This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.
This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.
If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network.
Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narrow the possible avenues of attack and it works. If your inner layer of authz fails its not the vpn's fault.
Whats your alternative? Just make every application and network endpoint publicly accessibly on the internet?
Yes, basically you should consider all networks untrusted including your internal network. You can still have a VPN but it shouldn't be the thing that protects the services inside your corp net because if it is then any breach means the intruder gets access to all your stuff.
The purpose of a VPN was never supposed to be the authentication layer to internal services. It's just a layer of security that makes it more difficult to carry out some types of attacks; thus increasing security defenses of an organization. Assuming that it has been breached is good practice, but doesn't mean that there's no point to it.... Unless layered security has been overturned?
VPN can be a security tool, as long as it is not your only security tool.
For these big companies (FAANG, Twitter too), please spend all those money on your security instead of market please.
Sorry, but what? I've worked in multiple small companies where the we where less than 5 system administrators and inside the vpn we had encrypted traffic and ldap auth on everything. It's a few days job for a single person to set everything up this way with open source tools that are extremely well known and documented.
My visceral reaction was "you got to have a VPN" as well but the more I thought about it the more I was convinced you don't _need_ a VPN.
Not sure if it still doesn't work effectively for that.
I'm all for debate but some things are close and shut. Yes, don't trust your user just because they are in the internal network, but no, that doesn't mean everything has to be visible from the outside.
Yes, yes we (more accurately "they") did. I don't know which schmuck with a blog came up with this idea that VPN is a thing of the past and a lot of people followed suit.
I bet there are IT shops out there that rely solely on VPN and the schmuck worked there, but that's like seeing somebody not lock their door and concluding doors are bad model for security and we should get rid of them.
your beyondcorp link has nothing to do with a well implemented vpn solution + standard access controls to network endpoints like the link suggests. Your clearly supporting a false dichotomy in which having a well constructed vpn solution is "wrong" and does not add to your overall security posture. Shenanigans.
vpn or not you still need to authorize/authenticate your network endpoints. But hey, you don't want a vpn so give me a list of your internet accessible ssh hosts and well see how well your "zero trust" gets you if you can't keep up with best practices. Good luck!
You can safely ignore anyone that unironically uses "anti-pattern" or "dark-pattern".
Yes, in a perfect world everyone would have an army of SecOps ninjas pentesting and patching all systems 24/7, but this is the Real World™
Defence in depth.
VPN and IP restrictions in general is a very good tool to limit the attack surface. That does not mean that Karen from accounting should be able to log into the production environment servers.
How do you jump from "VPN is not authorization" to "VPN is an anti-patern"? It's at a completely different layer than authorization ffs! You don't give up on seat-belts because they don't stop bullets coming through the windshield.
"Defense in depth" is not an anti-pattern. Using an VPN as the only layer is, certainly, but that is a straw man.
> If the account with VPN access is compromised, then the attacker has full access to these sensitive systems.
No. Logging in the VPN is one thing, logging into the internal systems requires an extra login
This is not hard
I could be wrong, but I think they mean that access to the internal site should have been behind VPN (whether at the IP network level or via an HTTP proxy) even when accessed over the internal network. That is, the internal network should not be trusted any more than the network at the cafe down the street.
By whom? It's another layer of security, nobody claimed it should be the sole defense.
It's a part of security, along with other multi-faceted authentication routes.