3 ms·
I wonder if we will see "zero trust" going full circle, and back to isolating privileged systems from the internet, on the basis of endpoint compromises stealin
by g_p 3y ago
I wonder if we will see "zero trust" going full circle, and back to isolating privileged systems from the internet, on the basis of endpoint compromises stealing user session cookies.
Just making the authentication and service endpoints inaccessible online significantly reduces the attack complexity.
- wepple 3y agoExcept “inaccessible” != “vpn” There are a bunch of things folks forget when talking down zero trust; EG if it is done properly then the endpoint the user is using has to AuthN too, and be in good health. That solves cookie/token theft, forcing the attacker to fully route through the endpoint.
- bayindirh 3y agoActually, not putting administrative or sensitive servers behind a public key + certificate authenticated VPN baffles me. It's very simple and very effective. Also has no usability problems whatsoever.