3 ms·
Our corporate Wi-Fi is shifting towards an open guess network. The idea blew the security team's mind, then COVID came and sure enough, most people worked from
by pwarner 2y ago
Our corporate Wi-Fi is shifting towards an open guess network. The idea blew the security team's mind, then COVID came and sure enough, most people worked from home or Starbucks or hotels etc, so all the sudden we had to assume the Wi-Fi network was insecure....
VPN to get to get to secured resources, and direct fast access to SaaS services.
- Gigachad 2y agoThe whole security mindset everywhere has shifted towards not trusting the network. Everything encrypted in between your laptop and the end server.
- dylan604 2y agoAnyone that ever had a policy of trusted devices on the network was just living in a fantasy land. The only reason the network ever had trusted devices was when it was in its infancy and there was nobody using it so the only devices on the net were the devices the admins put there. As soon as the first device that was not controlled by the admins was allowed to connect, the network should have been immediately untrusted. I've now taken my hindsight glasses off and recognize that it's hard to imagine that assholes and criminals would so easily ruin it for the rest of us. 50+ years later and ~30 years later of the interwebs and now it's an "but of course they would". The sad thing is that there should no longer be a blank sheet of paper for a startup, but every "new" sheet should already have defensive strategies on it. It's just not sexy, and hard to get to MVP so it's easy to drop/ignore/delay. I'm guilty too, but maybe I'm worse because I'm well aware that I'm doing it????
- avidiax 2y agoIPSec has been used for some time to provide a secure network where only trusted devices can communicate to each other or the infrastructure. You can still argue about the endpoint security, but at least the network participants and their messages can be secured, even if an endpoint is compromised.
- Hilift 2y agoA lot of orgs had VPN with forced tunneling before the pandemic. They caved on that in the first few days due to the increased usage and instant split tunneling with no planning. We also caught multiple people who connected unauthorized network connections and created unauthorized bridges/routes. These people exist and you don't know it until they start connecting stuff.
- generalizations 2y agoCalling "split tunneling" a bad thing is such a cargo cult. Even the good security the GP is describing is a split tunnel: "VPN to get to get to secured resources, and direct fast access to SaaS services".
- simonm21 2y agoSince Covid we have moved to a Zero Trust approach regarding all the things regarding the network. We have more and more access control on the LAN to avoid whoever to connect and now it's time for the Wi-Fi to change its implementation. Currently, most of companies have implemented an "Open SSID" to provide access to visitors, BYOD or partners. Because no other solution existed. Based on the Open SSID, we can configure multiple layers of security to avoid to have this network impacting the corporate network. But now, some mechanisms exist such like OWE to secure the association of device to the network. You may say that I need to have an OWE device to connect to an OWE network and you right, not all devices support this security mechanism. Based on a vendor solution, you can implement an "Open SSID" with a redirection mechanism allowing OWE device to connect to the SSID with OWE and other device which doesn't understand OWE will still connect to the Open SSID. So you keep one SSID with both functionalities and this is huge
- Simranjeet2709 2y agoWhen it comes to securing access through open SSIDs, the best way is to have the captive portal in place. Its the perfect way to to build a zero trust network, where in you don't trust anyone who connects to the SSID and is forced to authenticate through the captive portal. Put captive portal in place and force the users to validate through their phone numbers, social media accounts or emails. You can even integrate your existing IdP to the captive portal and even ask your employees to connect through the captive portal.