Nile Minds the Zero Trust Gap at MFD14

Nile continues to share how they are rebuilding the network for a Zero Trust world. That means no vlans, no layer 2 access. Removing the Security Gap.

Is that what’s best for a modern network? Let’s dig into what Nile presented at Mobility Field Day 14.

The big push the last 15 years is about network segmentation and limiting access. That is at the top of most security checklists. I’ve personally been on a venture to build better segmentation into the networks I support. That is a Gap, the industry continues to struggle to close.

Nile mentioned one such vulnerability that made a lot of noise but was largely brushed off by the Wi-Fi vendors, AirSnitch.

AirSnitch

The vulnerability that gain a lot of attention. Wi-Fi is vulnerable was the claim.. but only under certain circumstances and if the attacker was already on the network. It wasn’t really a Wi-Fi problem but an architecture problem with relying on Layer 2.. the problem we’ve known about when it comes to segmentation for a long time.

Nile says that because of how they have architected their infrastructure, they are not susceptible to AirSnitch because they remove Layer 2 attack vectors. They are building a Zero Trust architecture that all traffic has to be verified instead of trusted by default as old architectures follow. It’s semantics to many because they are still using industry technologies, just muddying the water in obfuscating the VLAN out of the network because of higher network layers. Wi-Fi operates at the Layer 1 and Layer 2 only. So removing the layer 2 vulnerabilities is a step in the right direction.

Trust Circles

A lot of technologies rely on that Layer 2 design.. especially when it comes to homes and students. So Nile discussed how to handle Residents or Student housing. They have created some Nile Trust Circles that allow access between devices at the layer 2 level but only certain devices. Other devices are still protected from accessing those devices even if they are connected to the same SSID on the same AP. This raises some additional problems we asked about such as sharing a neighbor’s device on a separate apartment’s network to say Airplay to an Apple TV. This is an issue, but this is what Zero Trust is calling for. Always Verify, Never Trust.

So is a Zero Trust architecture network right for your network? Maybe. There are more pieces to Nile. They are following the Network as a Service model. This fits some orgs but not everyone. Is preventing a security vulnerability worth redesigning how your whole network runs? Maybe.

Nile has a compelling product but there are still a lot of features to figure out for your individual setup. I’m not ready to give my whole network over to Nile but am intrigued to have a Zero Trust network design. From multiple discussions with them over the years, they are moving in the right direction. Is the Gap being closed? That is up for your specific network engineer or maybe accounting department to flesh out.

Check out Nile’s presentation about the Security Gap from MFD14.

Marko Does Wireless
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.