Live data from Hacker News

How to use BeyondCorp to ditch VPN, improve security and go to the cloud

blog.google

141–150 of 163 posts

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#141

Earlier quoted context omitted.

Directors might get to work remotely. Good for you. I hope you enjoy Palm Springs while your reports are trapped on 101. Mere Developers are essentially never permitted to work remotely long-term. Google would rather lose someone valuable like Tim Bray to a major competitor than allow him to do so. If you're a global subject expert like Professor Hinton, maybe you'll be accommodated, but you dare don't mislead people…

Probably more dependent on one's immediate manager and/or chain than on company wide policy. Personally, I would not want to report to someone who spends the majority of time remote. But maybe this person is a really great boss.

> I would not want to report to someone who spends the majority of time remote

Why? There is really little to no difference if person is in next cubicle or video chat away.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#142
post #32

This is really awesome. My own venture ZeroTier (www.zerotier.com) was strongly influenced by the original BeyondCorp paper. Our vision is a little different in that we do network virtualization that treats the whole world like one data center. Instead of eliminating the LAN you make it fully virtual and mobile and replace the physical perimeter with a cryptographic one. Here's a somewhat over-simplified TL;DR on Goo…

ZeroTier is amazing. I tell everyone about it.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#143

Earlier quoted context omitted.

Probably more dependent on one's immediate manager and/or chain than on company wide policy. Personally, I would not want to report to someone who spends the majority of time remote. But maybe this person is a really great boss.

> I would not want to report to someone who spends the majority of time remote Why? There is really little to no difference if person is in next cubicle or video chat away.

I work on a team with another remote team, and I assure you this is not always the case.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#146
post #39
post #17

Earlier quoted context omitted.

This is incorrect! I began as a full-time remote employee and stayed so for 16 months until it made more sense for me to move to HQ. There are hundreds of remote workers, but being local has definitely allowed me to not need to rely on email and video chats so heavily. (Disclosure: Google employee)

How does one request full-time work in the interview? Is it normal to do it during the onboarding process?

When I'm applying for jobs I'll open with an email to their recruiter saying that I'm interested and intend to apply, but only if they can confirm they're open to me working remotely the majority of the time, I also mention my expected salary range. Doing it that way saves us both time and hassle in going through the motions only to find down the line that it would never have worked out because of either work arrangements or salary.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#147

Earlier quoted context omitted.

But if you don't provision the device yourself how can you be sure it hasn't been tampered with in a way that just displays "bootloader OK, everything good" but in the mean time it was rooted? Or is that a risk calculated in the "no full amount of trust"?

https://www.chromium.org/chromium-os/chromiumos-design-docs/...

That protects against newbies, but we’re talking here about Google employees – modifying and cloning the ICs on the board to fake a verified boot status should be a triviality for people who design their own chips and boards for Google’s own servers, right?

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#149

Earlier quoted context omitted.

https://www.chromium.org/chromium-os/chromiumos-design-docs/...

That protects against newbies, but we’re talking here about Google employees – modifying and cloning the ICs on the board to fake a verified boot status should be a triviality for people who design their own chips and boards for Google’s own servers, right?

On a Google-approved device, you can still use that device, and copy content to another, non-Google-approved device. Nothing is perfect, but at some point you trust your employees.

Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud

#150

Earlier quoted context omitted.

https://www.chromium.org/chromium-os/chromiumos-design-docs/...

That protects against newbies, but we’re talking here about Google employees – modifying and cloning the ICs on the board to fake a verified boot status should be a triviality for people who design their own chips and boards for Google’s own servers, right?

That would be covered by policy controls, not technical ones—it's the same issue as someone taking pictures of the screen with their personal phone. You'd need to address the actual issue that's causing people to do that (ill-thought-out policies, employee actually working for $INTELLIGENCE_AGENCY, employee enjoys espionage,…).
Post reply on HN