4 ms·
Beyondcorp is not used for access to non Google sites (and even if it was, it could be a WAF but not much more). As for how beyondcorp protects if a employee w
by advisedwang 3y ago
Beyondcorp is not used for access to non Google sites (and even if it was, it could be a WAF but not much more).
As for how beyondcorp protects if a employee workstation does get owned: the zero trust means simply being within a network permimeter does not grant access... But employee workstations are trusted to do whatever that employee is authorized to do. So beyondcorp massively reduces what an attacker can do and adds lots of hurdles (e.g. requiring pressing a security key, pervasive monitoring), but doesn't render a hacked employee workstation harmless
- mardifoufs 3y agoAhhh that makes a lot of sense!! Thank you! I guess it is inevitable that an attacker could have access to something, no matter how constrained and limited it is, as long as they can get an employee to authenticate even if it is for a single action. It still sounds miles better than the traditional IT hell that is trying to constrain the devices as much as possible instead of securing the network and implementing auth internally.