Earlier quoted context omitted.
This would be paired with deterministic controls. So you have, for example, "engineers can only read from the database, and only after they've perform a 2FA" but then there's context like "why is this engineer reading from the payments table when their IP is in a weird location and they're supposed to be on PTO?" and perhaps that's something a model decides. It's possible to turn that second thing into a sort of "ris…
Non of it really matters if the end product is just going to be ignored because there's zero people who want to be the guard in the panopticon and therefore, it'll still be given to an AI to watch and make it's dumb decisions about how trust worthy you are to do X, Y and Z. Even if the middle is deterministic, if one end is just going to be lazily hooked up to an AI, it's the shitty dystopian future.
Google's Beyond Zero: Enterprise Security for the AI Era
21–30 of 87 posts
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#22Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)
This would be paired with deterministic controls. So you have, for example, "engineers can only read from the database, and only after they've perform a 2FA" but then there's context like "why is this engineer reading from the payments table when their IP is in a weird location and they're supposed to be on PTO?" and perhaps that's something a model decides. It's possible to turn that second thing into a sort of "ris…
Heck, many websites I visit on the web cannot understand why I, a Ghanaian living in Ghana, might be interested in the service offered or the information therein. I am sometimes blocked for no good reason.
If you are in a third world country, the web is extra hostile. This is going make things worse.
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#23Zero trust is deterministic. AI is non-deterministic Non-deterministic access controls is Terrible idea
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#24Zero trust is deterministic. AI is non-deterministic Non-deterministic access controls is Terrible idea
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#25Doesn't this simply shift the attack vector? Compromising this overlord brain now becomes a new target.
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#26Earlier quoted context omitted.
This would be paired with deterministic controls. So you have, for example, "engineers can only read from the database, and only after they've perform a 2FA" but then there's context like "why is this engineer reading from the payments table when their IP is in a weird location and they're supposed to be on PTO?" and perhaps that's something a model decides. It's possible to turn that second thing into a sort of "ris…
This is going to make things worse for all kind of use cases that are legitimate but seem non-standard or marginal. Heck, many websites I visit on the web cannot understand why I, a Ghanaian living in Ghana, might be interested in the service offered or the information therein. I am sometimes blocked for no good reason. If you are in a third world country, the web is extra hostile. This is going make things worse.
Isn't this for enterprises managing access to corporate resources?
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#27""" Beyond Zero shifts the trust boundary from the application to the action being performed on a piece of data in realtime—and from after-the-fact investigation to in-the-moment evaluation and containment. It augments BeyondCorp’s foundational identity with a “brain” capable of reasoning about the context and intent of a specific request in realtime. """ Doesn't this simply shift the attack vector? Compromising this…
Attribute-based access control is already a thing. User X logs in the US East between the hours of 6am and 6pm. If User X logs in from Russia at 3am, deny access. This seems like an evolution of that pattern
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#28""" Beyond Zero shifts the trust boundary from the application to the action being performed on a piece of data in realtime—and from after-the-fact investigation to in-the-moment evaluation and containment. It augments BeyondCorp’s foundational identity with a “brain” capable of reasoning about the context and intent of a specific request in realtime. """ Doesn't this simply shift the attack vector? Compromising this…
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#29Earlier quoted context omitted.
This is going to make things worse for all kind of use cases that are legitimate but seem non-standard or marginal. Heck, many websites I visit on the web cannot understand why I, a Ghanaian living in Ghana, might be interested in the service offered or the information therein. I am sometimes blocked for no good reason. If you are in a third world country, the web is extra hostile. This is going make things worse.
> This is going make things worse. Isn't this for enterprises managing access to corporate resources?
I don't think once this is established in enterprises it is going to stop there.
Re: Google's Beyond Zero: Enterprise Security for the AI Era
#30Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)
This would be paired with deterministic controls. So you have, for example, "engineers can only read from the database, and only after they've perform a 2FA" but then there's context like "why is this engineer reading from the payments table when their IP is in a weird location and they're supposed to be on PTO?" and perhaps that's something a model decides. It's possible to turn that second thing into a sort of "ris…