Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PLG88
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
PLG88
2y ago
Agreed. My point was that ZTNA requires more than just micro segmentation, it should also include deny by default, service based access, least privilege, endpoint posture checks etc.
92.
▲
by
PLG88
2y ago
I refer to doing service based connections, abstracted away from whether its DNS, IP or something else. To do this you really need a private DNS function and to operate with attribute based access controls. Complexity of policy mngt. I read
93.
▲
by
PLG88
2y ago
I would add, doing Zero Trust Networking properly means deny by default (VPNs are open by default), service based access (not whole host or network), microsegmentation (not whole network), and least privilege. You should also use posture ch
94.
▲
by
PLG88
2y ago
They do if they are building it into their product/commercial offering. Less so if its a direct and internal usage.
95.
▲
by
PLG88
2y ago
Through OpenZiti into the mix too - https://openziti.io/ . Its open source and was designed from the ground up with zero trust, SDN, and deny-by-default principles. It also includes SDKs to allow developers to embed ZTN as p
96.
▲
by
PLG88
2y ago
My understanding is that Twingate uses a service-based access model, rather than host/IP/ACL-based, as Wireguard defines the world. As you are based on WG, have you somehow paperer over that to move away from network trust and lac
97.
▲
by
PLG88
2y ago
OpenZiti would be another - https://openziti.io/ . I work on the project. 1 issue with Nebula is the provisioning new clients with identities. Its not completely open sourced by the Nebula company.
98.
▲
by
PLG88
2y ago
secured at the endpoints yes... I would argue you can go one step further, doing it at the application level. This is what we built (and open sourced) with OpenZiti ( https://openziti.io/ ), the ability to embed an overlay ne
99.
▲
by
PLG88
2y ago
We are trying to change that with OpenZiti - https://openziti.io/ . Its an open source network overlay built with zero trust principles and deny by default in mind. We also built it for developers, so includes SDKs and other
100.
▲
by
PLG88
2y ago
Check out OpenZiti then - https://openziti.io/ . Its Tailscale on steroids, with. (IMHO) a much more scalable implementation of zero trust principles.
101.
▲
by
PLG88
2y ago
Tons of alternatives. I like and work on open source OpenZiti - https://openziti.io/
102.
▲
by
PLG88
2y ago
Whole bunch of alternatives too - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a free SaaS with more security har
103.
▲
by
PLG88
2y ago
There are tons of options - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a free SaaS.
104.
▲
by
PLG88
2y ago
Why not go further and make it 'dark' or 'invisible' to the external network... thus its secure by default from external network attacks. As BunkerWeb is built on Nginx, this is relevant - https://blog.openzit
105.
▲
by
PLG88
2y ago
Note, on 'Price of Zrok' is says you need to host in a server. Thats true if you choose to self-host zrok, it has a free SaaS as well (which is more generous and capable than ngrok.
106.
▲
by
PLG88
2y ago
Agreed, thats why for production workloads it should be done with hardening and auth. Ngrok does that, as does Cloudflare. The version my company created does that too - https://blog.openziti.io/zrok-frontdoor
107.
▲
by
PLG88
2y ago
zrok is a similar capability (though it can potentially do a lot more). OpenZiti is definitely a more complex project. In fact, zrok was built on top of OpenZiti. We did this as Ziti provides a platform to develop secure by default, distrib
108.
▲
by
PLG88
2y ago
mispelling, zrok - https://zrok.io/ . Its open source and has a free SaaS (or paid if you want).
109.
▲
by
PLG88
2y ago
There are a whole bunch of alternatives too - https://github.com/anderspitman/awesome-tunneling . I will advocate for zrok.io as I work on its parent project, OpenZiti. zrok is open source and has a free SaaS as well as
110.
▲
by
PLG88
3y ago
For sure, this is why I personally believe sharing platforms (Funnel, CF Tunnel, ngrok, zrok etc) should all have security hardening, WAF-type features, and auth so that anyone cannot just scan and access your services. To me, this is table
111.
▲
by
PLG88
3y ago
Sure, I hear that argument. That is why zrok (zrok.io) and OpenZiti (CloudZiti) have SaaS services so that the hosting is outsourced to specialists.
112.
▲
by
PLG88
3y ago
Have you tried https://zrok.io/ ? Its open source so you can self-host with custom domains, has a free SaaS incl. reserved shares which give static, vanity URLs, and includes internet hardening/auth.
113.
▲
by
PLG88
3y ago
also https://zrok.io/ . Its open source, and has a free SaaS. Its also more comprehensive than Tunnelmore, e.g., supporting TCP or UDP tunnels.
114.
▲
by
PLG88
3y ago
Some similarities: though when app embedded we are not using a user space TCP stack, we have a suite of SDKs so that you can embed the ingress/egress, authentication, mTLS, E2EE, etc directly into your app, really easily - https:/
115.
▲
by
PLG88
3y ago
Another option is using zrok - https://zrok.io/ . Its open source so you could build it directly into Bluesky and either host the backend yourself or use the zrok free SaaS. zrok also has SDKs so you could embed the capabili
116.
▲
by
PLG88
3y ago
"and if at all possible keep them off the public internet", this is the way. I would recommend going beyond a VPN to implement zero trust networking which does outbound-only connections so that its impossible to be subject to exte
117.
▲
by
PLG88
3y ago
Yes, better to make your bastion 'dark' without being tied to an IP address. This is how we do it at my company with the open source tech we have developed - https://netfoundry.io/bastion-dark-mode/
118.
▲
by
PLG88
3y ago
This is the way, outbound only connections so you can stop all external unauthenticated attacks. I wrote a blog 2 years back comparing zero trust networking using Harry Potter analogies... what we are describing is making our resources 
119.
▲
by
PLG88
3y ago
I may be wrong, but I am pretty sure Tailscale Funnel isn't free, you have to be in their premium tier to use it... at least that's what the pricing page implies.
120.
▲
by
PLG88
3y ago
Whats your definition of 'protocol-first design'? Incentives definitely exist for the company I work for, which develops OpenZiti and zrok, and we do have a SaaS offering for both, but fundamentally we lead with the open source an
More ›