Aflevering 140: Why Your VPN Is Lying to You About Security

Jan Stomphorst
Ronald Kers
Luister naar deze aflevering op jouw favoriete platform!
Apple Podcast Icon - Radio Webflow TemplateSpotify Icon- Radio Webflow TemplateGoogle Podcast Icon - Radio Webflow TemplateAnchor Icon - Radio Webflow TemplateSoundCloud Icon - Radio Webflow Template
Aflevering 140: Why Your VPN Is Lying to You About Security
August 4, 2026
29
 MIN

Aflevering 140: Why Your VPN Is Lying to You About Security

Traditional VPNs grant broad network access once a user authenticates, creating large lateral movement risk with little to no granular control or auditing. Instead of trusting users based on network location, every connection is signed and validated against intent, who is accessing what, and why.

Samenvatting

Ronald and Jan talk with Peter O'Neill and Boris Kurktchiev from Teleport about their talk "Signed, Sealed, Delivered: Why Reverse Proxies Beat VPNs." Both guests bring deep networking and security backgrounds, from early desktop support and Slackware days to leading Teleport's solutions engineering and CNCF community work.

The core argument: traditional VPNs grant broad network access once a user authenticates, creating large lateral movement risk with little to no granular control or auditing. Peter and Boris propose replacing that model with an identity layer using OIDC and a reverse proxy (Envoy), authenticated via an identity provider like Keycloak. Instead of trusting users based on network location, every connection is signed and validated against intent, who is accessing what, and why.

They walk through how this works in practice (SSH access, internal apps, audit logging that captures actual user identity instead of just status codes) and discuss trade-offs: more endpoints to manage, added resource and scaling costs, and real implementation complexity at enterprise scale. Boris is candid that VPNs aren't dead, they still serve as a useful front gate, but shouldn't be the only layer of defense.

The conversation also touches on how AI agents on a network expose the weaknesses of old identity assumptions, since AI will scan and probe everything it can reach unless access is explicitly scoped. The episode closes with both guests' hopes for the future of Kubernetes and CNCF: more community involvement in AI-related working groups, and more regional KubeCon-style events outside the usual hubs.

Stuur ons een bericht.

ACC ICT Specialist in IT-CONTINUÏTEIT
Bedrijfskritische applicaties én data veilig beschikbaar, onafhankelijk van derden, altijd en overal