Live data from Hacker News

Google Moves Its Corporate Applications to the Internet

blogs.wsj.com

111–120 of 155 posts

Re: Google Moves Its Corporate Applications to the Internet

#111
post #53

Earlier quoted context omitted.

Few workplaces are fond of remote workers. The major reason a lot of people remain employed is so they have a purpose to wake up, leave their houses, and spend the day occupied by the relative comfort of an office building, surrounded by reasonably-intelligent coworkers, as a faux-family. And it's a slap in their face that you don't want to spend your time basking in their physical proximity.

>it's a slap in their face that you don't want to spend your time basking in their physical proximity That's slightly self-centered. Nobody cares about you or their co-workers so much that they are offended if you don't want to work (or bask) in the team's presence. People are tribal by nature, and one of the ways humans feel a sense of belonging is through overcoming common conflict (i.e. Tuckman's stages). While no…

> People are tribal by nature

People were tribal before communication tech.

That said the company success will depend on how frequently the information can be mixed up. That said, some roles do not need as much communication as others, especially in mature business and niche positions.

Re: Google Moves Its Corporate Applications to the Internet

#112
post #49

Earlier quoted context omitted.

The only way to succeed with this is with heavy firewalling or VPNs. There are several unknown zero days in any application so just by opening up your application to 0.0.0.0/0 makes it possible for blackhats to get in. The only question is how much your information is worth for somebody. If you it is less than price of a brand new zero day you might be ok, but there are still the script kiddies and political blackhat…

> There are several unknown zero days in any application I think you want all your applications to authenticate the device and the user before proceeding to anything. This looks indeed impossible with third party closed source apps (if only because you can never be sure there is no backdoor). Then, even if you authenticate every remote peers using TLS client certificates, you have to follow closely the vulnerabilitie…

This looks indeed impossible with third party closed source apps (if only because you can never be sure there is no backdoor).

Seems easy enough: don't allow the app to bind to a port on any interface besides loopback, then put an authenticating reverse proxy in front of it that can actually receive remote connections.

If it's an HTTP service, you can use nginx with client SSL certificates. For other protocols, spiped[1] might be a good choice.

[1] https://www.tarsnap.com/spiped.html

Re: Google Moves Its Corporate Applications to the Internet

#113
post #102

Earlier quoted context omitted.

If you leave your gun lying around and someone commits a crime with it, I'm pretty sure that's criminal negligence.

If you leave your gun loaded and your kid shoots someone - yes. If you leave your gun and someone 'steals' it to kill others - I don't think so. It's all about intentions of third party which is one of many paradoxes of the law system.

Right, but if someone steals your registered gun and uses it in a crime that gets traced to your gun, the police will be visiting you, if not arresting and prosecuting. For this reason, I'd assume it's smart to do what you can to avoid having your gun being used by strangers. For the same reason, you could argue it's smart to not let strangers use your internet connection, even if theoretically you can make a case that you're not legally responsible.

Re: Google Moves Its Corporate Applications to the Internet

#114

Earlier quoted context omitted.

If you leave your gun loaded and your kid shoots someone - yes. If you leave your gun and someone 'steals' it to kill others - I don't think so. It's all about intentions of third party which is one of many paradoxes of the law system.

Right, but if someone steals your registered gun and uses it in a crime that gets traced to your gun, the police will be visiting you, if not arresting and prosecuting. For this reason, I'd assume it's smart to do what you can to avoid having your gun being used by strangers. For the same reason, you could argue it's smart to not let strangers use your internet connection, even if theoretically you can make a case th…

What is a registered gun? I have plenty of guns, none of them are registered.

Re: Google Moves Its Corporate Applications to the Internet

#115

Earlier quoted context omitted.

Right, but if someone steals your registered gun and uses it in a crime that gets traced to your gun, the police will be visiting you, if not arresting and prosecuting. For this reason, I'd assume it's smart to do what you can to avoid having your gun being used by strangers. For the same reason, you could argue it's smart to not let strangers use your internet connection, even if theoretically you can make a case th…

What is a registered gun? I have plenty of guns, none of them are registered.

Guns in Europe are registered and you are obliged to have a dedicated safe.

That said, it's better not to own a gun.

Re: Google Moves Its Corporate Applications to the Internet

#116
post #90

Earlier quoted context omitted.

Do you think Schneier is ignorant of the risks?

>Certainly this does concern ISPs. Running an open wireless network will often violate your terms of service. But despite the occasional cease-and-desist letter and providers getting pissy at people who exceed some secret bandwidth limit, this isn't a big risk either. The worst that will happen to you is that you'll have to find a new ISP. ^ FTA. Not "ignorant", but more flippant. Not everyone has options when it com…

Or unlimited bandwidth. There's no way I'd run open WiFi in Australia because I only have a finite amount of downloading I can do, and I pay for the amount I expect to use myself so can't afford other people leeching off my connection.

Re: Google Moves Its Corporate Applications to the Internet

#117

Earlier quoted context omitted.

Right, but if someone steals your registered gun and uses it in a crime that gets traced to your gun, the police will be visiting you, if not arresting and prosecuting. For this reason, I'd assume it's smart to do what you can to avoid having your gun being used by strangers. For the same reason, you could argue it's smart to not let strangers use your internet connection, even if theoretically you can make a case th…

What is a registered gun? I have plenty of guns, none of them are registered.

This varies by country. In Australia if I want a gun I need to have a firearms license, I have to register every weapon I own and store them in an safe that meets certain minimum requirements (separate ammunition, requires key and combination to enter, minimum thickness, rules about how it is secured to the wall/floor, etc) and at any time the police can show up and ask me to show them I have the weapons correctly secured.

Or I could rent appropriate storage space at a gun club, store the weapons that way.

It's a completely different gun culture to what is seen in the US, and personally I like it a lot more.

Re: Google Moves Its Corporate Applications to the Internet

#118
post #82

Earlier quoted context omitted.

>can now have an publicly routable/addressable IP in ipv6 Almost no one can actually route "publicly routable" IPv6. When it becomes a standard feature of DSL/cable, maybe.

Your information is out of date. Every T-Mobile subscriber with a modern Android device on LTE has a fully-working, native ipv6 address. And somewhere between 30% and 50% of Comcast subscribers already have native dual-stack ipv6.

Somewhere between 50 and 80% of Comcast subscribers, then, do not have IPv6. In a couple years, yes this should be viable, but it isn't now.

Re: Google Moves Its Corporate Applications to the Internet

#119

Earlier quoted context omitted.

Right, but if someone steals your registered gun and uses it in a crime that gets traced to your gun, the police will be visiting you, if not arresting and prosecuting. For this reason, I'd assume it's smart to do what you can to avoid having your gun being used by strangers. For the same reason, you could argue it's smart to not let strangers use your internet connection, even if theoretically you can make a case th…

What is a registered gun? I have plenty of guns, none of them are registered.

They all have serial numbers, and you had to show ID when buying them. So yes they are registered, you just might not be aware of this fact.

Re: Google Moves Its Corporate Applications to the Internet

#120

Earlier quoted context omitted.

What are "authenticated devices"? The closest I can think of are client certificates being installed on the devices and used as a first-level of authentication. It could be anything from TLS client certificates to VPN certificates.

Yep, client certs installed on a device with verified boot and an account authenticated via 2FA would be a good start.

Wouldn't that require a browser plugin to login with?
Post reply on HN