6 ms·
Google's Beyond Zero: Enterprise Security for the AI Era
- urup2l8 2mo agoOh yeah, a company whose business model is taking everyone’s data and selling it is going to help me secure my data. I guess there’s one born every minute…
- stingraycharles 2mo agoWhere do you see them offering this service to you? They’re just publishing what they developed internally, which is what they often do. Now, Cloudflare, on the other hand, would be much more likely to offer a service like this.
- arccy 2mo agoyou could probably buy it as part of BeyondCorp https://cloud.google.com/beyondcorp https://cloud.google.com/beyondcorp
- stingraycharles 2mo agoTell me where I can buy it then. Because it’s not listed there. And the approach the paper describes requires tight integration between applications and a security provider, which I don’t think exists yet.
- zobzu 2mo agocorrect.
- exitheone 2mo agoThis trope is so tiring. There is a massive difference between Google for enterprise customers and Google for consumers. The consumer offering is massively subsidized by ads and will use your data for ad placement, although they still never sell your data because that would hurt their business. The Enterprise offering guarantees you contractually that they never touch your data.
- sam_lowry_ 2mo agoExcept if the authorities anywhere in the world or valuable partners politely ask for it, yeah.
- cyanydeez 2mo agoOr if they eventually get "SOTA" AI and it breaks out of it's sandbox trying to do whatever the MBA has told it to do.
- speed_spread 2mo agoIn this case, they wouldn't touch your data but their AI safety system would also prevent you from accessing it! What do you think their security model will be trained on? That's right, other people's data.
- jayd16 2mo agoWhere's the line exactly because it's certainly not right after you start paying? How big of a customer do I need to be to not be a 'consumer'?
- preommr 2mo ago> This trope is so tiring. While I also find it annoying, the alternative of just rolling over and being desensitized to it is much, much worse. If we're going to be wrong, I'd rather be wrong by being overly cautious than overly trusting.
- firasd 2mo agoHonestly I think non-malicious odd behavior is under-weighted when it comes to AI agents. Even the example in this paper is about someone suspiciously accessing sales data when "why did you do that" often comes down to something in the model's training that fired as a reflex I wrote about this a few days ago https://firasd.substack.com/p/accidental-data-loss-in-claude-code-openai-codex-ai-agent-harness-file-deletion https://firasd.substack.com/p/accidental-data-loss-in-claude... "Many researchers have made demos along these lines: An agent is asked to check a webpage like example.com The webpage asks for a name to proceed further The agent calls example.com/evil?myname=John, thus sending the user’s name from the context window to the external server. In practice, however, these elaborate ‘confused deputy’ exfiltration attacks seem rare compared to widely-reported data loss incidents. The risk of undermining the user’s interests through clumsiness deserves at least as much scrutiny as the risk of leaking secrets." So while the idea of shifting the permission boundary from the app level to the action level makes sense, what we should also have is some 'failsafes', eg. if the action says 'delete' then maintain a rollback window, if the action is 'send an email' then maintain an events log. Preparing for AI agents means expanding auditability and reversibility in software
- mooreds 2mo ago> Preparing for AI agents means expanding auditability and reversibility in software While I think that makes sense, I also think more controls are a good solution. That is, prevent access to the sales data without escalation, probably to a human, but possibly to another AI. The issue there is twofold: - if you start with least privilege, the agents become less useful - need to balance escalation with frequency otherwise it's just another version of MFA fatigue Agree that auditability is important because otherwise you don't know what you don't know.
- oscarcp 2mo agoAm I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)
- oscarcp 2mo agoJust to make my point: can I really trust humans to keep up with the required identity data that will give me enough "credibility" so the AI will give me access? Let's say I had a promotion, who changes my title in the system, who changes my responsibilities and my place in the org chart, more importantly, will they do it or is <HR_NAME_HERE> on leave and forgot? those are data points required by the agent to determine if I'm "good enough" to access a certain resource. What if... someone spoofed my address and did a flood in one of the resources that are lateral to what I'm allowed to access (let's say I don't have access to company sales but I do to department sales and the attacker floods company sales with requests under my address), would the AI determine that I'm a high-threat actor and not allow me to access legitimate files going forward? Will exceptions be made by humans? In which case we go back to human-managed permissions. Sorry, I might be barking up the wrong tree but I think these are questions that are not meant to be solved during implementation. And they add to what @firasd said about legitimate-but-odd behaviour
- firasd 2mo agoI think the dynamic risk signals is already an assumed part of the system. The proposal here seems to be shrinking the trust boundary from "can Alice use Google Drive?" to "should this specific read/write/export API call on this specific resource be allowed right now?" So yeah you're right in that it does add more probabilistic randomness just by virtue of changing the boundary of when the permission gate kicks in
- thewebguyd 2mo agoCorrect. In existing zero trust identity, we already have deterministic risk signals. In Entra where I work we already check things like "Is this person on a managed device? Is it compliant? Where are they? What MFA methods do they have registered/did they use?" on top of existing RBAC, etc. and its continuously evaluated. Entra watches for leaked passwords, assigns risk scores, etc. and you can make access decisions based on user risk or sign in risk, force password changes, require different MFA methods depending on the resource and the risk level, etc. "Should this API call on this resource be allowed right now?" is mostly already determined by the above. Where I see adding AI into the evaluation is to watch for unusual behavior that's not picked up by the deterministic signals. "Alice is trying to download gigs worth of data from the company file share, however she has never done that in the past, and there hasn't been any recent role/job changes" and so the LLM flags it or denies the request, or pushes it for a human approver, etc.
- stogot 2mo agoZero trust is deterministic. AI is non-deterministic Non-deterministic access controls is Terrible idea
- Someone1234 2mo agoI completely agree. I think LLMs may have a role in security posture, specifically flagging/identifying potential threats for human review. But a Zero Trust/Access Controls should be a HARD boundary, not an inconsistent one. The problem we have right now is that there are some legitimately interesting ideas out there for things we could be using LLMs for, but we also have a ton of "I have a hammer, and everything looks like a nail" going on too.
- TeMPOraL 2mo ago> The problem we have right now is that there are some legitimately interesting ideas out there for things we could be using LLMs for, but we also have a ton of "I have a hammer, and everything looks like a nail" going on too. It's not a problem as much as a phase the world is going through. LLMs are a technological breakthrough in the same generality class as the Internet, or possibly electricity, and in both cases the world went through a phase of attempting to apply the newfound invention to literally everything. It's a necessary phase, when a technology obviously could be useful for everything, but it's not obvious whether it will in practice.
- thewebguyd 2mo agoI don't think Google are advocating for removing the deterministic controls, are they? Sounds like adding the LLM in would be on top of the existing deterministic controls. Existing controls handle the "Should you be able to access this resource right now?" the LLM handles "Is this user behaving as we expect them to while accessing this resource?"
- rossjudson 2mo agoAgreed; I don't think we want security controls to devolve into an argument between LLMs. Attacking and defending LLMs operate in an ecosystem, and are (hopefully) limited by constraints. Defending LLMs will be able to rely on and evolve those constraints. Attacking LLMs want to find a way around them.
- insumanth 2mo agoI was confused when google acquired "Wiz" for so much money But now, it makes sense to some extent. Security is non-negotiable in AI Era
- Melatonic 2mo agoWas this what Wiz was doing?
- kriro 2mo ago""" Beyond Zero shifts the trust boundary from the application to the action being performed on a piece of data in realtime—and from after-the-fact investigation to in-the-moment evaluation and containment. It augments BeyondCorp’s foundational identity with a “brain” capable of reasoning about the context and intent of a specific request in realtime. """ Doesn't this simply shift the attack vector? Compromising this overlord brain now becomes a new target.
- thomascgalvin 2mo agoThis is a layer on top of normal security, so this isn't a matter of compromising the "brain" instead of RBAC, etc, but in addition to. Attribute-based access control is already a thing. User X logs in the US East between the hours of 6am and 6pm. If User X logs in from Russia at 3am, deny access. This seems like an evolution of that pattern
- butterclaw-tech 2mo agoOne partial answer is to not make it a single brain. If the reasoning layer that evaluates a request is independently audited by a second pass at lower temperature with an explicit skepticism mandate, compromising the evaluator requires compromising both passes simultaneously — and they're running the same local model with different system prompts and no shared state between them. Doesn't eliminate the attack surface but raises the cost considerably compared to a single inference gate.
- thesuitonym 2mo agoAll security measures "simply shift the attack vector." The idea is to shift it to something that is more difficult to compromise.
- antonvs 2mo agoThis is oversimplifying. For example, encryption at rest or in transit essentially eliminates attack vectors. The possible attack avenues necessarily shift as a result, but only because an avenue was blocked. That's very different from e.g. adding a layer of protection around something insecure, where the insecure thing remains insecure inside the protection, which I think is what the other commenter was imagining. Similarly, memory safe languages (including most GC languages, not just a certain language beginning with R) eliminate entire classes of security hole. Again, the possible attack vectors necessarily "shift", but that doesn't capture the fact that you've entirely eliminated a class of attacks. The same goes for eliminating unnecessary services, firewall holes, etc. None of these are specifically trying to "shift it to something to something that is more difficult to compromise." They're entirely blocking attack vectors, and the strength or weakness of other parts of the system aren't really a factor.
- FailMore 2mo agoIf this is interesting to you (as it is to me) but you want to quickly digest it instead of read the paper, Claude + SmallDocs[1] converted it into a slideshow which serves it to you in bitesized ideas: https://smalldocs.org/s/2SH6FHiUK1mcym24Z8E37I#k=2Sk6c_IdKJLGrQ_YX_OL8zcNpaY1FgAsZQ4PqximZEY https://smalldocs.org/s/2SH6FHiUK1mcym24Z8E37I#k=2Sk6c_IdKJL... [1] I am the developer behind SmallDocs.
- BorisMelnik 2mo agonot sure if you made the app or not - I like it a lot, only feedback is it should be a bit more intuitive on how to start the slides, I couldn't figure it out and old ppl like me don't always know
- troyzhxu 2mo agoThe font is different after downloading from the preview on the web page, but I still like it.
- aniceperson 2mo agoreally nice project! I would never consider websockets for the bridge mode, why do browsers allow websockets to localhost crossing domains ahah
- simonmorley 2mo ago[flagged]
- vouaobrasil 2mo agoThis is exactly why big tech companies love AI. It's not because it will take every job - it probably won't. It's not because it will achieve AGI. It probably won't. It's because it threatens security with more subtle, advanced, and automated exploits so that you'll HAVE to rely on them for countermeasures.
- mannanj 2mo agoI wonder: Could your data be more secure if you didn't give its custody to a company like Google? i.e. is there actually a sound basis that an alternative like taking control of your data and securing it yourself, would be more secure that the "banks exist to protect you" type of fear-mongered custodian idea against the self-ownership of things?
- skybrian 2mo agoMaybe this is more interesting in the context of the HuggingFace incident? Suppose you have an AI and some access controls for what it can do. If the access control is too broad or has a bug, can you still detect suspicious activity and slow it down long enough for someone to be alerted?
- seanc 2mo agoMy goodness, the security layer looks like it could be more complex than the applications themselves. And if this security agent is wandering around the IT system gathering all of these details about access and identity and business process, who watches the watcher? How does that thing build and maintain trust?
- nitwit005 2mo ago> In this scenario, a system administrator logs into a service as usual, but in another window is looking up basic questions about the architecture of the system—information that would be obvious to anyone experienced at the company. These signals are placed in long-term storage but are then processed into an attribute indicating potential risk. Every system admin is going to send that signal. People pin pictures of the architecture to the walls sometimes.
- singhsanjay12 1mo agoWe explored a closely related architecture at LinkedIn around centralized identity and policy enforcement at the action/resource boundary, which I presented at RSA Conference earlier this year in San Francisco. Interesting to see similar architectural patterns emerging from different directions. I’d be curious where the authors see the biggest challenges in extending this model from human/service identities to autonomous agents.