> A VPN is theoretically superfluous in a zero trust environment, where you have no concept of a trusted network and your applications should be sufficiently hardened to prevent unauthorized access.
Defense in depth is theoretically superfluous in a secure system, but it's still a good idea for... what I thought were obvious reasons. I don't see how this is any different.
And, again, as I mentioned above this isn't even just about network trust, it's also about the ability to monitor, audit, and intercept potentially malicious connections when something does get compromised. "We assume our one layer of security will work perfectly" cannot be the starting assumption...
> Google operates this way, if I recall correctly.
Google also has 24/7 world-class security teams monitoring everything across the planet. They have a ton of power to monitor and mitigate damage across the entire internet. Just because something works for Google that doesn't mean it'll work for arbitrary organizations.
Defense in depth is theoretically superfluous in a secure system, but it's still a good idea for... what I thought were obvious reasons. I don't see how this is any different.
And, again, as I mentioned above this isn't even just about network trust, it's also about the ability to monitor, audit, and intercept potentially malicious connections when something does get compromised. "We assume our one layer of security will work perfectly" cannot be the starting assumption...
> Google operates this way, if I recall correctly.
Google also has 24/7 world-class security teams monitoring everything across the planet. They have a ton of power to monitor and mitigate damage across the entire internet. Just because something works for Google that doesn't mean it'll work for arbitrary organizations.