have a SIM slot and it should ALSO have eSIM functionality. I can almost guarantee the reason they're pushing for eSIM is because it's cheaper to manufacture a phone without a milled out slot with water sealant lining, little switch to pop out the SIM deck, etc. Can we all not agree that the real "enemy" here is the corporations taking away your options? If we were really thinking about the consumer here, we'd be ensuring you had access to both technologies to ensure your phone is robust and capable of working on any network regardless of their SIM requirements. Maybe this is crazy talk though. Maybe eSIM is so amazing, old SIM doesn't even matter anymore, but I can't help but feel like I'm right here, because having both quite literally appeases everyone except rich corpo's trying to save a buck.
- judge2020 4y ago> I can almost guarantee the reason they're pushing for eSIM is because it's cheaper to manufacture a phone without a milled out slot with water sealant lining, little switch to pop out the SIM deck, etc. That's precisely it, it's just that Apple et al. don't need to explain their reasoning to sell phones. They never have an official reason for removing the headphone jack, but their COGS is definitely lower.
- deleted 4y ago[deleted]
- silentlinkuser 4y agohttps://silent.link/ https://silent.link/ is the real 0 trust SIM: "Anonymous eSIM Get global mobile 4G/5G Internet access and burner phone numbers instantly and privately on any modern eSIM-compatible smartphone. Pay as you go international roaming in 200+ countries Worldwide coverage at low prices pay with bitcoin or lightning" I'm just a user. I use it at times. It works well and prices are ok.
- base0010 4y agoI had hopes this product would be way less draconian. People miss the real reason you should push back on eSIM-only devices! It seems that most of HN hasn't done their DD on how eSIM provisioning dosen't work unless you're a billion dollar telco incumbant..... The eSIM-only precedent telco tech giants are pushing towards is part of the time honored tradition of locking consumers out of their own hardware. Indeed, this is another version of "the carrier owns the hardware you've purchased". TL;DR in order to provision an eSIM to live inside the eUICC (secure element inside phone); as per GSMA standards your eSIM HAS to have a key signed by a SOLE CA determined by the GSMA and the incumbent billion dollar telco industry cartel!!! With a SIM-card you have the freedom to connect to any network you want including those that aren't inside the realm of: "Only eUICC manufacturers, and SM-SR and SM-DP hosting organisations that have successfully been accredited by the GSMA SAS can apply for the necessary certificates from the GSMA Certificate Issuer to participate in the GSMA approved ecosystem." Please push back on this draconian nonsense as a whole people!!! eSIM Whitepaper: https://www.gsma.com/esim/wp-content/uploads/2018/06/eSIM-Whitepaper-v4.11.pdf https://www.gsma.com/esim/wp-content/uploads/2018/06/eSIM-Wh...
- jackson1442 4y agoShould we reject TLS certificates for the same reason then? If they aren't trusted by the "TLS cartel" then your users are told that the site is "not secure" and shouldn't be trusted. Many browsers will even completely block you from accessing pages without valid trust roots.
- base0010 4y agoI can add a CA to every modern OS with a few clicks and a password can't I? Furthermore, in a browser it's usually 2 clicks away from getting to a site with an expired TLS cert...Why can't I do similar with a eUICC in a device I paid for and own? Hint: control. Furthermore "reject TLS certificates" implies rejecting a useful security mechanism as a whole...eSIM provides no further security mechanism to a [p]SIM as far as LTE/5G security goes... ie. MILENAGE etc. The only added security of an eSIM is that it adds security to big telcos subscriber revenue and makes them sticky as providers. It's a big telco cartel and if you ain't in it you're dependent on them at the very least.
- dathinab 4y ago> [..] logs only what it blogs putting aside that it's not clear weather it can be configured to do so or always does so and if the employee has any way to know if it is configured to log only blocked content or log everything its still a no-go the things is that content which is fully legal no-risk is feed all the time into block list and fishing protection to make it less accessible for example the CCC ticket selling side was frequently "somehow" in the minor protection DNS filter enabled by default by all UK ISPs... you can be pretty sure that union and employer right protection related sites will "somehow" end up in the filter and not only will that bar the employee from realizing their information need/rights, it will also show up in the log accessible to the employer then you probably can configure the "protection". How long will it take to be possible to enable blocking of adult-content or similar? This would lead to a potential indirectly exposing of employee sex related preferences to the employer, or religion, or ... Trying to pretend this system is not incredible invasive to employees privacy is hypocrisy and puts a pretty bad light on cloudflair. I mean they could say it's less invasive then many other existing methods, I guess that might be right, but that doesn't mean it's okay at all. In the end trying to marry BYOD with security is just nonsense. If the work tasks need a phone then provide a phone to the employee (which could use this system). If you only worry about 2FA use HSKs. Remove phones out of any security related procedure, that is anyway recommended for other reasons like SIM-hijacking. Then don't require or allow employees to install anything which could be used as a attack vector on their private phone, no slack, no teams no nothing. If there is an emergency you can call them and tell them to use their employer provided device, it's that simple.
- zzz95 4y agoHow is this even Zero Trust. Admittedly, there is no precise definition for ZT, but Cloudflare's solution seems to run counter to the idea of perimeter-less ZT philosophy. Instead of assuming that phones can be insecure and developing appropriate crypto based mechanisms, Cloudflare is proposing to bring the phone inside a 'trusted' network. Remember, ZT does not rely on trusted network. Solutions like this will increase confusion and fragment the already 'interpretation led' as opposed to definition led ZT landscape.
- jchw 4y agoI don't see anything about a trusted network, it looks like this is about authorizing devices. It seems a little bare on the details of how it works, but apparently it ties into a Cloudflare product called Magic WAN. Authorizing specific devices is still a good strategy even with zero-trust networking.
- yellow_lead 4y agoYeah I thought the same. Sounds like the marketing team got a bit excited here
- ec109685 4y agoDevice attestation is an important piece of the zero trust design, which this esim approach helps facilitate. ZT / BeyondCorp benefits from multiple layers of security, not the hard exterior and crunchy interior approach of VPNs, and this solution from cloudflare is aligned with that.
- zzz95 4y agoMaybe I got it wrong, but the eSIM seems to be enabling a corporate VPN of sorts here.
- elithrar 4y agoThat’s not the case — note that we don’t say “trusted network” in the blog. That’s definitely not the right solution. There’s two key parts: 1) we can filter and secure traffic _leaving_ the device, whether bound for the Internet or internal apps. This isn’t VPN like: this is part of our software gateway. When you click (tap!) on a phishing link, we can filter it and render it inert. 2) using the eSIM, which is associated with a specific employee, as an identity signal and device posture signal. This fits squarely into the Zero Trust model. ZT is about explicit identity, not the old days of implicit “I’m on the VPN and can move laterally!”. (I work at CF)
- radicaldreamer 4y agoEvery one of these product launches makes me think Cloudflare is the CryptoAG of our time. There's an immense amount of centralization happening under this company under the guise of "security".
- totetsu 4y ago> Mitigating common SIM attacks: an eSIM-first approach allows us to prevent SIM-swapping or cloning attacks, and by locking SIMs to individual employee devices, bring the same protections to physical SIMs. I thought a sim swap attack is carried out by asking the operator to reissue a sim card, and getting it done via a failure of identity verification or a collaborator working at the operator. What is to stop just requesting the re-issue of an eSIM to a new device in the same way?
- throwawayKiwi9 4y agoYes, only every successful SIM swapper I am aware of. It sure is hard protecting a glass house.
- puyoxyz 4y agoI am NOT using a sim from Cloudflare