logoalt Hacker News

Sentinel-gateyesterday at 5:42 PM2 repliesview on HN

Yeah, more and more. Zero-trust is pushing TLS everywhere, even inside VPNs — lateral movement is a real thing. And several compliance frameworks now expect encryption in transit regardless of network topology. With connection pooling the overhead is basically zero anyway.


Replies

freedombenyesterday at 6:13 PM

Indeed, if you're running the db in production and aren't using TLS, you're doing it wrong nowadays. Nearly every compliance framework will require it, and it's a very good idea anyway even if you don't care about compliance.

singpolyma3today at 12:03 AM

... but if it's over a VPN it's already encrypted in transit?