2020-11-05
The Firewall Emperor Has No Clothes
Many people buy a network firewall and hoist a mission accomplished flag over security. The magic box prevents the bad of the Internet from infecting the good of the interior. But did you know the firewall itself can be taken over, or other internal resources can be traversed, just by your own browser?
As a user, whatever your browser can get to, JavaScript running in it can get to it. Your firewall allows all outbound. Thus if I can influence you to a site with some bad JavaScript, I can connect to something inside. That might be the administrative interface of your firewall. It could be your payroll system. O firewall where art thou in my time of need?
The solution is Defense in Depth. Stop thinking about security as a perimeter, start thinking about it as user+resource pairs. Look at a Zero Trust Architecture, its simpler than the other micro-segmentation approaches out there.
Don't Trust The Firewall (Absolutely). Defense In Depth Is Needed - YouTube
Tap to unmute
Don't Trust The Firewall (Absolutely). Defense In Depth Is Needed
Agilicus306 subscribers
Learn More?
Resource Library
Recent Articles
- The Epitome of Absolute Trust: Why Legacy Virtual Private Networks Are a Liability
- Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea
- Securing the Flow: GAO Highlights Persistent Cyber Threats to Water and Wastewater Systems
- NERC CIP Compliance for Small Independent Power Producers: A Pragmatic Approach
- Cyber Security Is Physical Safety: Lessons From a Thermal Runaway
- Water utility cybersecurity: The nearly £1 million lesson from South Staffordshire Water