▲ 1911 ▼ Zero Trust Architecture (lemmy.ml) submitted 9 months ago by cm0002@mander.xyz to c/programmer_humor@programming.dev 233 comments fedilink hide all child comments
[–] UnRelatedBurner@sh.itjust.works 44 points 9 months ago (3 children) Wouldn't it be enough to just create a seperate subnet? permalink fedilink source hideshow 6 child comments replies: [–] scrubbles@poptalk.scrubbles.tech 37 points 9 months ago (1 child) Yeah that's where it turned from story to joke for me permalink fedilink source parent hideshow 2 child comments replies: [–] scytale@piefed.zip 17 points 9 months ago They’re specifically talking about Zero Trust though and treating it like a corporate device as the joke. This means authenticate at every layer, RBAC, and endpoint security compliance before allowing access to a service. Putting the device into an isolated guest VLAN works too of course. permalink fedilink source parent [–] curbstickle@anarchist.nexus 6 points 9 months ago Thats all I do. Separate SSID, goes right into its own little hellscape with no access to anything but the internet. And a small 8 port switch for a hardwired guest option. But thats not lit until its needed. permalink fedilink source parent [–] Scoopta@programming.dev 5 points 9 months ago (1 child) Yeah, he did that...and then kept going for some reason. A separate subnet in a separate firewall zone that doesn't forward anywhere but the internet should be sufficiently safe permalink fedilink source parent hideshow 2 child comments replies: [–] ExLisper@lemmy.curiana.net 8 points 9 months ago (1 child) Not for the kid. permalink fedilink source parent hideshow 2 child comments replies: [–] Scoopta@programming.dev 4 points 9 months ago (2 children) Was he worried about the kid or his network lol? permalink fedilink source parent hideshow 4 child comments replies: [–] felbane@lemmy.world 5 points 9 months ago por_que_no_los_dos.meme permalink fedilink source parent [–] arin@lemmy.world 2 points 9 months ago Neither permalink fedilink source parent
[–] scrubbles@poptalk.scrubbles.tech 37 points 9 months ago (1 child) Yeah that's where it turned from story to joke for me permalink fedilink source parent hideshow 2 child comments replies: [–] scytale@piefed.zip 17 points 9 months ago They’re specifically talking about Zero Trust though and treating it like a corporate device as the joke. This means authenticate at every layer, RBAC, and endpoint security compliance before allowing access to a service. Putting the device into an isolated guest VLAN works too of course. permalink fedilink source parent
[–] scytale@piefed.zip 17 points 9 months ago They’re specifically talking about Zero Trust though and treating it like a corporate device as the joke. This means authenticate at every layer, RBAC, and endpoint security compliance before allowing access to a service. Putting the device into an isolated guest VLAN works too of course. permalink fedilink source parent
[–] curbstickle@anarchist.nexus 6 points 9 months ago Thats all I do. Separate SSID, goes right into its own little hellscape with no access to anything but the internet. And a small 8 port switch for a hardwired guest option. But thats not lit until its needed. permalink fedilink source parent
[–] Scoopta@programming.dev 5 points 9 months ago (1 child) Yeah, he did that...and then kept going for some reason. A separate subnet in a separate firewall zone that doesn't forward anywhere but the internet should be sufficiently safe permalink fedilink source parent hideshow 2 child comments replies: [–] ExLisper@lemmy.curiana.net 8 points 9 months ago (1 child) Not for the kid. permalink fedilink source parent hideshow 2 child comments replies: [–] Scoopta@programming.dev 4 points 9 months ago (2 children) Was he worried about the kid or his network lol? permalink fedilink source parent hideshow 4 child comments replies: [–] felbane@lemmy.world 5 points 9 months ago por_que_no_los_dos.meme permalink fedilink source parent [–] arin@lemmy.world 2 points 9 months ago Neither permalink fedilink source parent
[–] ExLisper@lemmy.curiana.net 8 points 9 months ago (1 child) Not for the kid. permalink fedilink source parent hideshow 2 child comments replies: [–] Scoopta@programming.dev 4 points 9 months ago (2 children) Was he worried about the kid or his network lol? permalink fedilink source parent hideshow 4 child comments replies: [–] felbane@lemmy.world 5 points 9 months ago por_que_no_los_dos.meme permalink fedilink source parent [–] arin@lemmy.world 2 points 9 months ago Neither permalink fedilink source parent
[–] Scoopta@programming.dev 4 points 9 months ago (2 children) Was he worried about the kid or his network lol? permalink fedilink source parent hideshow 4 child comments replies: [–] felbane@lemmy.world 5 points 9 months ago por_que_no_los_dos.meme permalink fedilink source parent [–] arin@lemmy.world 2 points 9 months ago Neither permalink fedilink source parent
[–] felbane@lemmy.world 5 points 9 months ago por_que_no_los_dos.meme permalink fedilink source parent