Did they impersonate the software development manager in order to steal credentials? Did Disney integrate their sensitive data storage with Slack?
Did they impersonate the software development manager in order to steal credentials? Did Disney integrate their sensitive data storage with Slack?
So the industry has basically just gone and reinvented the very premise Google built BeyondCorp to mitigate, starting back in 2009.
IIUC the baseline premise was to move away from "login to the VPN and you're inside the corporate network and you can access everything". It was incredibly convenient but a logistical nightmare in practice.
The BeyondCorp approach was to integrate authentication into each product so that the access control could be managed on a case by case basis.
Google standardised on OAuth across the board, and had a centralised login protocol/API with a WAF etc, but each product called out to this, and policy was decided by the calling application. This approach shines through to the whole Login with Google ideology.
Thinking about it, I wonder how much corporate/enterprise/even SOHO OAuth is effectively the inverse of this approach - login to eg Auth0 once and you immediately have access to all your apps.
That approach isn't technically broken, but it feels a bit like there's an antipattern here in the encouragement of centralised policy management. That just encourages everyone to think about "login once!" just like the old VPNs.
And it's just hilarious how everyone's just... wandered in this direction. First VPNs, then "centralised access bad", then BeyondCorp, then OAuth, then "login once!", and back to the beginning.
At least the web gives you the tools to setup siloed authentication per app. VPNs don't provide that level of slicing and dicing. So it's easier to fix, and merely a (complex) security design problem now.
Could you elaborate? I'd like to learn from the errors of the past
After all, what could have been done differently? Require password retype/MFA multiple times per day? This would drive people crazy, and if the computer ia infected then credentials could be stolen anyway.
Now talking in #ds_it_helpdesk
RoyD: hi guys this is roy. i have trouble with logging on says my password is wrong. i double checked it multiple times but it doest let me in. can you reset it to Mickey123?
MarkP: hi. reset it for you, check now?
RoyD: works now thanks
This is a work of fiction. Names, characters, places and incidents either are products of the author's imagination or are used fictitiously. Any resemblance to actual events or locales or persons, living or dead, is entirely coincidental.