blog.howardjohn.info/posts/bypass-egress

Preview meta tags from the blog.howardjohn.info website.

Linked Hostnames

4

Search Engine Appearance

Google

https://blog.howardjohn.info/posts/bypass-egress

Outbound sidecars are not secure enforcement points

It is a very common misconception that egress policies in Istio can be used for security purposes. This is not true. Despite repeatedly explaining this (and documenting it), I still often see people that do not believe it, and that they can just add one more check to lock things down. In this post, I will show a variety of ways to bypass any possible check, and prove that these policies cannot be used as secure policies.



Bing

Outbound sidecars are not secure enforcement points

https://blog.howardjohn.info/posts/bypass-egress

It is a very common misconception that egress policies in Istio can be used for security purposes. This is not true. Despite repeatedly explaining this (and documenting it), I still often see people that do not believe it, and that they can just add one more check to lock things down. In this post, I will show a variety of ways to bypass any possible check, and prove that these policies cannot be used as secure policies.



DuckDuckGo

https://blog.howardjohn.info/posts/bypass-egress

Outbound sidecars are not secure enforcement points

It is a very common misconception that egress policies in Istio can be used for security purposes. This is not true. Despite repeatedly explaining this (and documenting it), I still often see people that do not believe it, and that they can just add one more check to lock things down. In this post, I will show a variety of ways to bypass any possible check, and prove that these policies cannot be used as secure policies.

  • General Meta Tags

    14
    • title
      Outbound sidecars are not secure enforcement points | howardjohn's blog
    • charset
      utf-8
    • X-UA-Compatible
      IE=edge
    • viewport
      width=device-width, initial-scale=1, shrink-to-fit=no
    • robots
      index, follow
  • Open Graph Meta Tags

    6
    • og:url
      https://blog.howardjohn.info/posts/bypass-egress/
    • og:site_name
      howardjohn's blog
    • og:title
      Outbound sidecars are not secure enforcement points
    • og:description
      It is a very common misconception that egress policies in Istio can be used for security purposes. This is not true. Despite repeatedly explaining this (and documenting it), I still often see people that do not believe it, and that they can just add one more check to lock things down. In this post, I will show a variety of ways to bypass any possible check, and prove that these policies cannot be used as secure policies.
    • og:locale
      en-us
  • Twitter Meta Tags

    3
    • twitter:card
      summary
    • twitter:title
      Outbound sidecars are not secure enforcement points
    • twitter:description
      It is a very common misconception that egress policies in Istio can be used for security purposes. This is not true. Despite repeatedly explaining this (and documenting it), I still often see people that do not believe it, and that they can just add one more check to lock things down. In this post, I will show a variety of ways to bypass any possible check, and prove that these policies cannot be used as secure policies.
  • Link Tags

    7
    • apple-touch-icon
      https://blog.howardjohn.info/apple-touch-icon.png
    • canonical
      https://blog.howardjohn.info/posts/bypass-egress/
    • icon
      https://blog.howardjohn.info/favicon.ico
    • icon
      https://blog.howardjohn.info/favicon-16x16.png
    • icon
      https://blog.howardjohn.info/favicon-32x32.png
  • Website Locales

    1
    • EN country flagen
      https://blog.howardjohn.info/posts/bypass-egress/

Links

14