Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The rhetoric of this statement is far more of an "anti-pattern" than VPN will ever be. If VPN is your only line of defense, then it's not secure at all - not because of VPN, but because of poor security practices in general.

VPN and IP restrictions in general is a very good tool to limit the attack surface. That does not mean that Karen from accounting should be able to log into the production environment servers.



Exactly. We have application level authentication on top of various network level security policies. Karen from accounting can't even see servers that she doesn't need, and anything she does need has additional authentication requirements. Even if someone mistakenly gave her access to something at one of these layers, she would need that same mistake at multiple layers to actually get in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: