We tried this where I worked (with the exception of the evil desktop app financial program)... and had to retract after a zero day defacement in one of our web apps. In the meantime we also learned that keeping all of your web apps 100% up to date at all times is really freaking difficult. The good news is that the (failed) attempt got us off of a few client side applications and made us much more platform agnostic t…
Google Moves Its Corporate Applications to the Internet
21–30 of 155 posts
Re: Google Moves Its Corporate Applications to the Internet
#22As a remote worker, it's delightful to see things move in this direction, as VPNs are a regular thorn in my side. Of course, there's a certain irony that Google isn't fond of remote workers. :)
Re: Google Moves Its Corporate Applications to the Internet
#23As a remote worker, it's delightful to see things move in this direction, as VPNs are a regular thorn in my side. Of course, there's a certain irony that Google isn't fond of remote workers. :)
Re: Google Moves Its Corporate Applications to the Internet
#24Finally, the zero trust network has its day. I've been following this for quite a while, especially since this kind of architecture makes even more sense for smaller businesses than large ones that can pay for sophisticated network-edge protection. Edit: Great talk at lisa in 2013: https://www.usenix.org/conference/lisa13/enterprise-architec...
Re: Google Moves Its Corporate Applications to the Internet
#25We tried this where I worked (with the exception of the evil desktop app financial program)... and had to retract after a zero day defacement in one of our web apps. In the meantime we also learned that keeping all of your web apps 100% up to date at all times is really freaking difficult. The good news is that the (failed) attempt got us off of a few client side applications and made us much more platform agnostic t…
Re: Google Moves Its Corporate Applications to the Internet
#26I wonder which "cloud hosting provider" they will choose. Microsoft? Amazon? Does it make a difference? If my company starts selling cloud hosting and then I announce my company will be hosting its internal applications in "the cloud" (i.e., in my own data centers), what are the security implications for my company? Are they the same if some other company asks me to host their applications in my data centers? Is this…
Meant to be sarcastic? Google is in this market. Doesn't strike me that there is any chance they'd use MSFT or Amazon for infrastructure.
Re: Google Moves Its Corporate Applications to the Internet
#27We tried this where I worked (with the exception of the evil desktop app financial program)... and had to retract after a zero day defacement in one of our web apps. In the meantime we also learned that keeping all of your web apps 100% up to date at all times is really freaking difficult. The good news is that the (failed) attempt got us off of a few client side applications and made us much more platform agnostic t…
You can't succeed with this model by just setting your firewall to allow 0.0.0.0/0. This approach still requires defense in depth, and a holistic view of security. If someone was able to deface your web app, then your company wasn't actually using all the components that are required to make this model work (such as authenticated devices, device patch management, and user 2-factor authentication).
Re: Google Moves Its Corporate Applications to the Internet
#28As a remote worker, it's delightful to see things move in this direction, as VPNs are a regular thorn in my side. Of course, there's a certain irony that Google isn't fond of remote workers. :)
Google doesn't like workers who always work remotely, but periodically working from home (or the bus, or hotel, or coffeeshop, or the lobby at the auto mechanic, etc.) for a day is common for all employees.
Re: Google Moves Its Corporate Applications to the Internet
#29Earlier quoted context omitted.
You can't succeed with this model by just setting your firewall to allow 0.0.0.0/0. This approach still requires defense in depth, and a holistic view of security. If someone was able to deface your web app, then your company wasn't actually using all the components that are required to make this model work (such as authenticated devices, device patch management, and user 2-factor authentication).
What are "authenticated devices"? The closest I can think of are client certificates being installed on the devices and used as a first-level of authentication. It could be anything from TLS client certificates to VPN certificates.
Re: Google Moves Its Corporate Applications to the Internet
#30As a remote worker, it's delightful to see things move in this direction, as VPNs are a regular thorn in my side. Of course, there's a certain irony that Google isn't fond of remote workers. :)
Few workplaces are fond of remote workers. The major reason a lot of people remain employed is so they have a purpose to wake up, leave their houses, and spend the day occupied by the relative comfort of an office building, surrounded by reasonably-intelligent coworkers, as a faux-family. And it's a slap in their face that you don't want to spend your time basking in their physical proximity.