5 ms·
Firewalls exist, many network environments block everything not explicitly allowed. Authentication is only part of the problem, networks are firewalled (with d
by bogantech 2y ago
Firewalls exist, many network environments block everything not explicitly allowed.
Authentication is only part of the problem, networks are firewalled (with dedicated appliances) and segmented to prevent lateral movement in the event of a compromise
- klysm 2y agoIsn’t that completely orthogonal? IP addresses aren’t authenticated, they can be spoofed
- bogantech 2y agoIt's not authentication. People aren't using static ips for authentication purposes But if I have firewall policies that allow connections only to specific services I need a destination address and port (yes, some firewalls allow host names but there's drawbacks to that) > IP addresses aren't authenticated, they can be spoofed For anything bidirectional you'd need the client to have a route back to you for that address, which would require you compromising some routers and advertising it via BGP etc. You can spoof addresses all you want but it will generally not do much for a stateful protocol
- otabdeveloper4 2y ago> People aren't using static ips for authentication purposes Lol. Of course they do. In fact, it's the only viable way to authenticate servers in Current Year. Unlike ssh host keys, of which literally nobody on this planet takes seriously, or https certificates which is just make-work security theater.
- klysm 2y agoNow this is an interesting take - I can’t tell if you are being serious
- otabdeveloper4 2y agoI am serious. Have you ever done infrastructure work? The big and serious guys all use IP whitelists. Look at how email actually works, for example.
- klysm 2y ago> People aren't using static ips for authentication purposes Unfortunately they are! I’ve seen up whitelistijg used as the only means of authentication over the WAN several times