Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
PLG88
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
181.
▲
by
PLG88
4y ago
I would say thats a bonus. Zero trust should be based on strong identity (e.g., x509) and authentication/authorisation-before-connect, ideally that identity would come from HWRoT/TPM. Unfortunately, many vendors say they are ze
182.
▲
by
PLG88
4y ago
I agree that it quickly became a radar for every single tech/vendor which slaps a 'zero trust' sticker on their product. Personally, I believe that while zero trust applies to all pillars, the most consequential is the networ
183.
▲
by
PLG88
4y ago
I would extend it to not inherently trusting the agent as well as being able to not have to trust the network (e.g., internet WAN) by closing all inbound ports by implementing authentication-before-connect using strong identity (e.g., x509)
184.
▲
by
PLG88
4y ago
I think its goes beyond this, its doing authentication-before-connect using strong identity so that we can have 'zero trust' of the network, whether internet/WAN (e.g., closed inbound ports), LAN or even host OS.
185.
▲
by
PLG88
4y ago
Fully agreed. Want you probably want is OpenZiti. It's a modern mesh overlay network which is explicitly built on zero trust principles including using strong embedded identity (with the ability to plug in 3rd party IdP). This ensures
186.
▲
by
PLG88
4y ago
Funny, this covers a lot from my post below ( https://news.ycombinator.com/reply?id=33234667&goto=item%3Fi... )... you cannot have zero trust, its really about less trust of the network (at least in the case of ZTNA). I w
187.
▲
by
PLG88
4y ago
You have both non-technical people ruining it as well as purists that say zero trust is a paradox in itself. They are both wrong in my opinion. I just gave a response on the latter in the CSA (message 57... long thread) - https://
188.
▲
by
PLG88
4y ago
Zero Trust pricniples may implie having a flat underlay but explicitly access to applications and services should be microsegmented, least privilege, and authenticate/authorised on strong identity before any connectivity can be establi
189.
▲
by
PLG88
4y ago
Tailscale would also need to natively provide segmentation, least privilege, attribute based access, endpoint posture checks, and do authentication/authorisation before connectivity is established. I believe they recommend a firewall d
190.
▲
by
PLG88
4y ago
Broad interpretagtion of zero trust to me... seems to be ZT application or workload only... not ZT network, device, identity or other aspects... am I wrong?
191.
▲
by
PLG88
4y ago
Aspects of it yes, that would be the principles of micro-segmentation and least privilege. There are other aspects of ZT principles, e.g., software-defined perimeters which OpenZiti delivers where this anology does not work. For example, SD
192.
▲
by
PLG88
4y ago
OpenZiti has some similarities to Wireguard/Tailscale... lets give s description of the former as thats then opensource vs opensource. Wireguard is built to be a better VPN and really cares about "connecting machines" and not
193.
▲
by
PLG88
4y ago
I have seen this comparison to Tor before. There are similarities related to the mesh overlay which OpenZiti operates. Sessions are routed according to a policy which can be security or performance-based (natively its routes to the lowest l
194.
▲
by
PLG88
4y ago
Yes, it is a zerotier alternative but there are key differences in how we do somethings... in fact, its on my list of things to do for creating some of these comparisons.... in the mean time, here is some comments on Ziti vs others - https
195.
▲
by
PLG88
4y ago
There is a lot of truth to this. To provide some further context on differences with a comparison of Tailscale and OpenZiti. - Tailscale is a great VPN, super easy to use. Being based on wireguard means, it differs from OpenZiti (note, I wo
196.
▲
by
PLG88
4y ago
FWI, the OpenZiti project 'integrated' their Go SDK into NATS last year - https://www.youtube.com/watch?v=8V_HlDZy6M8&ab_channel=OpenZ... . I say 'integrated' as it was a quick and dirty integration r
197.
▲
by
PLG88
4y ago
Zero trust (ZT) is a set of ideas to move defenses from static, network-based perimeters to focus on users, assets, and resources. It allows us to focus is on protecting resources and applications, not network segments (which are inherently
198.
▲
by
PLG88
4y ago
No ports are required to be opened at the edge (i.e., source and destination). The OpenZiti edge makes outbound connections using the strong identity into the fabric mesh network. Therefore its only the fabric dataplane which needs inbound
199.
▲
by
PLG88
4y ago
Many organisations do/used to operate where if a device was in a site (for example), it was trusted to access resources. SO in this scenario, using their definition of zero trust is more secure. The issue (in my opinion) is that ZT is
200.
▲
Open source blueprint for zero trust principles applied to autonomous vehicles
9 points
by
PLG88
4y ago
|
0 comments
201.
▲
by
PLG88
4y ago
One can only hope that it's these sort of events which slowly pushes to having more legislation and responsibility to the provider of digital services (i.e., Honda) if things go wrong (e.g., goods inside or even vehicle stolen). While
202.
▲
by
PLG88
4y ago
Nice! You should embed OpenZiti into it so that the K8S API can be dark and private from day 0 onwards with no inbound ports, public DNS configuration, complex FW rules, VPNs or ACLs. Here is how the team there embedded OpenZiti into Promet
203.
▲
by
PLG88
4y ago
Personally I do not like Teams. It's ok for calls, but it kills CPU/Ram on my mac. Also, its chat function it far inferior to Slack. Now I use Mattermost as my main tool but use the other 2 sometimes when needed.
204.
▲
by
PLG88
4y ago
You are shifting / reducing the attack suface. In your example, only B is 'open' on the internet, A and C are both dark and thus cannot be subject to attack. Further, B only 'accepts' connects to authenticated and a
205.
▲
by
PLG88
4y ago
Agreed pretty good site, but it is subtly pushing Cloudflare as they created this content. You'll notice that it's all framed to align with how they see zero trust as well as the products they integrate with.
206.
▲
Demystifying the magic of zero trust with my daughter and open source
2 points
by
PLG88
4y ago
|
0 comments
207.
▲
by
PLG88
4y ago
As some who works partially with marketing... this is exactly how it works. We build what reflects our incentives.
208.
▲
Gaming on the go: How I game remotely and keep my firewall “Perfect Dark”
(netfoundry.io)
8 points
by
PLG88
4y ago
|
0 comments
209.
▲
by
PLG88
4y ago
The performance results are really interesting. Any reasons or thoughts on why OpenZiti performs better than wireguard and solutions built on WG?
210.
▲
by
PLG88
4y ago
Nice work! "rise of Zero Trust ... like ZScaler ... why can't this be open-source and built on top of universal connectivity that works anywhere" Have you checked out OpenZiti? It's very similar to Zscaler ZPA in that it
More ›