A case against Layer 4 security tools
pomerium.com
pomerium.com
Disrupt productivity Increase workload and margin of error No monitoring capability Poor security, utilizing a flawed and incomplete security model
None of which are true. I have hundreds of healthcare employees all over the country and they're highly productive, we have LOTS of monitoring abilities, highly secure and does not have an "incomplete" security model for whatever that means. The workload increase thing is silly, clicking a single button is not an increased workload.
https://www.nccoe.nist.gov/sites/default/files/2022-12/zta-n...
Line 259:
"It is no longer feasible to simply enforce access controls at the perimeter of the enterprise environment and assume that all subjects (e.g., end users, applications, and other non-human entities that request information from resources) within it can be trusted."
A VPN has security at the gate, aka, it keeps people out of the network perimeter. The assumption is that if someone gets within the perimeter, they passed most checks and can be trusted. Or, if something is already within the perimeter, that entity is to be trusted.
Insider threats are very real. Negligent/malicious employees cause damages. BYOD stands for both Device and Disaster. Supply chain attacks work through ways that the perimeter cannot defend against, and that is why the National Institute of Standards and Technology calls for a shift away from the perimeter-based security.
Page 22 of https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
"Remote enterprise assets should be able to access enterprise resources without needing to traverse enterprise network infrastructure first. For example, a remote subject should not be required to use a link back to the enterprise network (i.e., virtual private network [VPN]) to access services utilized by the enterprise and hosted by a public cloud provider (e.g., email)."
Uh, doesn't stuff like HTTP run on top of layer 4? (eg, tcp). This article doesn't seem entirely correct, but I'm a dunce with this stuff.
If you cannot accept the overhead of TCP’s reliability guarantees (or just don’t need it,) but still want service multiplexing, you’d typically use UDP for your protocol.
Edit: I am not exactly sure of the distinction between HTTP and FTP in the layers.
In the OSI reference model, it was opined that people would build common session and presentation management protocols on top of the transport layer. That, by and large, didn’t happen with IP.