3 ms·
Oh yikes. So the industry has basically just gone and reinvented the very premise Google built BeyondCorp to mitigate, starting back in 2009. IIUC the baselin
by exikyut 2y ago
Oh yikes.
So the industry has basically just gone and reinvented the very premise Google built BeyondCorp to mitigate, starting back in 2009.
IIUC the baseline premise was to move away from "login to the VPN and you're inside the corporate network and you can access everything". It was incredibly convenient but a logistical nightmare in practice.
The BeyondCorp approach was to integrate authentication into each product so that the access control could be managed on a case by case basis.
Google standardised on OAuth across the board, and had a centralised login protocol/API with a WAF etc, but each product called out to this, and policy was decided by the calling application. This approach shines through to the whole Login with Google ideology.
Thinking about it, I wonder how much corporate/enterprise/even SOHO OAuth is effectively the inverse of this approach - login to eg Auth0 once and you immediately have access to all your apps.
That approach isn't technically broken, but it feels a bit like there's an antipattern here in the encouragement of centralised policy management. That just encourages everyone to think about "login once!" just like the old VPNs.
And it's just hilarious how everyone's just... wandered in this direction. First VPNs, then "centralised access bad", then BeyondCorp, then OAuth, then "login once!", and back to the beginning.
At least the web gives you the tools to setup siloed authentication per app. VPNs don't provide that level of slicing and dicing. So it's easier to fix, and merely a (complex) security design problem now.
- zoover2020 2y agoAmazon is no different, needs a $bigCorp in your story there
- exikyut 2y agoIs Amazon on the "built a BeyondCorp clone" side, or the "Auth0 is the new VPN!" side?
- 12345ieee 2y ago> a logistical nightmare in practice Could you elaborate? I'd like to learn from the errors of the past
- deleted 2y ago[deleted]
- ricktdotorg 2y ago[assuming you're using best practices etc] having your users log into a centralized VPN means that you've got all your different on-prem/DC services and services all in well-designed tightly-controlled VLANs with pinhole access network ACLs between them. additionally, you've got your VPN users in tightly-controlled role-specific VPN groups in their own IP pools that are again additionally tightly-controlled via network ACLs. all of this takes time to setup, run and monitor. unless you run a tight ship with automation helping many of these steps and layers, it can be a logistical nightmare. maybe that's GP meant.
- deleted 2y ago[deleted]
- theamk 2y agoI don't see how Slack is not the prime example of BeyondCorp approach? No VPN or firewall, all access control is done via centralized system. I don't know what Disney was using for identity, but it could have even been Google. After all, what could have been done differently? Require password retype/MFA multiple times per day? This would drive people crazy, and if the computer ia infected then credentials could be stolen anyway.