TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Unpacking the Benefits of Zero Trust Architecture as Defined by NIST

150 pointsby CKMoover 2 years ago

6 comments

barathrover 2 years ago
Zero Trust certainly has its benefits over the old perimeter-based model, but it also requires new, and massive, trust in third-party cloud providers. A bit more on that:<p><a href="https:&#x2F;&#x2F;invisv.com&#x2F;articles&#x2F;zerotrust.html" rel="nofollow">https:&#x2F;&#x2F;invisv.com&#x2F;articles&#x2F;zerotrust.html</a><p>What we need to move towards is something more like Oblivious Trust -- you rely upon third parties but they have nothing sensitive in the first place.
评论 #34838622 未加载
评论 #34841468 未加载
评论 #34842224 未加载
评论 #34843650 未加载
评论 #34841335 未加载
评论 #34839034 未加载
评论 #34841416 未加载
评论 #34867755 未加载
评论 #34844398 未加载
评论 #34838434 未加载
colinrandover 2 years ago
With many new ideas, the early folks love the benefits and aren&#x27;t put off by the challenges. With ZTNA, after doing quite a few deployments myself, I can say that the biggest challenges are operational. Nothing will piss off developers more than having had access to a resource one day, lose it unexpectedly, and then not know who to track down to get it back. Or, users hating on their VPN, want something else, and then that something else (often just another VPN provider) works differently and causes them disruptions. ZTNA is a long journey, not a quick fix.
评论 #34841278 未加载
评论 #34846030 未加载
评论 #34841810 未加载
评论 #34838999 未加载
评论 #34838588 未加载
评论 #34838214 未加载
cscheueuerover 2 years ago
Has anyone used Pomerium and is it any good compared to Tailscale or Twingate?
评论 #34841095 未加载
评论 #34840316 未加载
EGregover 2 years ago
Anyone know Ziti?
评论 #34841508 未加载
out-of-ideasover 2 years ago
ive always correlated zero-trust with that which was recently on top of HN: <a href="https:&#x2F;&#x2F;dilbert.com&#x2F;strip&#x2F;2023-02-11" rel="nofollow">https:&#x2F;&#x2F;dilbert.com&#x2F;strip&#x2F;2023-02-11</a><p>treat your employees like cattle; see how far that will go
评论 #34843183 未加载
评论 #34839679 未加载
badrabbitover 2 years ago
Zerotrust is cancer.<p>I dismissed it a few years ago as a harmless hype but I am now seeing real harm being caused by this hype.<p>To avoid writing an essay here let me keep it short and explain why: I am seeing orgs spending valuable time, money and resources on box checking and implementing false security all over. It is being used in place of improving security posture that is aware of threat context facing the organization. It has scope-creeped beyond the original intended purpose of ensuring all actions are explicitly authorized and eliminating implicit trust to mean a buch of ridiculous goals and hype words no one can explain consistently.<p>I caution everyone to avoid using the term but to still implement the original beyondcorp architecture.<p>Another cancer that is begining to spread:&quot;passwordless&quot;.
评论 #34843250 未加载
评论 #34840847 未加载
评论 #34841438 未加载
评论 #34842749 未加载
评论 #34841386 未加载
评论 #34841390 未加载