Twelve Years Without a VPN

Google says it ditched the office lock years ago — commenters say “nice ad, still a VPN”

TLDR: Google says it moved beyond the old office VPN years ago and is now pushing an even stricter system that controls exactly what people or software can do. Commenters were split between “this is smart” and “come on, this is just a rebranded VPN plus extra hassle,” which matters because companies are rushing to copy this stuff.

Google veteran Arthur Khessin dropped a bold flex: he says he hasn’t used a corporate virtual private network, or VPN, in more than a decade because Google replaced the old “office network = trusted” idea with a system that checks who you are and whether your device is safe every time. Now Google is pitching a sequel, Beyond Zero, which goes even further by deciding not just whether someone can open a system, but whether they can do a specific action on a specific piece of data. In plain English: not just “can you get in,” but “can you do this exact thing once you’re inside?”

But the real fireworks were in the comments, where readers instantly split into camps. One bluntly called the whole thing “an advertisement”, basically accusing the post of being less personal essay and more polished product pitch. Another came in swinging with the spicy counterclaim that Google didn’t kill the VPN at all — it just hid it inside the browser, with the delightfully meme-ready line that using Chrome is basically using a VPN anyway. And then came the practical grumbling: one commenter declared these “zero trust” gatekeepers a nightmare for simple automation, saying they make basic tasks harder than the supposedly old-fashioned VPN ever did.

Not everyone was mad, though. One supporter basically said: forget the shiny AI hype, this is the real breakthrough, because forcing companies to finally understand and organize their own data might be the true win. So yes, the article is about the future of security — but the comments turned it into a classic internet brawl over marketing spin, hidden complexity, and whether the “future” is genius or just a fancier login screen.

Key Points

  • The article says Google’s BeyondCorp model replaced corporate VPN-based trust with per-request access decisions based on user identity and device state.
  • It cites Google’s 2014 BeyondCorp paper by Rory Ward and Betsy Beyer as arguing that internal networks should be treated as untrusted like the public internet.
  • Khessin highlights the migration method described in the paper: netflow collection, laptop-based simulation, and user migration only after 30 days with over 99.9% compatible traffic.
  • The article states that zero trust was later standardized by NIST as SP 800-207 in 2020 and mandated for U.S. federal agencies in 2021.
  • It presents Beyond Zero as a new Google model that authorizes specific actions on specific records in context, rather than only granting broader application access after identity and device verification.

Hottest takes

"advertisement for something called Beyond Zero" — inigyou
"Running Chrome = running a VPN" — pir8life4me
"Zero trust proxies are the enemy of easy automation" — egamirorrim
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.