Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you are just misreading it. Read correctly, IMO, it says that no trust is granted to anything... note how they list multiple general examples, enough items to cover everything multiple times, to help make sure this was the reading. That authentication is discrete from authorization and outside of each others purview. And given zero trust is all about access control, I think my framing makes sense.


Any framing which helps one to reduce systematic risk is fine by me and fully agreed that authentication is discrete from authorization. My framing is set by the open source project I work on (https://openziti.github.io/) which allows anyone to embed zero trust networking into anything including an application with an SDK, this allows us to have zero trust in the network, be it internet/WAN, local or even the host OS network. This reduces a lot of the attack surface but you do have the trust the overlay control plane.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: