Restrict Access to your internal websites on AWS with BeyondCorp
1–10 of 59 posts
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#2Re: Restrict Access to your internal websites on AWS with BeyondCorp
#3Please let us know if you have any questions about getting started :)
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#4A lot of companies that care deeply about security are moving to this “trust no one” approach which has the added benefit for end users of allowing access to “secure internal sites” over the plain old internet. If done right this can all be a big boost for security and improved end user experience. That said, the old “you need to be on the VPN” approach is going to stick around for some time.
We did it for the security, but if I’d have known the convenience benefits, I think we’d have started earlier.
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#5A lot of companies that care deeply about security are moving to this “trust no one” approach which has the added benefit for end users of allowing access to “secure internal sites” over the plain old internet. If done right this can all be a big boost for security and improved end user experience. That said, the old “you need to be on the VPN” approach is going to stick around for some time.
At Transcend we are able to do it because we had an early focus on protecting our internal apps, but obviously it's a lot harder to migrate hundreds of services than to start out with a newer approach.
I loved not having to use a VPN back when I worked at Google though, and am glad to see that the open source world is starting to offer some tools to play around with.
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#6A lot of companies that care deeply about security are moving to this “trust no one” approach which has the added benefit for end users of allowing access to “secure internal sites” over the plain old internet. If done right this can all be a big boost for security and improved end user experience. That said, the old “you need to be on the VPN” approach is going to stick around for some time.
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#7Re: Restrict Access to your internal websites on AWS with BeyondCorp
#8Re: Restrict Access to your internal websites on AWS with BeyondCorp
#9The BeyondCorp paper explicitly mentions that the device state is taken into consideration when giving access to a user, i.e. that the device is identified and controlled, not just the user. It seems to me like it is an important part in the BeyondCorp access model, otherwise wouldn't this just be a SSO portal?
0: https://docs.microsoft.com/en-us/azure/active-directory/cond...
Re: Restrict Access to your internal websites on AWS with BeyondCorp
#10A lot of companies that care deeply about security are moving to this “trust no one” approach which has the added benefit for end users of allowing access to “secure internal sites” over the plain old internet. If done right this can all be a big boost for security and improved end user experience. That said, the old “you need to be on the VPN” approach is going to stick around for some time.
For sure, VPNs will always be used. I think it'll take a BeyondCorp SaaS company to really take off (or have it become a more "Managed"auth method from the big cloud providers). At Transcend we are able to do it because we had an early focus on protecting our internal apps, but obviously it's a lot harder to migrate hundreds of services than to start out with a newer approach. I loved not having to use a VPN back whe…