Couple notes: * VPNs are not panacea. My own experience is that ssh and significant key management (no password or emergency password only) is a more scalable strategy than relying solely on VPNs for small business. The whole default port thing with ssh is a no-brainer (don't do it + restrictive configurations of ssh for port forwarding and tunneling) as are the standard approaches to dealing with abuse of any service (fail2ban, etc...) Add to this a design which sandboxes ssh access based on time/privilege and only allows escape|access to critical resources via another mechanism. * WAFs are great but are extremely high maintenance and can be a productivity and production malf and bottleneck waiting to happen. * DDOS mitigation: https://www.akamai.com/us/en/solutions/products/cloud-securi... or the like.
One example if you have an internal web service, how would you restrict access only to employees (without having it open to the internet?). SSO is not enough since you want the ports closed to non employees.
Another example is accessing a database that is not configured with SSL. You don't want your info travelling in plaintext on the internet.
$ ssh -D 8888 <bastion host>
I have a Firefox add-on that makes it very easy to switch the proxy settings on and off.I am not sure configuring these settings are trivial, and VPN clients provide that out-of-the-box.
1. We are a company that develops for iOS, so we have Apple computers and laptops... Nothing to be done about that. 2. We are on AWS, switching to Google Cloud is definitely not for everyone, definitely not just for this feature. 3. Even if we had not been developing for iOS, some developers really value working on a MacBook, and in a highly competitive recruiting market, that's a factor, and not an insignificant one.
Also, do you know of startups that use chrome books or toshiba zero client?
Also keep in mind that laptops are used by data scientists and management