3 ms·
You can't succeed with this model by just setting your firewall to allow 0.0.0.0/0. This approach still requires defense in depth, and a holistic view of secur
by tedchs 11y ago
You can't succeed with this model by just setting your firewall to allow 0.0.0.0/0. This approach still requires defense in depth, and a holistic view of security. If someone was able to deface your web app, then your company wasn't actually using all the components that are required to make this model work (such as authenticated devices, device patch management, and user 2-factor authentication).
- giovannibajo1 11y agoWhat are "authenticated devices"? The closest I can think of are client certificates being installed on the devices and used as a first-level of authentication. It could be anything from TLS client certificates to VPN certificates.
- mdwrigh2 11y agoYep, client certs installed on a device with verified boot and an account authenticated via 2FA would be a good start.
- lukeschlather 11y agoIf you do it right (store the cert in a TPM) the device itself actually is a second factor so you don't need anything other than the device.
- voltagex_ 11y agoWouldn't that require a browser plugin to login with?
- giovannibajo1 11y agoYou can have a SSO server that requires a TLS client certificate signed by your own internal CA, or you could put it behind a VPN authenticated with the certificate. Either way, with no custom software, you get device and use authentication.
- philipw 11y agoDevice patch management only works when there are patches available, ever heard of a 0day?