9 ms·
Unpacking the Benefits of Zero Trust Architecture as Defined by NIST
- out-of-ideas 4y agoive always correlated zero-trust with that which was recently on top of HN: https://dilbert.com/strip/2023-02-11 https://dilbert.com/strip/2023-02-11 treat your employees like cattle; see how far that will go
- deleted 4y ago[deleted]
- panzagl 4y agoI log into a Citrix client to log into a Azure Virtual Desktop so I can run a vpn to get into Confluence. It's awesome, shoot me now.
- HyperSane 4y agoI once worked at a company where I had to logon to the corporate VPN with an MFA token, then logon to the datacenter VPN with a second token, then logon to a VMWare Horizon virtual desktop and then RDP to a VM inside a tenant network. I needed a different AD cred for every tenant.
- cscheueuer 4y agoHas anyone used Pomerium and is it any good compared to Tailscale or Twingate?
- Aaronstotle 4y agoI'm testing Twingate out now and I've gotten lot of good back from Engineers. Curious to know as well
- CKMo 4y agohttps://www.pomerium.com/comparisons/tailscale-with-pomerium/ https://www.pomerium.com/comparisons/tailscale-with-pomerium... The tools do different things. Pomerium plays well with Tailscale.
- _8j50 4y agoZerotrust is cancer. I dismissed it a few years ago as a harmless hype but I am now seeing real harm being caused by this hype. To avoid writing an essay here let me keep it short and explain why: I am seeing orgs spending valuable time, money and resources on box checking and implementing false security all over. It is being used in place of improving security posture that is aware of threat context facing the organization. It has scope-creeped beyond the original intended purpose of ensuring all actions are explicitly authorized and eliminating implicit trust to mean a buch of ridiculous goals and hype words no one can explain consistently. I caution everyone to avoid using the term but to still implement the original beyondcorp architecture. Another cancer that is begining to spread:"passwordless".
- cscheueuer 4y agoWhat is the easiest way to implement the original beyondcorp architecture without spending multiple months building a solution in house?
- jupp0r 4y agoIf you already have authentication and authorization in front of every service in your internal network (unlikely), it's as easy as making everything routable from the internet. If not (more likely) you need to start there, which will improve your security posture incrementally, even if the beyondcorp project gets cancelled along the way.
- adobrawy 4y agoI will add that in the case of authentication before each service, it is important that it does not happen in the application itself, but before reaching it, which usually means either network centralization (e.g. Teleport) or authentication proxy (Traefik + forward auth + proxy, GCP identity-proxy, AWS Verified Access). It is also important to centralize the identity provider, of course, which in the times of SAML / OAuth is easily achievable even for small organizations.
- eikenberry 4y ago
- barathr 4y agoZero Trust certainly has its benefits over the old perimeter-based model, but it also requires new, and massive, trust in third-party cloud providers. A bit more on that: https://invisv.com/articles/zerotrust.html https://invisv.com/articles/zerotrust.html What we need to move towards is something more like Oblivious Trust -- you rely upon third parties but they have nothing sensitive in the first place.
- Hikikomori 4y agoWhy would it require you to trust a cloud provider?
- JamesAdir 4y agoYou will always need to trust someone. How did you trust your hardware such as laptops and network equipment so far? So either you trust the vendor, or you're trusting a 3rd party that checks the hardware for you and give you some form of approval.
- michaelt 4y agoIMHO there's a huge gap between "trust this dell hardware not to contain hardware implants" vs "trust cloudflare warp to MITM every SSL connection I make"
- colinrand 4y agoWith many new ideas, the early folks love the benefits and aren't put off by the challenges. With ZTNA, after doing quite a few deployments myself, I can say that the biggest challenges are operational. Nothing will piss off developers more than having had access to a resource one day, lose it unexpectedly, and then not know who to track down to get it back. Or, users hating on their VPN, want something else, and then that something else (often just another VPN provider) works differently and causes them disruptions. ZTNA is a long journey, not a quick fix.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- paradice 4y agoI work in infra engineering in such a company and it indeed is so mentally draining when something that should be a few clicks on Azure take me 2 days of chasing shadows to figure out what access I need and who to ask for it and then having to prove that I really need that access level and not a weaker one.
- deleted 4y ago[deleted]
- CKMo 4y agoIt is indeed a continuous process, like devops!
- timcavel 4y ago[dead]
- EGreg 4y agoAnyone know Ziti?
- PLG88 4y agoI know OpenZiti very well (I work on the project)... whats the question?