Live data from Hacker News

Google Moves Its Corporate Applications to the Internet

blogs.wsj.com

71–80 of 155 posts

Re: Google Moves Its Corporate Applications to the Internet

#71
post #65

One interesting question is: how many companies have enough public IP addresses to publish their applications to the internet? If you assume that there are multiple services and each one is hosted on their own server (or server farm), then you'd need many more public IP addresses. When we live in a world that is severely lacking free IPv4 space, how feasible is this? Or is this just a matter of pushing things from 10…

[deleted]

Re: Google Moves Its Corporate Applications to the Internet

#72
I wonder how far this really extends into their network and how ipv6 is related. In principal it sounds really good to me. I realize this is mostly about access to corporate applications, but how much further could this approach go?

Thinking out loud, if I suddenly removed the firewall perimeter security from my network, moved security to devices/servers directly, dropped my NAT, switched to ipv6 with all publicly routable addresses, my network infrastructure simplifies incredibly. However, I do have to still protect my network to ensure network quality of service/availability and protect my devices/equipment from "public attacks". I guess the principal here is, the surface area that can be attacked is the same if you can penetrate the layered security approach - it all ends in the devices and equipment.

The fact that all devices/equipment can now have an publicly routable/addressable IP in ipv6 solves the problem of running out of address space, and would fit hand in glove with such an architecture.

Put another way, the network becomes just the network, without the need to discern between the intranet/LAN, the extranet/WAN (or DMZ) and the Internet/WAN.

Re: Google Moves Its Corporate Applications to the Internet

#73
Really so they are using a 3rd party hosted HR systems etc on the internet, or something on their own services?

When you are talking about a company like Google that basically owns a large part of the internet (backbones, CDNs, hosting services) "moving stuff to the internet" it means a lot less than a non IT company like a bank.

Re: Google Moves Its Corporate Applications to the Internet

#74
post #38

I'm so happy to see this. As Bruce Schneier (who runs an open WiFi network at home) explains, "if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1] The same is true for corporate applications (and devices like printers). If they're not secure on a public network, securing the corporate network won't reduce their risk that much: they're still exposed to…

There are other, valid reasons to not run a public access point. Not wanting neighbors to steal your bandwidth, run a TOR node off it, or host illegal content, for example. All of these activities could get you removed from your ISP, and even taken to court. While you could probably prove your innocence in court, I can not imagine why taking the risk for absolutely no personal benefit is worth the risk. I don't really see how running an open wifi network shows anything other than ignorance of the risks.

Re: Google Moves Its Corporate Applications to the Internet

#75
post #65

One interesting question is: how many companies have enough public IP addresses to publish their applications to the internet? If you assume that there are multiple services and each one is hosted on their own server (or server farm), then you'd need many more public IP addresses. When we live in a world that is severely lacking free IPv4 space, how feasible is this? Or is this just a matter of pushing things from 10…

Any sane design is going to have exactly one ingress/egress for end-user traffic per application. Even an application with a few hundred servers is only going to be available to end-users at 1 IP address (maybe several for load balancing/redundancy).

It wouldn't be hard to add a global reverse-proxy/load-balancer HA cluster at the actual network edge forwarding traffic to individual applications' own load balancers.

Re: Google Moves Its Corporate Applications to the Internet

#76

I wonder how far this really extends into their network and how ipv6 is related. In principal it sounds really good to me. I realize this is mostly about access to corporate applications, but how much further could this approach go? Thinking out loud, if I suddenly removed the firewall perimeter security from my network, moved security to devices/servers directly, dropped my NAT, switched to ipv6 with all publicly ro…

>can now have an publicly routable/addressable IP in ipv6

Almost no one can actually route "publicly routable" IPv6. When it becomes a standard feature of DSL/cable, maybe.

Re: Google Moves Its Corporate Applications to the Internet

#77
post #38

I'm so happy to see this. As Bruce Schneier (who runs an open WiFi network at home) explains, "if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1] The same is true for corporate applications (and devices like printers). If they're not secure on a public network, securing the corporate network won't reduce their risk that much: they're still exposed to…

Does Bruce have his open-wifi clients connections pass through a VPN (in-between him and clients destination) ...

Re: Google Moves Its Corporate Applications to the Internet

#78
post #20

As a remote worker, it's delightful to see things move in this direction, as VPNs are a regular thorn in my side. Of course, there's a certain irony that Google isn't fond of remote workers. :)

Few workplaces are fond of remote workers. The major reason a lot of people remain employed is so they have a purpose to wake up, leave their houses, and spend the day occupied by the relative comfort of an office building, surrounded by reasonably-intelligent coworkers, as a faux-family. And it's a slap in their face that you don't want to spend your time basking in their physical proximity.

You can wake up, leave your house and go to a confortable office building surrounded by people working in the same industry by going to a coworking space.

As a remote worker I actually want to have this routine, meet people, this is why I go to a coworking space.

The benefit of remote work is that you can have much more choice in the company you work for, without having to move to SF/NY/London/Paris/.

Re: Google Moves Its Corporate Applications to the Internet

#79

Earlier quoted context omitted.

Could you explain what you mean about the incentives from tax and accounting policy? Are you saying that tax benefits for having office space are richer than the actual expense of renting that office space?

In the USA, you can deduct your business expenses (including building rental) from your profits for tax purposes. This creates a huge incentive to rent, as it's basically free - the company is basically paying part of their tax payment to their landlord.

It's not even close to free. It's X% cheaper where X is the tax rate the company is paying.

eg.

$10,000 in gross profit - 20% in taxes = $8,000 net profit

$10,000 in gross profit - $1,000 rent = $9,000 - %20 taxes = $7,200 net profit

The net rent was $800 instead of $1,000 but not free.

Re: Google Moves Its Corporate Applications to the Internet

#80
post #38

I'm so happy to see this. As Bruce Schneier (who runs an open WiFi network at home) explains, "if my computer isn't secure on a public network, securing my own network isn't going to reduce my risk very much."[1] The same is true for corporate applications (and devices like printers). If they're not secure on a public network, securing the corporate network won't reduce their risk that much: they're still exposed to…

There are other, valid reasons to not run a public access point. Not wanting neighbors to steal your bandwidth, run a TOR node off it, or host illegal content, for example. All of these activities could get you removed from your ISP, and even taken to court. While you could probably prove your innocence in court, I can not imagine why taking the risk for absolutely no personal benefit is worth the risk. I don't reall…

Do you think Schneier is ignorant of the risks?
Post reply on HN