The idea is that drawing a clear line between outside and inside became futile and you are much better off with an approach that recognizes that fact. Their somewhat provocative slogan is: "The perimeter is dead".
For those working at FAANG: Do you have a corporate VPN? Do you use it? Do you need it for your daily work?
[1] https://www.usenix.org/system/files/login/articles/login_dec...
When I was at Microsoft, you still needed a VPN to connect to your dev machine and write code, but more and more internal services were moving to a zero-trust model that didn't require a VPN. Not sure if they've gotten there 100%, but it felt like the clear direction.
No access for anyone while you scale your VPN? Just wait while everyone pulls and pushes gigs of data over the VPN to perforce, you didn’t need that video meeting after all?
You’ll get a big fat nope to that when you try to do it; this is a pretty tough challenge you’re trivialising here.
Google “zero trust” as an alternative; clearly they didn’t do that properly either, but I can at least understand why they didn’t just demand everyone use a VPN.
Trivial VPN use cases like people who d/l source code and have then occasional 5 person video meeting and this use case are not the same thing.
The companies that do it well implement something like google's beyondcorp, the bad just uses direct authentication.
They’re the ones getting screwed over the most here imo