Cloud & Network Security

Where a system is reachable from and what proves a service's identity: the network attack surface and segmentation, zero trust in place of a perimeter, and mutual authentication between services.

Before anyone can attack a service, they have to be able to reach it. That is the cheapest security control in existence and the one most often left to a default: a database that binds to 0.0.0.0 instead of loopback is not a vulnerability in anybody's scanner, and it is how a great many incidents start. This domain is about reachability and about what a service should conclude from the fact that a request arrived at all.

It works through three shifts. The first is exposure as something you can read off a configuration: what a binding address actually means, how a first-match firewall rule set with a default deny behaves, and how to classify a service as loopback, private or public without guessing. The second is the collapse of the perimeter. Once every workload is somewhere else and every user is anywhere, "inside the network" stops being evidence of anything, and each request has to be decided on identity and device posture instead of source address — micro-segmentation then shrinks what a single compromise can reach. The third is what two services should demand of each other: mutual TLS, so both ends prove identity rather than one, and the workload identity and short-lived, rotated certificates that make that practical instead of a spreadsheet of secrets.

Exposebindings, default-deny rulesDistrustidentity, not source addressSegmentshrink the blast radiusProvemutual TLS between workloads
From what can reach the service, to what the service should believe about whoever did.
Cloud & Network Security — TransformerLab