- Knowledge
- technology
- OOP
- Tips
- Programming
- Tips
- Tutorial
- SEO
- Ranking
- Knowledge
- Special Day
- Seo
- Bug
- Data science
- Seo
- artificial intelligence
- Machine Learning
- Robotics
- happyNewYear2021
- newYearEve
- 2021
- Automation
- Smart Home
- Career
- Best Practices
- Git
- Logging
- Web Fundamentals
- DNS
- HTTPS
- Performance
- AI Tools
- ChatGPT
- Claude
- Gemini
- Laravel
- Eloquent
- MySQL
- HTTPS
- TLS
- Web Security
- Certificates
- Developer Life
- Debugging
- Docker
- DevOps
- Transactions
- Queues
- LLMs
- AI
- AI Coding
- Developer Tools
- React Native
- Expo
- Kate PMS
- Mobile Apps
- Laravel
- Authentication
- Sanctum
- Cookies
- API Design
- Payments
- Idempotency
- DeepSeek
- Open Source AI
- LLMs
- AI News
- Git
- Version Control
- AI Coding
- Prompting
- PHP
- Checklist
- MCP
- AI Agents
- OpenAI
- Architecture
- Microservices
- Modular Monolith
- Estimation
- Developer Life
- Project Planning
- Humour
- OAuth
- OpenID Connect
- Authentication
- Embeddings
- Vector Search
- RAG
- pgvector
- OpenAI
- GPT-4.1
- Codex CLI
- Events
- Testing
- Clean Code
- Maintainability
- Code Review
- Webhooks
- API
- Security
- Claude Code
- Workflow
- AI
- LLM
- Prompt Injection
- Mobile
- React
- Networking
- TCP
- UDP
- HTTP/3
- CLAUDE.md
- AWS
- Cloud Security
- Backups
- PHPUnit
- Software Engineering
- Leadership
- Communication
- RAG
- Embeddings
- AI Engineering
- IT Infrastructure
- Networking
- Access Control
- CI/CD
- GitHub Actions
- Gemini CLI
- Claude Code
- JavaScript
- Async/Await
- Node.js
- Promises
- Security
- Cryptography
- Passwords
- MySQL
- Database
- Vibe Coding
- Software Quality
- DNS
- Code Reading
- Onboarding
- Productivity
- Background Jobs
- Developer Humour
- Estimates
- Dev Life
- JWT
- o3-mini
- DeepSeek R1
- Rate Limiting
- Kate PMS
- E-Signing
- Audit Trail
- REST
- GraphQL
- API Design
- Laravel 12
- Upgrade Guide
- Open Source
- Self-Hosting
- Task Scheduling
- Cron
- Secrets
- CORS
- PHP
- PHP-FPM
- OPcache
- GitHub Copilot
- Software Architecture
- Engineering
- TypeScript
- JavaScript
- Type Safety
- AI Security
- React Native
- Product Design
- AI Agents
- Kiro
- Queues
- Redis
- RabbitMQ
- AWS SQS
- Nginx
- Apache
- GPT-5
- gpt-oss
- Clean Code
- Architecture
- Naming
- Documentation
- Career
- ADR
- Teamwork
- Supply Chain
- Kate HRM
- HR Software
- Permissions
- System Design
- Pagination
- SSH
- Linux
- Big O
- Databases
- Laravel Boost
- MCP
- Developer Skills
- Validation
- Databases
- Indexes
- Code Quality
- Deployment
- Developer Humour
- Feature Flags
- Code Review
- Pull Requests
- Docker
- Cursor
- Authorization
- RBAC
- Gemini
- Long Context
- PHP 8.4
- Caching
- Dependency Injection
- Web Performance
- Browser
- CSS
- Database
- Migrations
- ChatGPT
- AI for Developers
- Monitoring
- On-Call
- REST
- Backend
- SQL
- NoSQL
- Database Design
- Coding Agents
- Claude 4
- API Resources
- REST API
- Load Balancing
- Scaling
- AWS
- AI Tools
- Claude
- Sora 2
- CTE
- 2FA
- TOTP
- Programming Languages
- Prompts
- Developer Workflow
- API Gateway
- APIs
- Passport
- API Auth
- Learning
- Burnout
- Developer Growth
- Web Development
- SEO
- Kate Mall
- ChatGPT Atlas
- Agent Skills
- Middleware
- Laravel 12
- Collections
- Context Window
- Monitoring
- Commit Messages
- Self Review
- Growth
- Regex
- Programming Basics
- Text Processing
- Database Design
- Normalization
- Linux
- Server Security
- Linux Foundation
- Open Standards
- Legacy Code
- Documentation
- AI Workflow
- File Uploads
- Test Data
- Hashing
- Performance
- Caching
- Enums
- Scope Creep
- Estimation
- Codex
- Gemini CLI
- Timezones
- Carbon
- Bugs
- PHP 8.5
- Gemini 3
- GPT-5.1
- Data Integrity
- Event Loop
- Async
- Opus 4.5
- AI Models
- React
- Forms
- Frontend
- Backups
- AI Images
- DALL-E
- Midjourney
- Race Conditions
- Concurrency
- Legacy Code
- Refactoring
- Senior Engineer
- Scope
- LLM
- CDN
- Web
- Sub-Agents
- Soft Deletes
- Audit Log
- Concurrency
- AI Learning
- NestJS
- AI Evals
- Policies
- SPF DKIM DMARC
- Unicode
- UTF-8
- Knowledge Graph
- Value Objects
- Technical Debt
- Feature Flags
- Laravel Pennant
- Deployment
- Copilot
- Composer
- Dependencies
- Artisan
- Automation
- AWS S3
- Object Storage
- Cloud
- Small Language Models
- Ollama
- Production
- Sessions
- HTTP
- Mentoring
- SQL
- Virtual Machines
- Web Development
- HTTP/2
- QUIC
- Web Performance
- AI Integration
- LLM API
- SOLID
- OOP
- Hosting
- Serverless
- Merge Conflicts
- Temperature
- AI Development
- Reverse Proxy
- Nginx
- Infrastructure
- Verification
- Passkeys
- WebAuthn
- Teams
- Communication
- Stakeholders
- Monorepo
- CI/CD
- Versioning
- JSON Schema
- Livewire
- Inertia
- Meetings
- Distributed Systems
- Privacy
- Full-Stack
- T-Shaped Skills
- Money
- Notifications
- Web Security
- HTTP Headers
- CSP
- Function Calling
- Load Testing
- k6
- Data Extraction
- Debugging
- WebSockets
- SSE
- Real-Time
- Laravel Reverb
- Infrastructure as Code
- Terraform
- Side Projects
- Laravel Pint
- OpenAPI
- Swagger
- UX
- Multimodal
- Jest
- Pair Programming
- APIs
- Rate Limiting
- Resilience
- Dev Humour
- Design Tokens
- JWT
- API Keys
- Sessions
- PHPStan
- Rector
- Incidents
- Reporting
- Dashboards
- Zero Trust
- IAM
- Search
- Laravel Scout
- Junior Developers
- Mentoring
- Images
- WebP
- AVIF
- Bug Reports
- Let's Encrypt
- Design Docs
- Software Design
- Observers
- Replication
- Accountability
- Data Structures
- Reliability
- LLM Memory
- Error Handling
- Payments
- Payment Gateway
- Webhooks
- PCI DSS
- Observability
- OpenTelemetry
- Personal Brand
- Writing
- Conventions
- Dates
- Scheduling
- Disaster Recovery
- Compression
- Brotli
- Deadlines
- Developer Habits
- State Machines
- Tech Roles
- UUID
- ULID
- Horizon
- Planning
- Engineering Culture
- Ownership
- Soft Skills
- Socialite
- Cost Control
- Collations
- Unicode
- Octane
- PostgreSQL
Zero Trust Security Explained Simply: Why "Inside the Network" Means Nothing
About Post
For a long time, company security worked like an old office building. Getting past reception was hard. But once you were in, you could wander anywhere: any floor, any meeting room, any unlocked filing cabinet. Being inside was the permission.
Networks were built the same way. A firewall at the edge, a VPN to get in, and inside, everything trusted everything. The admin panel only checked that you came from an internal IP address. The database accepted connections from anything on the same network.
Zero trust is the idea that this was always a bad deal. It's become a buzzword that vendors stick on everything, but the core idea is simple and, honestly, a bit obvious once you hear it.
The one-sentence version
Never trust a request because of where it comes from. Check who is making it, from what device, and whether they should be allowed to do this specific thing, every time.
A better analogy than the office is a modern hotel. Your key card opens your room and the gym. Not other rooms, not the kitchen, not the server cupboard. It stops working when you check out. And the hotel can cancel it instantly if you lose it. Being inside the hotel gives you nothing by itself.
Why the castle-and-moat model stopped working
- There's no "inside" anymore. People work from home, cafés and phones. Apps run in AWS, email is a SaaS product, files live in cloud storage. The perimeter has holes everywhere by design.
- Attackers get in eventually. One phishing email, one reused password, one unpatched laptop. Once they're inside a flat, trusting network, they move sideways to everything else. That "lateral movement" is what turns a small breach into a big one.
- Insiders and mistakes exist. Not every risk is a hooded hacker. Over-broad access turns an honest mistake into an incident.
The US standards body NIST describes zero trust architecture in its publication SP 800-207, and Google's BeyondCorp work is the best-known early example of a company moving its staff off the VPN model. You don't need to read either to apply the idea, but they're a sign this isn't just marketing.
The principles, in plain words
1. Verify explicitly
Every request is authenticated and authorised, based on identity and context, not network location. Strong sign-in is the foundation: single sign-on so there's one place to control access, and multi-factor authentication. Phishing-resistant methods like passkeys and security keys are the gold standard, because a code from an SMS can be phished and a passkey can't be used on a fake site.
2. Least privilege
Everyone (and every service) gets the minimum access needed, for the minimum time. The finance team gets the finance app, not the whole network. Admin rights are granted when needed and expire, rather than living permanently on someone's everyday account.
3. Assume breach
Design as if an attacker is already inside, and limit what they can reach. Segment networks and systems so one compromised laptop or server can't talk to everything. Encrypt traffic even between internal services. Log access so you can see what happened.
4. Check the device, not just the person
A valid password typed on an unpatched, unmanaged laptop is a risk. Mature zero trust setups check device health before granting access: is it a company device, is the disk encrypted, is the OS up to date?
The mindset shift: the question changes from "is this request coming from inside our network?" to "who is this, on what device, asking for what, and should they be allowed right now?"
What it means for developers
Zero trust isn't only an IT department project. A lot of it lives in the code we write:
- Don't use the network as your auth. "This endpoint is internal, so it doesn't need authentication" is the castle model in a single line. If an attacker lands on any internal machine, that endpoint is theirs. IP allow-lists can be a useful extra layer, never the only one.
- Services should prove who they are to each other. Service-to-service calls should carry credentials (scoped tokens, signed requests, or mutual TLS), and each service should check them.
- Give each app its own, smallest credentials. A reporting service needs read access to some tables, not the root database user. In AWS, that means IAM roles scoped to what each workload actually does, not one all-powerful key shared everywhere.
- Authorise every action, not just the login. Being signed in proves who you are. It doesn't prove you can view this contract or approve this payment. Check permissions on each request (in Laravel, policies and gates exist for exactly this).
- Keep sessions and tokens short-lived and revocable, so access can actually be taken away.
- Log access to sensitive data, with enough detail to answer "who looked at this, and when?"
Three myths worth dropping
Myth: zero trust is a product you buy. Vendors sell components (identity providers, device management, secure access gateways), but zero trust is an approach. You can't install it, any more than you can install "good code".
Myth: zero trust means we don't trust our people. It's not about suspicion. It's about not giving every account the power to cause a disaster if it's stolen. Your colleagues' passwords can be phished however trustworthy they are.
Myth: it's all or nothing. Nobody flips a switch. It's a direction you move in, one improvement at a time.
Where a small team can start
You don't need an enterprise budget to move in this direction. A practical order:
- Single sign-on for the main business apps, and MFA everywhere, starting with admin and email accounts.
- Remove shared accounts and standing admin rights. Named accounts, elevated only when needed.
- Review who can access what, and remove what isn't needed. Do it again every few months, and when people change roles or leave.
- Put authentication in front of every internal tool, including the ones "only reachable from the office".
- Manage and patch company devices, with disk encryption turned on.
- Segment the network so guest Wi-Fi, office devices and servers can't freely reach each other.
Each step makes a stolen password or an infected laptop less catastrophic. That's really all zero trust promises: not that nothing will ever go wrong, but that when it does, the damage stays small.
Which "internal only" endpoint or shared admin account would you fix first if you started on this tomorrow? Most of us have at least one.

Be first to comment it...