Skip to main content

authors

Colin Mo

Colin Mo articles and resources from Pomerium.

Colin Mo

Topic archive

More from Colin Mo

Announcing Pomerium v0.26
blog posts

Announcing Pomerium v0.26

Pomerium v0.26 is here! This update focuses on bug fixes, performance, and stability improvements as well as policy builder enhancements for working with client certificates in Pomerium Enterprise.

4 Trends Shaping the Future of Access Control
blog posts

4 Trends Shaping the Future of Access Control

Access control is no longer an afterthought of the development process – it's the cornerstone of a secure environment. The rise of remote work has fundamentally changed how we access data and resources. Organizations now face the challenge of securing access for a distributed workforce while also fending off increasingly sophisticated cyberattacks. Weak access controls leave businesses vulnerable to data breaches and unauthorized access.

Announcing Pomerium v0.24
blog posts

Announcing Pomerium v0.24

Pomerium v0.24 is here! This performance-focused upgrade helps Pomerium run faster and returns it to its previous baseline RAM-usage in addition to adding certificate matching to the Enterprise Console PPL builder.

Logs Are Incomplete Without the “Why”
blog posts

Logs Are Incomplete Without the “Why”

When we talked about observability , we mentioned how logging and auditing is a mainstay of access control tools. One of the problems we see with logging today is a focus on the input and output, but lacking the system’s reasoning. This reasoning, known as the why, is important for simplifying the time to resolve issues.

Signed Headers: A Safety Net for Application Security
blog posts

Signed Headers: A Safety Net for Application Security

Cryptographically signed headers are a failsafe authentication mechanism for protecting your applications when Mutual Transport Layer Security (mTLS, also known as mutual authentication ) fails. Utilizing signed headers provides defense in depth to the protected application when:

Announcing Pomerium v0.23
blog posts

Announcing Pomerium v0.23

Pomerium v0.23 is here! This version brings improved Observability capabilities and mTLS settings, followed by major performance improvements and bug fixes. All of the changes apply to Pomerium Core!

The Three Pillars of Observability
blog posts

The Three Pillars of Observability

Observability is key to understanding your system’s performance and health. Learn how metrics, traces, and logs provide essential insights for monitoring, troubleshooting, and optimizing your infrastructure.

IAM Trends and Future Outlook
blog posts

IAM Trends and Future Outlook

Earlier this year, CISA (Cybersecurity and Infrastructure Security Agency) released their Enduring Security Framework Guidance on IAM (Identity Access Management). While we highly recommend practitioners read the document itself for its best practices and list of immediate actions, we want to discuss some of CISA’s best practices as well as their current and future trends.

Announcing Pomerium v0.22
blog posts

Announcing Pomerium v0.22

Pomerium v0.22 is here! It’s got new features, one for getting Pomerium up and running faster and the other for simplifying policy writing. Then, we have support for a new identity provider (the fruit), followed by performance improvements and bug fixes.

Pomerium Best Practices
blog posts

Pomerium Best Practices

You’ve got web apps and we’ve got a context-aware proxy for zero trust access control. (For the non-technical, it’s a form-fitting and flexible hazmat suit for your applications on the internet.)

A Case Against Layer 4 Security Tools
blog posts

A Case Against Layer 4 Security Tools

We often talk about how Layer 4 tooling such as VPNs are bad for security , so this post is going to dig into why. If you just want the conclusion, it's simple: Layer 4 tooling is fundamentally blind to its own traffic and Layer 7 tooling is not, which leads to different results for auditing, logging, and continuous verification.

Benefits of Zero Trust Architecture as Defined by NIST
blog posts

Benefits of Zero Trust Architecture as Defined by NIST

NIST has released a draft of SP 1800-35 , Implementing a Zero Trust Architecture. The lengthy documents lay out their definition of Zero Trust Architecture (ZTA) , the benefits, why it’s important, a few examples of how an organization can implement them, expected results associated with their example builds, and a mapping of ZTA security characteristics to current cybersecurity standards and compliance.

Minimizing CORS Misconfigurations
blog posts

Minimizing CORS Misconfigurations

Cross-Origin Resource Sharing (CORS) is a security mechanism that allows web browsers to only make requests to a different domain if that domain has explicitly granted permission. This is done to prevent malicious websites from making unauthorized requests to other domains and misconfigured CORS can be easily exploited by hackers .

Stellenbosch University Secures Internal Assets with Pomerium
blog posts

Stellenbosch University Secures Internal Assets with Pomerium

Stellenbosch University’s Computer Science department needed a scaling solution for safely exposing internal applications and resources to the internet. The solutions from Information and Communication Technology (ICT) services were not well suited to meet all of Computer Science’s (CS) requirements; notably, the VPN solutions would have added too large a layer of complexity for students. After testing out remote proxy solutions and briefly considering CloudFlare Access, Stellenbosch became drawn to Pomerium’s solution as a VPN-alternative.

Highlights from IBM’s Cost of a Data Breach 2022
blog posts

Highlights from IBM’s Cost of a Data Breach 2022

IBM’s yearly Cost of a Data Breach 2022 report is out. The 59 page report by IBM and the Ponemon Institute contains findings based on over 3,600 interviews studying 550 organizations impacted by data breaches that occurred between March 2021 and March 2022. The breaches occurred across 17 countries and regions and in 17 different industries.

Remote Work Infrastructure
blog posts

Remote Work Infrastructure

The discussion for or against remote work is mostly settled — and remote work has won despite the wishes of the tech giants . The studies prove that remote workers are more productive , are less likely to churn , and expect remote work to be normalized going forward . When it comes to the critical metrics of workforce productivity and employee retention, remote work is a clear winner. Embracing remote work also means saving money in the long run for both employees and employers.

How Breaches Affect Companies
blog posts

How Breaches Affect Companies

Cybersecurity professionals have a fundamental problem: you’re protecting a company that doesn’t understand or appreciate what you do. Upper management is loathe to give security any more resources than what they deem “enough” and your work is seen as a necessary evil. No one considers the effort necessary to minimize risk when no breaches have happened — and when a breach does occur (one you probably warned about), the blame falls onto you.

Insulation from Third-Party Breaches
blog posts

Insulation from Third-Party Breaches

The world’s #1 identity platform Okta has suffered a potential breach , and thousands of their corporate customers find themselves wondering if they may need to take corrective measures. Though Okta’s Chief Security Officer David Bradbury officially claims “There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers”, companies like Cloudflare have taken preventative measures to protect their internal and external accounts against hackers that may exploit Okta’s potential security breach.

Announcing Pomerium v0.16
blog posts

Announcing Pomerium v0.16

We are pleased to announce the v0.16 release of Pomerium! This big release includes several new features, including: a native Kubernetes Ingress Controller, a new desktop app to make working with TCP connections even easier, the ability to enforce device identity with WebAuthn, and the introduction of a concise but expressive policy language.

Social Engineering — An Enduring Vulnerability
blog posts

Social Engineering — An Enduring Vulnerability

While the world is still reeling from the Log4j RCE vulnerability and organizations around the globe are undoubtedly scrambling to secure their infrastructure, the recent IKEA email reply-chain cyberattack has become buried in the news. Yes, it is important for companies to secure themselves against ubiquitous technical vulnerabilities that exist throughout their stack. But what are organizations doing about their own very vulnerable, very exploitable human personnel?

The Move to Passwordless Authentication
blog posts

The Move to Passwordless Authentication

There's been a big move to passwordless authentication in recent years. After all, large scale data breaches are occurring on a weekly basis — and data breaches are just one way security breaches manifest themselves . Compromised credentials are, by and large, the hardest problem to identify and fix. Take a look at this chart from IBM's Cost of a Data Breach Report 2021 :

Elevate Productivity with Frictionless Security
blog posts

Elevate Productivity with Frictionless Security

It's not uncommon for organizations to deprioritize security as it's a cost center and is typically associated with negative effects on productivity. Many organizations equate security measures with increasing friction and frustrating work-arounds — resulting in Sisyphean uphill battles to introduce or change security measures. Just as no one likes TSA lines, no business wants to put operations at the mercy of security to the point of impacting productivity.

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.
blog posts

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.

Once again, we find ourselves combining the Cybersecurity & Infrastructure Security Agency's (CISA) Week 3 theme of Explore. Experience. Share. with Week 4's theme of Cybersecurity First. Ultimately, people and organizations can better prepare for an increasingly virtual world by sharing cybersecurity knowledge and making it top-of-mind.

August Newsletter
blog posts

August Newsletter

Hello again! August has been a busy month over here at Pomerium. This month’s newsletter covers some of the highlights since our v0.10 announcement .

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo