4 ms·
A lot of good stuff in the recommendations, but I find this one questionable: > “Enterprise applications should be able to be used over the public internet.”
by dataflow 2y ago
A lot of good stuff in the recommendations, but I find this one questionable:
> “Enterprise applications should be able to be used over the public internet.”
This is straight up arguing against defense-in-depth, and getting rid of connection auditing and interception capability. Seems extremely dubious, unless by "be able to" they mean "it should be OK security-wise if you get rid of the VPN" and not "you should actually get rid of the VPN".
- brendoelfrendo 2y agoThis is a fairly common recommendation for "zero trust." A VPN is theoretically superfluous in a zero trust environment, where you have no concept of a trusted network and your applications should be sufficiently hardened to prevent unauthorized access. Google operates this way, if I recall correctly. It's how their "Beyond Corp" white-paper recommends setting up the environment. It's not exactly a "one size fits all" solution; I believe PCI requires VPN usage, for example, so a bank trying to implement zero trust practices would need to keep their VPN intact, but that's a regulatory concern, not so much a technical one.
- dataflow 2y ago> A VPN is theoretically superfluous in a zero trust environment, where you have no concept of a trusted network and your applications should be sufficiently hardened to prevent unauthorized access. Defense in depth is theoretically superfluous in a secure system, but it's still a good idea for... what I thought were obvious reasons. I don't see how this is any different. And, again, as I mentioned above this isn't even just about network trust, it's also about the ability to monitor, audit, and intercept potentially malicious connections when something does get compromised. "We assume our one layer of security will work perfectly" cannot be the starting assumption... > Google operates this way, if I recall correctly. Google also has 24/7 world-class security teams monitoring everything across the planet. They have a ton of power to monitor and mitigate damage across the entire internet. Just because something works for Google that doesn't mean it'll work for arbitrary organizations.
- tptacek 2y agoYes. This is the right way to think about the OMB memo. Good thoughts, which may or may not apply to your organization.
- tptacek 2y agoDefense in depth is an idea that has probably done about as much harm as it's done good. The notion that your apps should be exposed on the public Internet is about clarifying the need for sound authentication on apps. In the OMBZT cinematic universe, there is no meaningful security benefit from being masked on a VPN, because so many different people get access to those VPNs. Your mileage will vary. I wouldn't expose internal apps on the public Internet even as I acknowledge the ideas OMBZT is pursuing make sense in OMB's setting.
- dataflow 2y ago> Defense in depth is an idea that has probably done about as much harm as it's done good Citation needed?
- tptacek 2y agoI'm not going to give you a citation. Historically, "defense in depth" has been a way to inoculate security tooling from critique or even assessment; things don't need to work at all in a "defense in depth" regime, because you can always say there's some marginal "fail2ban"-level utility to any countermeasure and retain it on that basis. It has in cases prevented meaningful defenses from being deployed, and has crudded up lots of people's attack surfaces. You see this most clearly in endpoint security, where "defense in depth" loaded everyone up with security and AV agents that were all riddled with memory corruption vulnerabilities.
- kibwen 2y agoBoth of the following can be true simultaneously: 1. The term "defense in depth" can be popularly abused by irresponsible people looking to pass the buck on security. 2. An application that is intended to withstand being exposed to the public internet becomes strictly more secure when it isn't exposed to the public internet. I can buy that the government contractors who fall into the former category are sufficiently numerous and sufficiently gormless that this memo is intended to be used as a weapon to drag them kicking and screaming towards default-secure applications. But for people who are already responsible enough that they're doing the right thing, keep using a VPN. Redundancy is resiliency.