I was explaining the diminishing value of VPNs yesterday.
Back in 2009, Canada’s neutered version of Netflix frustrated me. I learned about VPSes ($5/m VMesque Linux hosts) where I threw on OpenVPN and bypassed dumb licensing restrictions for that juicy top shelf US Internet.
#hacktheplanet
This same technology spawned into the VPN industry that now saturates our YouTube viewing pleasure. Nord…….
And I argued that while VPNs can add a layer of protection on public WIFIs and privacy from your ISP… There are also trade offs and concerns, especially with the 90% off VPN services.
I cut my teeth in the 2000’s, what seemed like the era of VPNing all the things. Governments to banks were trading dedicated and virtual private circuits for consumer grade Internet connections and VPNs to interconnect offices and data centre and make it feel… private. Additionally, VPNs allowed a remote workforce to feel like the were part of the… LAN.
At the time this made sense, most communications were unencrypted, most IT environments were flat and most business system were never intended to be exposed to the Internet. VPNs FTW.
As an OG network security geek, it makes me sad to admit the diminishing return on value, but it is the reality. Any application worth their salt communications securely, access control has ascended from the network layer to identity and if COVID has taught us anything in the network security space, centralizing user traffic does not scale well… Unless you sell network hardware.
So while LAN2LAN VPNs still have purpose inter-connecting physical locations, they are much more a transportation tool than a security tool. Why? Because they are generally configured as wholesale pipes between locations, lacking access control or other security capabilities.
And let’s not forget that the majority of VPN hardware devices are old and haven’t aged well. They have gone through several acquisitions which have left the owners of such hardware with rotting solutions at their front door.
And lastly, from the VPN user perspective, while it was once clever to have remote users feel like they were on the LAN, that is a bad play in this day and age. It puts a heavy reliance on less effective network security controls and also reflects an IT environment that is stuck in an architecture of yesteryear. Likely hiding ample tech debt behind the walled garden.
So while VPNs are still alive and well, we should recognize that they were a security control of a simpler time and between them not doing all that we think they are and their code base all but neglected by their private equity overlords, we should not be surprised when the next big ransomware outbreak happens because the rusty front gate, fell off its hinges.
Ps. This little creative writing bit I did this morning was inspired by Andrew Amaro’s blog I read this morning. Give him a follow: https://www.klavansecurity.com/news/why-vpns-are-worthless-but-you-should-use-one-is-terrible-advice
🔗 Subscribe to my Youtube channel here
Let me know what you think—and if you have topics or people I should feature, drop a comment! Let’s dig into the future.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.