EN

Teleport: boost the security of your environments

Learn how Teleport redefines infrastructure access with its identity-native and zero-trust approach. Increase security without unique passwords.

CTO

João Brito

Teleport is the first identity-native infrastructure access platform. It is a platform used not only by engineers or machines, but also by services directly, such as accessing a database, for example.

First of all, we will talk about "identity native". What does this mean?

Identity-native consists of three components. The first component of identity-native access is moving away from secrets towards true identity.

By secrets, I mean things like passwords, private keys, browser cookies, session tokens, and API keys. All these things are secrets and make you vulnerable. Instead, Teleport utilizes true identity, which is a combination of biometrics and machine identity. This includes trusted platforms, hardware security modules, YubiKeys, and others.

In the context of Teleport, “identity-native” refers to an authentication feature that allows a user to use their existing identity from an external identity provider to log in to Teleport. This is known as federated authentication.

With “identity-native” federated authentication, Teleport utilizes an external identity provider, such as Google, Okta, GitHub, or other supported providers, to authenticate the user. This allows the user to access Teleport using their existing credentials from the external identity provider, rather than creating new Teleport-specific credentials, making day-to-day identity management easier.

Teleport supports various external identity providers and allows system administrators to configure the authentication system according to their security and compliance needs. “Identity-native” authentication is an option that can be used in conjunction with other authentication options available in Teleport.

The second component is Zero Trust, which is a security approach that assumes all requests to access resources on a network are potentially malicious, even those originating from within an organization's internal network. This means that every resource within the data center is automatically configured as if there was no security perimeter, making it as secure as it would be on the public network. As such, it utilizes a variety of security techniques, such as strong authentication and identity verification, to ensure that only authorized users and devices have access to protected resources. 

And the third component is the Teleport access policy, maintained in a single place.

This means that for all protocols, including Kubernetes clusters, databases, and remote desktop, the access policy will be managed in one single place.

Exploring the Security of Biometric Data Compared to Traditional Passwords

In fact, your credentials could not be stolen in this system, simply because your TPM (Trusted Platform Module) on your laptop and your fingerprint cannot be downloaded. Teleport does not see your fingerprint: it does not leave your laptop, which is why Teleport has no access to your fingerprint. The system uses a combination of biometrics and machine identity, such as TPMs, HSMs, and YubiKeys, to provide true identity authentication without relying on secrets like passwords or private keys. Your fingerprint is kept only on your own device and is not shared with Teleport.

“Identity-native” authentication eliminates the need for users to create and remember unique passwords for Teleport, which can lead to security issues like weak passwords or password reuse. Instead, users can use their existing credentials from the external identity provider to log in to Teleport, making the authentication process more secure and convenient.

Furthermore, “identity-native” authentication in Teleport is based on open standards such as OAuth2 and OpenID Connect, meaning it is compatible with a wide variety of external identity providers. This allows organizations to choose the identity provider that best meets their security and compliance needs.

Finally, “identity-native” authentication allows system administrators to centralize identity and access management in a single system, facilitating the implementation of security policies such as two-factor authentication, role-based access control, and access auditing. This can help improve the overall security of the system and reduce the administrative burden associated with managing user credentials.

Conclusion 

Teleport offers an identity-based infrastructure access platform that utilizes an identity-native, zero-trust approach, and centralized access policies. This makes the authentication process more secure and convenient, eliminating the need for unique passwords and allowing users to utilize their existing credentials from external identity providers. Additionally, the tool maintains the access policy in a single place, facilitating the implementation of security policies and reducing the administrative burden associated with managing user credentials. The use of biometrics and machine identity makes the authentication process more secure, eliminating the vulnerability of secrets like passwords or private keys. In summary, Teleport offers a more secure and efficient access platform for engineers and machines.

To elevate the security of your environments, speak to a specialist at Getup, the tool's ambassador in Brazil. Get in touch.


Newsletter Getup.

Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.

Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.