Live data from Hacker News

Google Moves Its Corporate Applications to the Internet

blogs.wsj.com

101–110 of 155 posts

Re: Google Moves Its Corporate Applications to the Internet

#101
What has changed? I worked as a contractor at Google in 2013. Everyone had a securely locked down company laptop. All logins anywhere required a dual auth device.

I was really sick one day and I had no problems doing my work from home. Also, one of the great joys of working at Google is the availability of code labs that are individualized instruction to learn different aspects of their infrastructure and technology in general. I spent a ton of time when at home working through code labs that were relevant to my job. No problems with remote access.

Re: Google Moves Its Corporate Applications to the Internet

#102
post #81

Earlier quoted context omitted.

This law needs to change. An Internet connection isn't a gun. Just because somebody uses my Internet connection to do something illegal, I didn't do anything illegal.

Pretty sure that's not how guns work either

If you leave your gun lying around and someone commits a crime with it, I'm pretty sure that's criminal negligence.

Re: Google Moves Its Corporate Applications to the Internet

#103
This seems like the sort of thing that can work for Google because Google runs on Google software, which runs on Google hardware. They control the full stack from top to bottom, so they can decide where to put the doors and where to put the monitoring.

Most companies run on stuff that is not their own. Microsoft Exchange running on Windows running on VMWare running in some 3rd party datacenter is a fairly modern way to host an email server. In that situation, everything is out of your hands BUT the network edge. You don't audit Microsoft's code bases, you don't specify how Webmail works, you don't control the discovery, disclosure, or patching of critical vulnerabilities.

Sure maybe the firewall/IDS/VPN only keeps amateur griefers out, but there are way more of those than APTs.

And folks will only have limited insight into the internals of all this 3rd-party software. But if you have a gated network, then you can use a tool like NetWitness to characterize and alert on your traffic--and just your traffic.

Re: Google Moves Its Corporate Applications to the Internet

#104
post #38

I'm so happy to see this. As Bruce Schneier (who runs an open WiFi network at home) explains, "if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1] The same is true for corporate applications (and devices like printers). If they're not secure on a public network, securing the corporate network won't reduce their risk that much: they're still exposed to…

There are other, valid reasons to not run a public access point. Not wanting neighbors to steal your bandwidth, run a TOR node off it, or host illegal content, for example. All of these activities could get you removed from your ISP, and even taken to court. While you could probably prove your innocence in court, I can not imagine why taking the risk for absolutely no personal benefit is worth the risk. I don't reall…

I am fully aware of the risks and I judge them to be negligible in practice. I've been running open wifi at home since 2002.

Re: Google Moves Its Corporate Applications to the Internet

#105

Earlier quoted context omitted.

Do you think Schneier is ignorant of the risks?

Bruce Schneier is a very smart guy, but let's not deify him; he can be wrong about things too. For example in the above column he repeats an urban myth: that running an open WiFi access point provides an affirmative defense against prosecution for things like piracy, hacking, or child porn. I call it an urban myth because, personally, I have yet to find a court case in which such an argument was made, let alone one i…

People assert the counterexample, too, but in reality it's hard to find real cases where anything bad happened as a result of running an open wifi network.

Re: Google Moves Its Corporate Applications to the Internet

#106

Earlier quoted context omitted.

Do you think Schneier is ignorant of the risks?

Bruce Schneier is a very smart guy, but let's not deify him; he can be wrong about things too. For example in the above column he repeats an urban myth: that running an open WiFi access point provides an affirmative defense against prosecution for things like piracy, hacking, or child porn. I call it an urban myth because, personally, I have yet to find a court case in which such an argument was made, let alone one i…

He said later (~2-3 years ago) that he may change his attitude exactly because of possible liability.

Re: Google Moves Its Corporate Applications to the Internet

#107

Earlier quoted context omitted.

Do you think Schneier is ignorant of the risks?

Bruce Schneier is a very smart guy, but let's not deify him; he can be wrong about things too. For example in the above column he repeats an urban myth: that running an open WiFi access point provides an affirmative defense against prosecution for things like piracy, hacking, or child porn. I call it an urban myth because, personally, I have yet to find a court case in which such an argument was made, let alone one i…

https://torrentfreak.com/judge-an-ip-address-doesnt-identify... ?

not quite what you're looking for, but effectively the right thing. an ip address does not identify you personally, the same way a drivers license does.

Re: Google Moves Its Corporate Applications to the Internet

#108
post #82

Earlier quoted context omitted.

>can now have an publicly routable/addressable IP in ipv6 Almost no one can actually route "publicly routable" IPv6. When it becomes a standard feature of DSL/cable, maybe.

Your information is out of date. Every T-Mobile subscriber with a modern Android device on LTE has a fully-working, native ipv6 address. And somewhere between 30% and 50% of Comcast subscribers already have native dual-stack ipv6.

Time Warner Cable supports IPv6 as well.

Re: Google Moves Its Corporate Applications to the Internet

#109
post #102

Earlier quoted context omitted.

Pretty sure that's not how guns work either

If you leave your gun lying around and someone commits a crime with it, I'm pretty sure that's criminal negligence.

If you leave your gun loaded and your kid shoots someone - yes.

If you leave your gun and someone 'steals' it to kill others - I don't think so.

It's all about intentions of third party which is one of many paradoxes of the law system.

Re: Google Moves Its Corporate Applications to the Internet

#110
post #38

I'm so happy to see this. As Bruce Schneier (who runs an open WiFi network at home) explains, "if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1] The same is true for corporate applications (and devices like printers). If they're not secure on a public network, securing the corporate network won't reduce their risk that much: they're still exposed to…

Private network is just another layer on top.

Google did not just throw away this layer, but replaced with device authentication. They are essentially using two factor authentication.

Post reply on HN