5 ms·
The probably falls in the general category of a Good Thing™ for employees and people developing B2B applications since internal systems are more easily accessib
by atlbeer 11y ago
The probably falls in the general category of a Good Thing™ for employees and people developing B2B applications since internal systems are more easily accessible but, this will be a gut check/squeaky bum time for traditional on-premises B2B vendors like PeopleSoft/SAP/IBM and the like. The corporate firewall has always been a bastion of security they have been able to hide their applications behind. As the concept of a corporate firewall begins to fade their security risk increases and previously non-worrisome attack vectors become serious problems for them.
- JTon 11y agoApologies for being off topic.. > squeaky bum time Never heard this expression before. Quick search defines it as "An exciting part of a sporting event, particularly the final minutes of a close game or season". Unfortunately, I still don't really get the reference. Could someone spell this out for me?
- rmac 11y agoInsecure enterprise software and poor security practices mean death to firewalls and to vpns will take a long, long time. People hide behind these things for a reason. Google is right here though, this makes things easier for employees and probably saves them money (no vpn); unfortunately most orgs don't have the staff/expertise to pull something like this off. More importantly though, I think google builds all their enterprise web apps in-house (speculating). Most orgs who do have intranet apps use 3rd party off the shelf software so pulling off Google's BeyondCorp architecture is less likely as they can't control or easily modify how they work. Ergo, VPNs are here to stay. Even for those orgs who write their own internal applications: do you really want to expose your internal analytics dashboard to the internet?! GASP.
- deleted 11y ago[deleted]
- jahewson 11y agoLogin systems are only one small part of the surface area of most applications. Admin backdoors, an absence of SSL, SQL or other injection attacks, protocol vulnerabilities, unpatched code, homegrown/weak crypto, session hijacks, and XSS attacks going to need fixing too. Applying patches in a timely manner will be essential too.