authors
Colin Mo
Colin Mo articles and resources from Pomerium.

Topic archive
More from Colin Mo
Introducing Pomerium Ingress Controller for Kubernetes
UPDATED Dec 2025: Looking for options to replace NGINX? We've written a short tutorial on how to migrate from NGINX to Pomerium's ingress control by adding a few lines to you config. Check it out here .

Announcing FleetDM integration for adding device context to access control
Announcing our FleetDM integration to bring mobile device management into Pomerium's zero trust access control

Security is Usability — Examining Cybersecurity Erosion
We examine cybersecurity erosion, the concept that security systems are only as good as their least compliant user. To avoid it, security should always be designed to be usable.

Decisionmaker's Guide to Cloud Workstations
This guide will examine three common cloud workspace solutions, their trade-offs, and points of concerns that decisionmakers should keep in mind.
Achieving zero trust with Pomerium JWTs
We discuss how Pomerium JWTs enable zero trust architecture for verifying each request.
Announcing Pomerium v0.27
Pomerium v0.27 brings new features, performance improvements, and quality of life upgrades to our zero trust reverse proxy.
August 2024 Newsletter
Our newsletter covers the CrowdStrike BSoD incident, the ongoing Snowflake meltdown, and an upcoming Pomerium Zero feature!

The Real Lessons from the Snowflake Breach
Snowflake's breach showed companies have the Perimeter Problem, lack context-aware access control, and give third-parties too much access.
Network-centric vs Application-centric Approach
The traditional network model results in the Perimeter Problem. Here's why companies should be using the application-centric approach for better usability and security.

CrowdStrike is a Harsh Reminder of the Danger of Third-Party Clients
The true lesson from the CrowdStrike BSOD debacle: avoid third-party clients
Introducing Pomerium Zero
Pomerium Zero is a NextGen Access Platform for building secure clientless connections to web applications and services.
Announcing Pomerium v0.26
Pomerium v0.26 is here! This update focuses on bug fixes, performance, and stability improvements as well as policy builder enhancements for working with client certificates in Pomerium Enterprise.

4 Trends Shaping the Future of Access Control
Access control is no longer an afterthought of the development process – it's the cornerstone of a secure environment. The rise of remote work has fundamentally changed how we access data and resources. Organizations now face the challenge of securing access for a distributed workforce while also fending off increasingly sophisticated cyberattacks. Weak access controls leave businesses vulnerable to data breaches and unauthorized access.
Announcing Pomerium v0.25
Pomerium v0.25 is here! This is a performance and maintenance-focused upgrade to everyone’s favorite identity and context-aware proxy for clientless access.
Announcing Pomerium v0.24
Pomerium v0.24 is here! This performance-focused upgrade helps Pomerium run faster and returns it to its previous baseline RAM-usage in addition to adding certificate matching to the Enterprise Console PPL builder.
Elevating Remote Access: Understanding NextGen VPN Flaws
Virtual Private Networks (VPNs) have been around for decades, providing secure connections between remote locations and enabling remote workers to access company resources. NextGen VPNs, such as StrongDM , Tailscale , and Twingate offer streamlined experiences and advanced features that organizations not only use but also adore.
Applying Zero Trust to Multi-Cloud Environments
We read the National Institute of Standards and Technology (NIST)’s SP 800-207A: A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments to summarize it so you don’t have to.

Logs Are Incomplete Without the “Why”
When we talked about observability , we mentioned how logging and auditing is a mainstay of access control tools. One of the problems we see with logging today is a focus on the input and output, but lacking the system’s reasoning. This reasoning, known as the why, is important for simplifying the time to resolve issues.
Signed Headers: A Safety Net for Application Security
Cryptographically signed headers are a failsafe authentication mechanism for protecting your applications when Mutual Transport Layer Security (mTLS, also known as mutual authentication ) fails. Utilizing signed headers provides defense in depth to the protected application when:
Announcing Pomerium v0.23
Pomerium v0.23 is here! This version brings improved Observability capabilities and mTLS settings, followed by major performance improvements and bug fixes. All of the changes apply to Pomerium Core!

The Three Pillars of Observability
Observability is key to understanding your system’s performance and health. Learn how metrics, traces, and logs provide essential insights for monitoring, troubleshooting, and optimizing your infrastructure.

What is Zero Trust Architecture and Security?
The term "Zero Trust" has been co-opted by many marketing branches of products, but it has a defined meaning with real industry impact.

Zero Trust Maturity Rubric and Tool Matrix
Version 2 of CISA's Zero Trust Maturity Model expands on content and guidance compared to the first version, but a very specific change should be addressed:

IAM Trends and Future Outlook
Earlier this year, CISA (Cybersecurity and Infrastructure Security Agency) released their Enduring Security Framework Guidance on IAM (Identity Access Management). While we highly recommend practitioners read the document itself for its best practices and list of immediate actions, we want to discuss some of CISA’s best practices as well as their current and future trends.

SSO: OAuth2 vs OIDC vs SAML
Single Sign-On (SSO) is a way for users to be authenticated for multiple applications and services with one process. Should you use OAuth2, OIDC, or SAML?
Best VPN Alternatives
VPNs are insecure and slow. Here are the top VPN alternatives.

5 Lessons Learned Connecting Every IdP to OIDC
Integrating OIDC with various identity providers (IdPs) is notoriously complex and time-consuming for developers. We share five lessons learned while simplifying the process, including the challenges of standardizing tokens, handling directory sync at scale, and managing diverse IdP quirks.

Tailscale & Pomerium: Better Together
Tailscale is an encrypted network mesh that allows you to connect devices across different networks and make them accessible from anywhere in the world. Many of Tailscale’s customers use them to simplify networking and replace the traditional VPN.
Announcing Pomerium v0.22
Pomerium v0.22 is here! It’s got new features, one for getting Pomerium up and running faster and the other for simplifying policy writing. Then, we have support for a new identity provider (the fruit), followed by performance improvements and bug fixes.

What Is SASE? — A Buyer’s Guide
Update: Gartner is now supporting the service chained products they once warned about.

Device Management: Essential for Workplace Security and Efficiency
The digital workplace is using more devices in pursuit of workflow efficiency. This presents challenges for company networks, as every device costs the organization in terms of security risk and increased management burden.
Pomerium Best Practices
You’ve got web apps and we’ve got a context-aware proxy for zero trust access control. (For the non-technical, it’s a form-fitting and flexible hazmat suit for your applications on the internet.)

The Perimeter Problem: Why Traditional Network Security Fails
Traditional network perimeter defenses are failing, called the Perimeter Problem. We discuss the pitfalls of tunneling tools, and why going perimeter-less is the best option.

Pomerium and CHT Security Partner for Zero Trust Network Access Solution
For the Mandarin Chinese version of this announcement, please see CHT Security's post here .

A Case Against Layer 4 Security Tools
We often talk about how Layer 4 tooling such as VPNs are bad for security , so this post is going to dig into why. If you just want the conclusion, it's simple: Layer 4 tooling is fundamentally blind to its own traffic and Layer 7 tooling is not, which leads to different results for auditing, logging, and continuous verification.
Announcing Pomerium v0.21
While we’ve been cooking up something big , we have some nice entrees to whet your appetite. Pomerium v0.21 is packed with performance improvements, bug fixes, new features, and feature updates, including:

VPNs Are Killing Productivity
VPNs have long been the standard for secure remote access, but they come with significant drawbacks like poor security, performance issues, and increased IT workloads. As remote work continues to evolve, organizations must rethink their approach to access control.

Benefits of Zero Trust Architecture as Defined by NIST
NIST has released a draft of SP 1800-35 , Implementing a Zero Trust Architecture. The lengthy documents lay out their definition of Zero Trust Architecture (ZTA) , the benefits, why it’s important, a few examples of how an organization can implement them, expected results associated with their example builds, and a mapping of ZTA security characteristics to current cybersecurity standards and compliance.

A Close Read at NIST’s Definition of Zero Trust Architecture
This is written based on the second draft of SP 1800-35.

Minimizing CORS Misconfigurations
Cross-Origin Resource Sharing (CORS) is a security mechanism that allows web browsers to only make requests to a different domain if that domain has explicitly granted permission. This is done to prevent malicious websites from making unauthorized requests to other domains and misconfigured CORS can be easily exploited by hackers .

Jsonnet is better than YAML for generating JSON
We compare YAML to Jsonnet, and conclude Jsonnet might be the more efficient choice for complex projects.

Your Portal is Showing
Something’s happening in the realm of cybersecurity: breaches and data leaks are happening everywhere . Here’s a shortlist of the last few months:
Announcing Pomerium v0.20
New year, new big release! We’re thrilled to announce Pomerium v0.20, including:
Analyzing the US Government’s Adoption of Zero Trust
Two years ago, we published our original Demystifying Zero Trust to discuss the following topics without marketing buzzwords:
Stellenbosch University Secures Internal Assets with Pomerium
Stellenbosch University’s Computer Science department needed a scaling solution for safely exposing internal applications and resources to the internet. The solutions from Information and Communication Technology (ICT) services were not well suited to meet all of Computer Science’s (CS) requirements; notably, the VPN solutions would have added too large a layer of complexity for students. After testing out remote proxy solutions and briefly considering CloudFlare Access, Stellenbosch became drawn to Pomerium’s solution as a VPN-alternative.

Proxy vs Reverse Proxy
What's a forward proxy vs reverse proxy? We explore what proxies are and how they can be used to secure access.

Authn vs. Authz — Authentication vs. Authorization
When it comes to access control, authentication (AuthN) and authorization (AuthZ) fulfill different functions as methods to control access. In the modern world, those resources can be sensitive assets, applications, programs, devices, or more.

Prevent Insider Attacks With Context-Aware Access
Employees are a constant insider risk — they can expose, leak, or steal data from the organization at any moment with their existing access. Because of this, IT professionals have a common mandate to mitigate insider risk.

Highlights from IBM’s Cost of a Data Breach 2022
IBM’s yearly Cost of a Data Breach 2022 report is out. The 59 page report by IBM and the Ponemon Institute contains findings based on over 3,600 interviews studying 550 organizations impacted by data breaches that occurred between March 2021 and March 2022. The breaches occurred across 17 countries and regions and in 17 different industries.

Remote Work Infrastructure
The discussion for or against remote work is mostly settled — and remote work has won despite the wishes of the tech giants . The studies prove that remote workers are more productive , are less likely to churn , and expect remote work to be normalized going forward . When it comes to the critical metrics of workforce productivity and employee retention, remote work is a clear winner. Embracing remote work also means saving money in the long run for both employees and employers.

How Context Drives Full Access Decision-making
Access is an interesting topic. Fundamentally, it means “ permission, liberty, or ability to enter, approach, or pass to and from a place or to approach or communicate with a person or thing ." In the context of security, the layman might phrase access as: ”Who can do that?”

How Breaches Affect Companies
Cybersecurity professionals have a fundamental problem: you’re protecting a company that doesn’t understand or appreciate what you do. Upper management is loathe to give security any more resources than what they deem “enough” and your work is seen as a necessary evil. No one considers the effort necessary to minimize risk when no breaches have happened — and when a breach does occur (one you probably warned about), the blame falls onto you.

Security Posture: When and How to Reevaluate
Security posture isn't a concern for organizations unless they're trying to make compliance audits. After all, the perception has been that security is just a cost center and a hindrance to more productivity.

Q&A with Zero Trust Architecture Writers from NIST
We interviewed Scott Rose and Oliver Borchert from the National Institute of Standards and Technology (NIST) about their publication on Zero Trust Architecture (ZTA) discussing zero trust principles and how it affects organizations.

Insulation from Third-Party Breaches
The world’s #1 identity platform Okta has suffered a potential breach , and thousands of their corporate customers find themselves wondering if they may need to take corrective measures. Though Okta’s Chief Security Officer David Bradbury officially claims “There is no impact to Auth0 customers, and there is no impact to HIPAA and FedRAMP customers”, companies like Cloudflare have taken preventative measures to protect their internal and external accounts against hackers that may exploit Okta’s potential security breach.
Announcing Pomerium v0.17
We are pleased to announce the v0.17 release of Pomerium! This release includes several long requested features, including:

Log4J and the Fragility of Modern Infrastructure
It’s like watching a slow-motion train crash come to fruition. XKCD drew a comic in August 2020 effectively predicting an issue just like the Log4j RCE exploit , but we predict it to be the first of many headline-worthy exploitable dependencies.
Announcing Pomerium v0.16
We are pleased to announce the v0.16 release of Pomerium! This big release includes several new features, including: a native Kubernetes Ingress Controller, a new desktop app to make working with TCP connections even easier, the ability to enforce device identity with WebAuthn, and the introduction of a concise but expressive policy language.

Social Engineering — An Enduring Vulnerability
While the world is still reeling from the Log4j RCE vulnerability and organizations around the globe are undoubtedly scrambling to secure their infrastructure, the recent IKEA email reply-chain cyberattack has become buried in the news. Yes, it is important for companies to secure themselves against ubiquitous technical vulnerabilities that exist throughout their stack. But what are organizations doing about their own very vulnerable, very exploitable human personnel?

The Move to Passwordless Authentication
There's been a big move to passwordless authentication in recent years. After all, large scale data breaches are occurring on a weekly basis — and data breaches are just one way security breaches manifest themselves . Compromised credentials are, by and large, the hardest problem to identify and fix. Take a look at this chart from IBM's Cost of a Data Breach Report 2021 :

Elevate Productivity with Frictionless Security
It's not uncommon for organizations to deprioritize security as it's a cost center and is typically associated with negative effects on productivity. Many organizations equate security measures with increasing friction and frustrating work-arounds — resulting in Sisyphean uphill battles to introduce or change security measures. Just as no one likes TSA lines, no business wants to put operations at the mercy of security to the point of impacting productivity.

CyberSecurity Awareness Month: Cybersecurity First Aligned With Explore. Experience. Share.
Once again, we find ourselves combining the Cybersecurity & Infrastructure Security Agency's (CISA) Week 3 theme of Explore. Experience. Share. with Week 4's theme of Cybersecurity First. Ultimately, people and organizations can better prepare for an increasingly virtual world by sharing cybersecurity knowledge and making it top-of-mind.
CyberSecurity Awareness Month: Be Cyber Smart to Phight the Phish
October is CyberSecurity Awareness Month , and the first week's theme is Be Cyber Smart. We'll combine it with the second week's theme of Phight the Phish because the two are necessarily interlinked for organizations that want to prevent breaches.

August Newsletter
Hello again! August has been a busy month over here at Pomerium. This month’s newsletter covers some of the highlights since our v0.10 announcement .

Demystifying Zero Trust
Update: We have written a follow-up update post to this one — Demystifying Zero Trust With the U.S. Government.
