Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Internet exposed bastion hosts to production, that have no IP whitelisting are not the best idea, unfortunately not uncommon nowadays.


That's what a VPN server is.


Organizations that have high value assets would deploy multiple layers of these, not just one, basically depending on value of assets.


You're gonna get some pretty fun pathological networking behaviors tunneling VPNs on VPNs.


You need always need multiple layers of security. Using the network itself as one was never necessary, although it has been convenient.

Nowadays U2F based 2fa authentication and need to know based authorization are usually superior.


Applying both is better, then just depending on one of them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: