Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Them: How do we add zero trust to this

Them: How do we add zero trust to this

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
13 Indlæg 8 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • maya_b@hachyderm.ioM maya_b@hachyderm.io

    @petrillic

    "but agile..."

    petrillic@hachyderm.ioP This user is from outside of this forum
    petrillic@hachyderm.ioP This user is from outside of this forum
    petrillic@hachyderm.io
    wrote sidst redigeret af
    #3

    @maya_b do you want scaled agile? Because this is how you get scaled agile.

    maya_b@hachyderm.ioM 1 Reply Last reply
    0
    • petrillic@hachyderm.ioP petrillic@hachyderm.io

      @maya_b do you want scaled agile? Because this is how you get scaled agile.

      maya_b@hachyderm.ioM This user is from outside of this forum
      maya_b@hachyderm.ioM This user is from outside of this forum
      maya_b@hachyderm.io
      wrote sidst redigeret af
      #4

      @petrillic

      "what if you shard it?"

      (as long as we're being serious about it)

      1 Reply Last reply
      0
      • petrillic@hachyderm.ioP petrillic@hachyderm.io

        Them: How do we add zero trust to this?
        Me: :stares:

        Zero trust, like least-privilege, is a framework for thinking about problems. It's not a seasoning you sprinkle over your eggs.

        rnd@toot.catR This user is from outside of this forum
        rnd@toot.catR This user is from outside of this forum
        rnd@toot.cat
        wrote sidst redigeret af
        #5

        @petrillic *tells everyone to stop trusting the service* there, zero trust added

        1 Reply Last reply
        0
        • petrillic@hachyderm.ioP This user is from outside of this forum
          petrillic@hachyderm.ioP This user is from outside of this forum
          petrillic@hachyderm.io
          wrote sidst redigeret af
          #6

          @sam part of the challenge is that vendors have weaponized the terminology to describe whatever new product or feature they're peddling.

          My distillation is: 1) Everything secure always; 2) Everything means everything, no implicit trust; 3) Access is granted per-session/request and strictly enforced, explicit trust; 4) Policy and decisions account for all available surveillance data.

          1 Reply Last reply
          0
          • petrillic@hachyderm.ioP This user is from outside of this forum
            petrillic@hachyderm.ioP This user is from outside of this forum
            petrillic@hachyderm.io
            wrote sidst redigeret af
            #7

            @sam correct, it should have eto establish trust as well. Certificates are part of it, but it's inadequate. Unfortunately, i don't think the industry has really grappled with this.

            sam@gts.tabby.rocksS 1 Reply Last reply
            0
            • petrillic@hachyderm.ioP petrillic@hachyderm.io

              @sam correct, it should have eto establish trust as well. Certificates are part of it, but it's inadequate. Unfortunately, i don't think the industry has really grappled with this.

              sam@gts.tabby.rocksS This user is from outside of this forum
              sam@gts.tabby.rocksS This user is from outside of this forum
              sam@gts.tabby.rocks
              wrote sidst redigeret af
              #8

              @petrillic there are a ton of cool cryptographic widgets coming down the pipe to be excited about, like zero-knowledge proofs, homomorphic encryption, etc. too!

              1 Reply Last reply
              0
              • petrillic@hachyderm.ioP petrillic@hachyderm.io

                Them: How do we add zero trust to this?
                Me: :stares:

                Zero trust, like least-privilege, is a framework for thinking about problems. It's not a seasoning you sprinkle over your eggs.

                emily@infosec.exchangeE This user is from outside of this forum
                emily@infosec.exchangeE This user is from outside of this forum
                emily@infosec.exchange
                wrote sidst redigeret af
                #9

                @petrillic

                I've rarely worked at a place where they let you build in security from the start, rather than something they think they can add after everything else is done.

                And almost nobody, no matter the industry, will make an asset inventory for me to use.

                brass75@twit.socialB petrillic@hachyderm.ioP 2 Replies Last reply
                0
                • emily@infosec.exchangeE emily@infosec.exchange

                  @petrillic

                  I've rarely worked at a place where they let you build in security from the start, rather than something they think they can add after everything else is done.

                  And almost nobody, no matter the industry, will make an asset inventory for me to use.

                  brass75@twit.socialB This user is from outside of this forum
                  brass75@twit.socialB This user is from outside of this forum
                  brass75@twit.social
                  wrote sidst redigeret af
                  #10

                  @Emily @petrillic that's the only way to have good security. It's not something that can be effectively bolted on - it needs to be part of the design from day 1.

                  1 Reply Last reply
                  0
                  • emily@infosec.exchangeE emily@infosec.exchange

                    @petrillic

                    I've rarely worked at a place where they let you build in security from the start, rather than something they think they can add after everything else is done.

                    And almost nobody, no matter the industry, will make an asset inventory for me to use.

                    petrillic@hachyderm.ioP This user is from outside of this forum
                    petrillic@hachyderm.ioP This user is from outside of this forum
                    petrillic@hachyderm.io
                    wrote sidst redigeret af
                    #11

                    @Emily sadly, I can't disagree. This is why I continue to try and push for new ideas and new approaches. We've tried the same thing over and over, and failed. At some point, let's try something new, and potentially still fail, but at least maybe learn something.

                    1 Reply Last reply
                    0
                    • petrillic@hachyderm.ioP petrillic@hachyderm.io

                      Them: How do we add zero trust to this?
                      Me: :stares:

                      Zero trust, like least-privilege, is a framework for thinking about problems. It's not a seasoning you sprinkle over your eggs.

                      reedmideke@mastodon.socialR This user is from outside of this forum
                      reedmideke@mastodon.socialR This user is from outside of this forum
                      reedmideke@mastodon.social
                      wrote sidst redigeret af
                      #12

                      @petrillic "Well, my trust in your organization already dropped significantly, throw in some post-quantum AI blockchain and I bet we can get to zero"

                      1 Reply Last reply
                      0
                      • reynir@social.data.coopR This user is from outside of this forum
                        reynir@social.data.coopR This user is from outside of this forum
                        reynir@social.data.coop
                        wrote sidst redigeret af
                        #13

                        @sam @petrillic what I gathered from talking to a vendor at a security conference is that it's definitely not VPNs no matter the context when I told him that we had reimplemented parts of the OpenVPN protocol.

                        1 Reply Last reply
                        0
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Har du ikke en konto? Tilmeld

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper