Live data from Hacker News

How to use BeyondCorp to ditch VPN, improve security and go to the cloud

blog.google

131–140 of 163 posts

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#131
post #126

Earlier quoted context omitted.

Is logging into a VPN in 3 seconds and starting to work not "right away" enough?

Maintaining a stateful VPN connection is much harder than making a stateless HTTP request.

Modern VPN solutions allow for full IP roaming. Nothing to maintain really.

I see what these guys are trying to get at - its essentially how I run distributed services for my small business, but having a VPN in front of those is still a more secure option. VPN should not mean the keys to the kingdom and should indeed be restricted to a subset of explicitly exposed services.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#132
post #91

Earlier quoted context omitted.

It's plausible that they changed jobs ;).

bingo

I see -- I thought the patent was new. I'd ask you why you wrote a patent that allows large companies to block the open flow of online information (considering that it might prompt other companies to block information in different, but similar, ways), but I'm guessing that you won't be able to talk about it.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#136
post #7

Yesterday, I saw an article[1] about Amazon's plans to block websites in their stores (a very bad thing) and was wondering when a company like Google was going to launch a VPN service. I wonder if these things will meet in the long term. If companies that control the network try to limit access to information about their competitors, then their competitors might try to liberate that information. [1] http://gizmodo.co…

Google has a VPN service fyi. When you connect to a non secure network there's an option to proxy all traffic through a free Google VPN. http://www.androidpolice.com/2016/09/14/wifi-assistant-can-s...

To a Google-approved Wi-Fi network.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#137

How is this different or more secure than let's say TLS client authentication with the private key on a smart card / Yubikey?

They also take into account the state of the machine you're working on. So locked bootloader and probably a client cert in TPM-like component, plus "device health". Client certs alone are good for authentication (don't work in HTTP/2 though) but they want to reach even better target - no malicious software running on your computer. That's from reading old papers, I don't know if anything changed now.

Ah that's a good point, thanks!

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#140

Earlier quoted context omitted.

bingo

I see -- I thought the patent was new. I'd ask you why you wrote a patent that allows large companies to block the open flow of online information (considering that it might prompt other companies to block information in different, but similar, ways), but I'm guessing that you won't be able to talk about it.

If you are a good guy, getting a patent for X may help you prevent bad guys from using X.

Also if you don't patent X, somebody else might and then figure out a away to use it against you.

News sites too often write the patent articles in the form "company A plans to do Z" when the only fact available is that company A has applied a patent for Z. There's an incentive for a company to patent pretty much everything they can, since besides the patenting costs, there's no downside I'm aware of in having extra patents. The costs are probably negligible on Google/Amazon scale and when you have good processes.

Post reply on HN