Public internet SSH isn’t the worst thing in the world; but for some people that doesn’t mean a reasonable bastion story but rather “every host has a public IP” — and that’s just just an extra opportunity to put an unauthenticated Redis or Elasticsearch on the Internet by accident. I don’t think Tom’s death to public internet ssh was a reference to preauth ssh vulns or whatever. (But there’s a ton less code to trust in wireguard, so it’s still better :))
That's fair! I've still been on team BeyondCorp there - every host should either be configured correctly or have a local firewall, to the point where a public IP is safe, because an unauthenticated Elasticsearch on a VPN is still exposed to CSRF attacks against someone on the VPN, malware, etc. But I can buy that not giving them public IPs is an important defense-in-depth mechanism.
Yeah, I think we’re in violent agreement. (I worked at one of the impacted organizations during Project Aurora.)
Having a VPN is a pretty great control for the vast majority of organizations that don’t have the operational maturity to pull the public IP apart of BeyondCorp off. FWIW: we are helping customers with differential access controls (and I love Chromebooks despite the license purchasing experience). But even if you go full public-IP BeyondCorp you’re going to have some machines you’re not exposing (though it should be fine to expose them, as you mention), and occasionally you need to reach them, and VPNs remain great for that. VPNs being unnecessary (and giving a false sense of security) for human-facing endpoints in a company with a multi billion dollar security org? Sure, it’s hard to disagree: to your point Google is working on the proof by construction :-D