logoalt Hacker News

ronbenton08/09/20252 repliesview on HN

Does having a VPN/intranet preclude zero trust? It seems you could do both with the private network just being an added layer of security.


Replies

AWebOfBrown08/09/2025

It doesn't, but from my perspective the thinking behind zero trust is partly to stop treating networking as a layer of security. Which makes sense to me - the larger the network grows, the harder to know all its entry-points and the transitive reach of those.

tw04last Sunday at 5:08 AM

A VPN? Yes, by definition. Zero trust requires that every connection is authenticated and users are only granted access to the app they request. They never “connect to the network” - something brokers that connection to the app in question.

VPN puts a user on the network and allows a bad actor to move laterally through the network.

show 1 reply