It seems there can still be lateral re-infection via difficult to patch shared services (finance/procurement/obscure wikis). The examples in one of the papers (delivery people not needing access to financial systems) is completely bogus -- sometimes the worst engineered, most xss-y, mission critical apps have to be accessed by everyone, have insanely hand coded 'business logic', and no docs. Content aware behavioral profiling would seem to have a role in managing that risk.
How to use BeyondCorp to ditch VPN, improve security and go to the cloud
151–160 of 163 posts
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#152Earlier quoted context omitted.
That protects against newbies, but we’re talking here about Google employees – modifying and cloning the ICs on the board to fake a verified boot status should be a triviality for people who design their own chips and boards for Google’s own servers, right?
That would be covered by policy controls, not technical ones—it's the same issue as someone taking pictures of the screen with their personal phone. You'd need to address the actual issue that's causing people to do that (ill-thought-out policies, employee actually working for $INTELLIGENCE_AGENCY, employee enjoys espionage,…).
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#153This is really awesome. My own venture ZeroTier (www.zerotier.com) was strongly influenced by the original BeyondCorp paper. Our vision is a little different in that we do network virtualization that treats the whole world like one data center. Instead of eliminating the LAN you make it fully virtual and mobile and replace the physical perimeter with a cryptographic one. Here's a somewhat over-simplified TL;DR on Goo…
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#154Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#155Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#156Earlier quoted context omitted.
The major barrier is really for companies that lack a lot of internal IT expertise. It's really dangerous for people who don't understand security and networking to just open up like this, since most enterprise software is grotesquely insecure out of the box. Everyone assumes LAN = safe = no need to worry about security. This is always false, but it's especially false if you're devolving away from LAN.
The illusion that it's okay to run cleartext, unauthenticated services on an internal network is also pretty dangerous. Making it clear that the network is out in public might actually yield a better security posture overall. If an organization is doing 802.1x, competently manages its endpoints (this is a tiny, tiny fraction of "managed" Windows sites), etc then maybe a BeyondCorp-style architecture is a net loss of…
It's hard enough to get them to adopt IPv6 since most think NAT is essential for security. "But my address is world reachable!" Face palm...
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#157This sounds a lot like Microsoft's DirectAccess which has been in the Enterprise version of Windows since Windows 8. Please correct me if I'm wrong though.
Kind of. Microsoft sold it more as an always-on VPN. They weren't selling a radically different philosophy for securing your network with it. But regardless of the differences Microsoft really hamstrung themselves by making it so Windows centric.
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#158Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#159Earlier quoted context omitted.
I see -- I thought the patent was new. I'd ask you why you wrote a patent that allows large companies to block the open flow of online information (considering that it might prompt other companies to block information in different, but similar, ways), but I'm guessing that you won't be able to talk about it.
If you are a good guy, getting a patent for X may help you prevent bad guys from using X. Also if you don't patent X, somebody else might and then figure out a away to use it against you. News sites too often write the patent articles in the form "company A plans to do Z" when the only fact available is that company A has applied a patent for Z. There's an incentive for a company to patent pretty much everything they…
Re: How to use BeyondCorp to ditch VPN, improve security and go to the cloud
#160Earlier quoted context omitted.
This should be seen as a defensive move so they can sue anyone who comes to market with a product that blocks the shopper's ability to search Amazon while in a given store. Showrooming benefits Amazon and will continue to until they have a majority of retail space (never).
Back in the day, the one-click patent was claimed to be defensive, too. These decisions tend to be opportunistic. Or maybe a holder honestly convinces themselves that this particular offensive use is really a "defensive" move. I give these sorts of declarations the same value I give crime-law proposals where someone pushing it declares that it would never be used in that way.