Virtual Private Networks (VPNs) were introduced roughly two decades ago, aiming to provide organizations with secure remote access by establishing an encrypted tunnel between a computing device and a network.
The appliances were secure – albeit with certain limitations – but VPNs have been infamous for their sluggish performance and can be challenging to manage for IT admins.
Moreover, VPNs weren’t designed for today’s sophisticated cyber attacks, nor the ever-growing distributed workforce in mind, leaving organizations that use them vulnerable to threats that can lead to data breaches.
Learn more by reading this VMblog Expert Q&A with Tim Jester, Senior Product Marketing Manager for Keeper Security, with more than 10 years of experience in consulting, cloud, security and identity marketing. Tim now leads product marketing to apply Keeper’s award-winning technology to solve real world problems.
VMblog: 93% of organizations currently use a VPN – Are you saying there is some sort of misplaced trust in VPNs?
Tim Jester: A significant challenge associated with VPNs is their limited granular control over permissions.
Upon authentication, remote users are typically categorized as “trusted,” which can lead to them being granted excessive network access privileges.
This level of access can potentially expose network resources to insider threats. Additionally, the performance of VPNs tends to be unreliable, leaving employees to seek insecure alternatives.
VMblog: What are some of the main issues for IT admins with VPNs?
Jester: Tracking user activity with a VPN is complex.
In a distributed network environment that leverages the cloud, remote employees often require secure access to numerous servers. Consequently, every one of these VPN appliances and end-users will also have a policy to maintain and synchronize.
As the checklist grows, IT teams commonly rely on complex dashboards to gain insight into access permissions and their associated policies.
This added layer of complexity can cause IT admins to overlook certain tasks, opening the door to security risks.
VMblog: I see. Any other?
Jester: Major VPN providers frequently identify new vulnerabilities, which, upon disclosure, tend to draw cybercriminals like magnets.
Because VPNs generally establish a connection between an entry and an exit point, these weaknesses are relatively easy to uncover. Malicious actors can obtain data pertaining to a VPN connection, even when encryption is used. As a result, it becomes easier to manipulate the underlying network infrastructure, gain access to VPN traffic, move laterally across a network and target vulnerabilities.
As these vulnerabilities require immediate patches on a regular basis, VPN users must continuously keep their service up to date with substantial software updates.
VMblog: In the post-pandemic workplace, IT infrastructure isn’t the only thing that’s distributed; workforces are too – making VPNs a very popular target for attackers. What kind of security model can help combat that?
Jester: As most organizations now rely primarily on cloud-based data and systems, ensuring least privileged access is key to data and network security in remote and hybrid work environments.
A zero-trust security framework is centered around three core principles that solve this issue: assume breach, verify explicitly and ensure least-privilege access.
Instead of implicitly trusting all users and devices within the network perimeter, zero trust doesn’t trust any of them. Zero trust assumes that all users and devices could potentially be compromised, and everyone, human or machine, must be verified before they can access the network. Once logged in to the network, users should have the minimum amount of network access they need to perform their jobs, and nothing more.
When deployed properly, the zero-trust model gives IT administrators full visibility into all users, systems and devices, helps ensure compliance with industry and regulatory mandates, and helps prevent cyber attacks caused by compromised user credentials.
According to a 2022 IBM study, only 41% of organizations stated that they utilize a zero-trust security architecture – Leaving the other 59% at risk of potentially incurring millions of dollars in security breach costs.
VMblog: Does Keeper have any secure substitute for VPNs?
Jester: As part of our next-gen Privileged Access Management platform, Keeper Connection Manager (KCM) provides users with a remote desktop solution that reduces administrative overhead, and improves reliability, performance and employee productivity.
Moreover, with a zero-trust framework and zero-knowledge security architecture, Keeper stores all customer data in a secure vault with multiple layers of encryption keys, making it more secure than VPNs.
As a result, KCM users are able to access remote desktops and apps from a web browser, on their device of choice, using only their credentials – securely.
VMblog: How does Keeper Connection Manager work exactly?
Jester: KCM is a clientless remote desktop gateway powered by Apache Guacamole, an open-source, clientless, remote desktop software relied upon by tens of millions of people worldwide:
- “Clientless” means only a web browser is needed for access. No need to download or install anything.
- “Remote Desktop” refers to the use of one machine to access another remotely.
- “Gateway” refers to the centralized server the software is installed on, which is where all traffic travels through.
Keeper uses standard protocols like RDP, VNC, SSH, etc., and there’s a translation layer that standardizes everything and presents the desktop to the user.
VMblog: Many organizations use separate tools to provide remote users with access to internal devices. While internal users might log in using IPsec remote access VPN solutions, third parties or internal users on BYOD might use proxies and SSL VPN solutions. What are the challenges with those and how can Keeper help?
Jester: Disparate remote access infrastructures pose significant challenges, including limited scalability and agility, high levels of administrative overhead, end-user confusion, and of course, security issues. Visibility into this type of setup is limited, and it’s extremely difficult to uniformly enforce security policies organization-wide.
Keeper Connection Manager enables administrators to provide IT and DevOps personnel with secure, privileged remote access through RDP, SSH, VNC, MySQL and other common protocols.
Fine-grained controls also enable administrators to provide access to the entire system – or just one machine. Access can be revoked at any time, and a robust audit trail identifies when and how the system was used.
VMblog: What makes Keeper different in the Privileged Access Management (PAM) landscape?
Jester: One of the things that really makes Keeper stand out is how easy it is to deploy and procure. Many PAM platforms are so complex that even after 12 months, they are only partially deployed.
Both zero knowledge and zero trust are at the core of what Keeper does, ensuring data privacy through our unique security and encryption model.
KeeperPAMTM is a next-gen platform that has all the necessary features, without any of the bloat that many other solutions consider acceptable. Professional services should not be required to update software.
It’s a much more user-friendly deployment without sacrificing security.
VMblog: How do people know Keeper is secure?
Jester: At Keeper, we pride ourselves in being extremely open about our security and encryption model.
We have a host of industry certifications, such as SOC-2 Type2 and ISO 27001 compliance, Fips 140-2 validation, FedRAMP and StateRAMP Authorization and more.
Probably the most important part of our security model is our true zero-knowledge approach. Users have control of their data, and even an admin cannot view or access any sensitive information without sharing or configuration changes.
The user is the only person who has full control over the encryption and decryption of their data.
Talk to one of our experts to learn more about Keeper Connection Manager today and get powerful, one-click, zero-trust access to your remote infrastructure.
##






