Home / Companies / Twingate / Blog / August 2022

August 2022 Summaries

7 posts from Twingate

Filter
Month: Year:
Post Summaries Back to Blog
With the increasing prevalence of remote work, traditional network architectures are no longer sufficient to provide a seamless experience for users. Slow-responding network connections directly impact user productivity and undermine business performance. Traditional secure perimeter technologies like VPNs and SD-WANs have inherent weaknesses that increase network latency and create poor user experiences. These solutions often concentrate traffic through gateways, causing congestion and backhaul issues. In contrast, Zero Trust Network Access (ZTNA) offers a better alternative by establishing direct connections between remote workers and the resources they access, eliminating congestion and backhaul associated with traditional gateways. ZTNA also enables split tunneling to further improve performance and provides granular access controls for improved security. By controlling access to both on-premises and cloud resources for all users, ZTNA relieves private networks from backhaul and unnecessary traffic, improving bandwidth, throughput, and latency.
Aug 26, 2022 4,661 words in the original blog post.
DNS filtering adds an extra layer of security to your employees’ internet use by giving you control over the websites that users access, intentionally or unintentionally. DNS filters act before a browser or other web-aware application ever connects to malicious or unauthorized sites. They can prevent user devices from becoming attack vectors and improve network performance by preventing access to bandwidth-hogging sites such as streaming services. Twingate's Secure DNS allows you to use DNS over HTTPS (DoH) for traffic outside the Twingate network, making DNS requests harder to intercept and modify. To enable DNS filtering services, you need to navigate to Settings > Secure DNS, toggle the switch to enable DoH, change the DoH resolver to Custom and add the URL for your DNS filtering service, choose a Fallback Method, and manage exceptions. This approach depends on how quickly DNS service providers spot emerging security threats. Any delay in updating a DNS filter’s blocklist leaves a window of opportunity for security breaches.
Aug 19, 2022 2,450 words in the original blog post.
TwinGate has integrated with Render, a unified cloud platform that automates infrastructure setup and enables developers to focus on building code. This integration allows users to securely access their internal networks without using VPNs, whether they're in the cloud, on-prem, or at home. The process of deploying Twingate connectors to Render involves connecting a GitHub account to Render, creating a remote network, generating connector tokens, and deploying the connectors to Render. Once deployed, the Twingate connector software runs on a Docker container and connects back to the user's cloud, providing secure access to their internal networks. The integration aims to rapidly implement a modern Zero Trust network that is more secure and maintainable than traditional VPNs.
Aug 16, 2022 2,282 words in the original blog post.
Transport Layer Security (TLS) is a cryptographic protocol that creates secure, private network connections over the public internet. It protects data passing over the internet by encrypting it with asymmetric and symmetric keys, ensuring authentication, data privacy, and integrity. TLS is used to secure web traffic, email, messaging, video conferencing, and other internet applications. Its most recognizable use is securing web traffic, but it also protects other forms of internet communications. TLS works in two stages: setting up a secure connection between a client and server and then using cryptography to protect the exchanged records. It uses digital certificates to confirm the server's and sometimes the client's identities and has built-in integrity checks to prevent tampering with data in transit. TLS is essential for protecting data passing over the public internet, especially when browsing the web or accessing other online services.
Aug 12, 2022 6,062 words in the original blog post.
WireGuard is a modern VPN protocol that aims to deliver performance, strong encryption capabilities, and a secure code base. Its kernel-level support for Windows has raised questions about its readiness to replace IPsec and OpenVPN. While WireGuard can outperform other protocols in terms of performance, it also has tradeoffs, such as limited federal approval and potential privacy concerns. Businesses may consider using WireGuard when they need a lightweight and secure solution, but larger organizations with specific use cases should carefully evaluate the risks and capabilities relative to IPsec or OpenVPN. Additionally, Twingate offers a more secure and performant alternative to WireGuard VPN based on a Zero Trust framework.
Aug 05, 2022 4,589 words in the original blog post.
Twingate and Indent partner to provide on-demand access control for high-growth companies, allowing engineers to dynamically access corporate resources across multiple cloud environments. This combination helps eliminate bottlenecks and increase security by reducing persistent elevated privileges. With Twingate and Indent together, teams can request access quickly, set the access duration, and automate access approvals, all while maintaining granular least-privileged access models and dynamic contextual access. The integration is designed to be easy to deploy, with step-by-step guides available on both platforms' documentation sites. By using Twingate and Indent, companies can rapidly implement a modern Zero Trust network that is more secure and maintainable than traditional VPNs.
Aug 03, 2022 1,490 words in the original blog post.
Twingate has announced its capability to protect and encrypt DNS (Domain Name System) traffic, a critical component of modern security strategies. The company's first ability to do so is designed to address the challenge of balancing security and usability when employees access both public and private resources from diverse networks worldwide. With this new feature, Twingate provides blanket DNS encryption for all DNS traffic on devices, ensuring that even non-browser-originated DNS requests are automatically encrypted. This system-wide DoH (DNS over HTTPS) capability enforces a comprehensive defense-in-depth strategy against various DNS-based attacks, including DNS poisoning and eavesdropping. By leveraging the Twingate client to route DNS requests to common DNS security tools like NextDNS, Cloudflare Gateway, and others, organizations can improve their cybersecurity posture without requiring additional installations or configurations.
Aug 02, 2022 3,029 words in the original blog post.