News: 1587454388

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google productises its own not-a-VPN secure remote access tool

(2020/04/21)


Google has productised a remote-access tool it uses internally, because it thinks the world might be quite keen on this sort of thing right now.

The tool is called "BeyondCorp" and the search'n'ad giant deployed it in 2011 to provide access to its own web apps.

The company describes it as being able to pull off tricks such as: "My contract HR recruiters working from home on their own laptops can access our web-based document management system (and nothing else), but only if they are using the latest version of the OS, and are using phishing-resistant authentication like security keys."

Google decided to launch the tool now because it thinks organisations scrambling to deliver apps to suddenly remote workers will appreciate an approach it promises is faster than rolling out a VPN, [1]according to Sunil Patti, general manager and veep of Google's cloud security business.

[2]

How Google's BeyondCorp not-a-VPN does its thing (click to enlarge)

"With BeyondCorp Remote Access, we can help you do this in days rather than the months that it might take to roll out a traditional VPN solution," Potti added. "Using BeyondCorp Remote Access, you can offload some of the strain on your existing VPN deployment, saving critical capacity for the users who already have access and need it most."

For now BeyondCorp can only enforce access controls for web apps, but can do so on-prem, or in clouds including Google's own.

Pricing has not been revealed, but Google has named a few customers – including Airbnb – that have already used it in production to access the G-Cloud. ®

Sponsored: [3]Legacy Modernization: Finding Your Way With Low-Code



[1] https://cloud.google.com/blog/products/identity-security/keep-your-teams-working-safely-with-beyondcorp-remote-access

[2] https://regmedia.co.uk/2020/04/21/google_beyondcorp.jpg

[3] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936

Zero Trust and Google

Locky

Yup, checks out

Anonymous Coward

Ah yes, another product on deathrow in a couple of years time.

Coming soon to Chrome...

RyokuMas

I think I speak for the majority of people on these forums when I say "it'll be a cold day in hell before I run all my web traffic through a Google proxy".

However, I can see a good number of the less tech savvy being taken in when they open Chrome/search on Google, see a great big call-to-action saying "Install BeyondCorp for safer, more secure web browsing!" or somesuch, and immediately clicking that "download & install" button - much the same way the Chrome became the #1 browser.

Again, a prime example of why Google needs to be split up, and all internal / inter-product interations being made publicly visible.

Great, Google has found another way to slurp our data

Pascal Monett

I don't care what Google promises, I am not touching their products with a bargepole if I can avoid it.

The Least Successful Executions
History has furnished us with two executioners worthy of attention.
The first performed in Sydney in Australia. In 1803 three attempts were
made to hang a Mr. Joseph Samuels. On the first two of these the rope
snapped, while on the third Mr. Samuels just hung there peacefully until he
and everyone else got bored. Since he had proved unsusceptible to capital
punishment, he was reprieved.
The most important British executioner was Mr. James Berry who
tried three times in 1885 to hang Mr. John Lee at Exeter Jail, but on each
occasion failed to get the trap door open.
In recognition of this achievement, the Home Secretary commuted
Lee's sentence to "life" imprisonment. He was released in 1917, emigrated
to America and lived until 1933.
-- Stephen Pile, "The Book of Heroic Failures"