5 ms·
Static IPs for allowlists need to die already. Its 2024, come on, surely we can do better than this
by cactacea 2y ago
Static IPs for allowlists need to die already. Its 2024, come on, surely we can do better than this
- ekzhang 2y agoWhat would you suggest as an alternative?
- thatfunkymunki 2y agoa more modern, zero-trust solution like mTLS authentication
- ekzhang 2y agoThat makes sense, mTLS is great. Some services like Google Cloud SQL are really good about support for it. https://cloud.google.com/sql/docs/mysql/configure-ssl-instance https://cloud.google.com/sql/docs/mysql/configure-ssl-instan... It's not quite a zero-trust solution though due to the CA chain of trust. mTLS is security at a different layer though than IP source whitelisting. I'd say that a lot of companies we spoke to would want both as a defense-in-depth measure. Even with mTLS, network whitelisting is relevant. If your certificate were to be exposed for instance, an attacker would still need to be able to forge a source IP address to start a connection.
- thatfunkymunki 2y agoI'd put it in the zero-trust category if the server (or owner of the server, etc) is the issuer of the client certificate and the client uses that certificate to authenticate itself, but I'll admit this is a pedantic point that adds nothing of substance. The idea being that you trust your issuance of the certificate and the various things that can be asserted based on how it was issued (stored in TPM, etc), rather than any parameter that could be controlled by the remote party.
- PLG88 2y agoIf mTLS is combined with outbound connections, then IP source whitelisting is irrelevant; the external network cannot connect to your resources. This (and more) is exactly what we (I work on it) built with open source OpenZiti, a zero trust networking platform. Bonus points, it includes SDKs so you can embed ZTN into the serverless function, a colleague demonstrated it with a Python workload on AWS - https://blog.openziti.io/my-intern-assignment-call-a-dark-webhook-from-aws-lambda https://blog.openziti.io/my-intern-assignment-call-a-dark-we....
- sofixa 2y agoJWT/OIDC, where the thing you're authenticating to (like MongoDB Atlas) trusts your identity provider (AWS, GCP, Modal, GitLab CI). It's better than mTLS because it allows for more flexibility in claims (extra metadata and security checks can be done with arbitrary data provided by the identity provider), and JWTs are usually shorter lived than certificates.
- Thaxll 2y agoHow do you allow a driver using that exactly?
- sofixa 2y agoA db connection driver? You pass the JWT as the username/password which contains the information about your identity and is signed by the identity provider that the party you're authenticating to has been configured to trust. Or, you use a broker like Vault to which you authenticate with that JWT, and which generates a just in time ephemeral username/password for your database, which gets rotated at some point.
- ekzhang 2y agoWe have a native OIDC integration at Modal, as well! Every container gets a token. https://modal.com/docs/guide/oidc-integration https://modal.com/docs/guide/oidc-integration
- fusjdffddddddds 2y ago[flagged]
- sofixa 2y agoAwesome, great for you. OIDC/JWT for cross-stuff auth should become the norm.
- klysm 2y agoCompletely agree. IP addresses are almost never a good means of authentication. It results in brittle and inflexible architecture as well. Applications become aware of layers they should be abstracted from
- bogantech 2y agoFirewalls exist, many network environments block everything not explicitly allowed. Authentication is only part of the problem, networks are firewalled (with dedicated appliances) and segmented to prevent lateral movement in the event of a compromise
- klysm 2y agoIsn’t that completely orthogonal? IP addresses aren’t authenticated, they can be spoofed
- bogantech 2y agoIt's not authentication. People aren't using static ips for authentication purposes But if I have firewall policies that allow connections only to specific services I need a destination address and port (yes, some firewalls allow host names but there's drawbacks to that) > IP addresses aren't authenticated, they can be spoofed For anything bidirectional you'd need the client to have a route back to you for that address, which would require you compromising some routers and advertising it via BGP etc. You can spoof addresses all you want but it will generally not do much for a stateful protocol
- otabdeveloper4 2y ago> People aren't using static ips for authentication purposes Lol. Of course they do. In fact, it's the only viable way to authenticate servers in Current Year. Unlike ssh host keys, of which literally nobody on this planet takes seriously, or https certificates which is just make-work security theater.