Live data from Hacker News

How to use BeyondCorp to ditch VPN, improve security and go to the cloud

blog.google

41–50 of 163 posts

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#41
I work for Duo Security, which this year launched the first major commercial implementation of BeyondCorp as a part of our product offering. Using it to jump on to the wiki, for diff reviews, and other internal resources has been excellent.

In addition to simple primary and second factor, you can design policies for MDM-controlled devices only (i.e. designing endpoints that are trusted for remote access), geolocation, and software versions on a per-application basis, for example.

I think save for a few use cases (SSH into your datacenter, e.g.), VPNs will be dead before we know it.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#42
post #34

Great to see them continue this series, and glad that this one touches on what it takes for other companies to achieve something similar. I talk about BeyondCorp a lot as evidence that the Zero Trust model works, and that employees will love it. The most common feedback I get is that it seems like too much of a stretch for companies that don’t operate at Google scale. That may be true if looking at the system as a wh…

The major barrier is really for companies that lack a lot of internal IT expertise. It's really dangerous for people who don't understand security and networking to just open up like this, since most enterprise software is grotesquely insecure out of the box. Everyone assumes LAN = safe = no need to worry about security. This is always false, but it's especially false if you're devolving away from LAN.

Very true... the "ditch your VPN" sure is a nice soundbite, but in reality it's the last thing you should be doing. I mean that literally... as in it's the last step. Better know what you're doing before getting there.

The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and understanding the traffic.

But the real point they make is that Internet != safe = very much worry about security.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#43
post #39
post #17

Earlier quoted context omitted.

This is incorrect! I began as a full-time remote employee and stayed so for 16 months until it made more sense for me to move to HQ. There are hundreds of remote workers, but being local has definitely allowed me to not need to rely on email and video chats so heavily. (Disclosure: Google employee)

How does one request full-time work in the interview? Is it normal to do it during the onboarding process?

Full-time remote work? If you're going to reach an agreement on where you will live and work it's better to do it as early in the process as possible. I'd say WELL before onboarding and interview. Like conversation #1 with the recruiter/internal contact. It's about mutual understanding and respect, and making sure your physical position would provide value.

The smaller the team, the better, but it's 100% on you to explain when there are 70,000 counter-examples in play. Same would go for discussing why a certain regional office (like Seattle) would maybe work vs. Mountain View. You have to be where you will give your best work to your self and team. I got really tired of flying back and forth and holding meetings being the one remote person out of ~12-20 got really ridiculous, so a move was inevitable for me.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#44
post #34

Earlier quoted context omitted.

The major barrier is really for companies that lack a lot of internal IT expertise. It's really dangerous for people who don't understand security and networking to just open up like this, since most enterprise software is grotesquely insecure out of the box. Everyone assumes LAN = safe = no need to worry about security. This is always false, but it's especially false if you're devolving away from LAN.

Very true... the "ditch your VPN" sure is a nice soundbite, but in reality it's the last thing you should be doing. I mean that literally... as in it's the last step. Better know what you're doing before getting there. The first couple BeyondCorp papers talk a lot about how Google deployed this architecture side-by-side their traditional LAN, and slowly migrated applications over, only after closely inspecting and un…

I'm not sure I understand the argument you're making here. A VPN offers you direct access to all the servers within your internal network. The BeyondCorp model offers you proxied access to only particular applications that have been opened up based on a wide variety of checks on the user and device accessing the application.

How is the latter going to be less secure than opening up your entire LAN to everyone who needs to access a single resource?

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#45
post #41

I work for Duo Security, which this year launched the first major commercial implementation of BeyondCorp as a part of our product offering. Using it to jump on to the wiki, for diff reviews, and other internal resources has been excellent. In addition to simple primary and second factor, you can design policies for MDM-controlled devices only (i.e. designing endpoints that are trusted for remote access), geolocation…

VPNs will remain because of SSH, eh?

https://github.com/google/huproxy

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#46
post #41

I work for Duo Security, which this year launched the first major commercial implementation of BeyondCorp as a part of our product offering. Using it to jump on to the wiki, for diff reviews, and other internal resources has been excellent. In addition to simple primary and second factor, you can design policies for MDM-controlled devices only (i.e. designing endpoints that are trusted for remote access), geolocation…

VPNs will remain because of SSH, eh? https://github.com/google/huproxy

I think you misunderstood. My point is that you will still need direct access into the network in order to work on the BeyondCorp servers themselves, for example -- not that SSH shouldn't, or couldn't, be covered under the zero trust model as well.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#47
post #17
post #8

Earlier quoted context omitted.

I thought Google doesn't allow remote work?

This is incorrect! I began as a full-time remote employee and stayed so for 16 months until it made more sense for me to move to HQ. There are hundreds of remote workers, but being local has definitely allowed me to not need to rely on email and video chats so heavily. (Disclosure: Google employee)

I concur: I'm typing this from my home office in Palm Springs, and I'm a Director at Google.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#48
post #13

Earlier quoted context omitted.

I know -- that's why I used the phrase "long-term". :) I probably shouldn't have used the word "plans" though, since I don't know for sure if they will implement it.

They very well could have patented it to prevent anyone else from doing it - which seems more likely.

Amazon employees are encouraged to patent basically anything, at least in AWS. Validity of content or relevance to future business plans isn't really a factor.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#49
post #7

Yesterday, I saw an article[1] about Amazon's plans to block websites in their stores (a very bad thing) and was wondering when a company like Google was going to launch a VPN service. I wonder if these things will meet in the long term. If companies that control the network try to limit access to information about their competitors, then their competitors might try to liberate that information. [1] http://gizmodo.co…

I'm the one who wrote that patent (sorry).

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#50
post #7

Yesterday, I saw an article[1] about Amazon's plans to block websites in their stores (a very bad thing) and was wondering when a company like Google was going to launch a VPN service. I wonder if these things will meet in the long term. If companies that control the network try to limit access to information about their competitors, then their competitors might try to liberate that information. [1] http://gizmodo.co…

One of the more interesting insights from the comments (which I agree with) was that the Amazon patent was for defensive purposes in order to prevent other companies from trying to implement such an idea in their stores. I have never given much thought to the idea of defensive patents, but if this is truly the intent of Amazon's patent then it's brilliant.

blush that was the intent.
Post reply on HN