[{"data":1,"prerenderedAt":342},["ShallowReactive",2],{"{\"cv\":1785043903981,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Fthe-internet-is-not-secure-by-design":3},{"data":4,"headers":320},{"story":5,"cv":317,"rels":318,"links":319},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":308,"full_slug":309,"sort_by_date":22,"position":310,"tag_list":311,"is_startpage":274,"parent_id":312,"meta_data":22,"group_id":313,"first_published_at":314,"release_id":22,"lang":315,"path":22,"alternates":316,"default_full_slug":22,"translated_slugs":22},"The Internet is not Secure by Design","2026-06-04T19:56:58.289Z","2026-07-25T19:03:27.480Z","2026-07-25T19:03:27.496Z",183965361344255,"a4b54366-44ea-4d2c-86a9-2948be900b46",{"Tags":13,"_uid":14,"title":15,"content":16,"component":268,"seoOgImage":269,"keyTakeaways":275,"previewImage":302,"previewTitle":304,"relatedContent":305,"seoDescription":306,"previewDescription":307},"","69a52ed9-008b-4441-a3c4-57b32d15254b","The internet is not secure by design.",{"type":17,"content":18},"doc",[19,27,39,44,49,81,86,97,108,117,125,130,135,140,147,152,157,162,167,172,192,197,213,227,234,239,244,251],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26},"Every day, our computers and smartphones receive updates with an endless array of security improvements. Headlines about hackers breaching major corporations and governments are so frequent that they become background noise.","text",{"type":20,"attrs":28,"content":29},{"textAlign":22},[30,32,37],{"text":31,"type":26},"Collectively, we expect that applications will forever have unforeseen issues and that it’s impossible for engineers to think of and proactively address ",{"text":33,"type":26,"marks":34},"all ",[35],{"type":36},"italic",{"text":38,"type":26},"security issues of the past and future. Features come first, and security comes second, if at all.",{"type":20,"attrs":40,"content":41},{"textAlign":22},[42],{"text":43,"type":26},"But what about our infrastructure?",{"type":20,"attrs":45,"content":46},{"textAlign":22},[47],{"text":48,"type":26},"Unfortunately, the internet itself was also designed feature-first.",{"type":50,"content":51},"blockquote",[52],{"type":20,"attrs":53,"content":54},{"textAlign":22},[55,61,76],{"text":56,"type":26,"marks":57},"“…[W]e were honestly not thinking…as much about security as we were about just getting it to work reliably.” — ",[58,60],{"type":59},"bold",{"type":36},{"text":62,"type":26,"marks":63},"Vint Cerf",[64,69,72,73,74],{"type":65,"attrs":66},"link",{"href":67,"uuid":22,"anchor":22,"target":22,"linktype":68},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FVint_Cerf","url",{"type":70,"attrs":71},"textStyle",{"color":13},{"type":59},{"type":36},{"type":75},"underline",{"text":77,"type":26,"marks":78},", a “Father of the Internet”",[79,80],{"type":59},{"type":36},{"type":20,"attrs":82,"content":83},{"textAlign":22},[84],{"text":85,"type":26},"After all, the internet is, at its core, a collection of software jammed together over time, vulnerable to the same ever-changing security challenges that plague other applications. The internet was not created to be “secure by design.\"",{"type":20,"attrs":87,"content":88},{"textAlign":22},[89,91,95],{"text":90,"type":26},"The good news is that there is hope. Key security measures and designs implemented in the network infrastructure we ",{"text":92,"type":26,"marks":93},"do",[94],{"type":36},{"text":96,"type":26}," control can transform a network built on insecure internet protocols into an ironclad fortress.",{"type":20,"attrs":98,"content":99},{"textAlign":22},[100,102,106],{"text":101,"type":26},"Regardless of the state of global networking infrastructure, companies have a cybersecurity duty to their customers and employees. Whether driven by legal requirements, moral obligations, or fiscal responsibility, companies must find a way to make ",{"text":103,"type":26,"marks":104},"their",[105],{"type":36},{"text":107,"type":26}," networks secure by design without altering the underlying structure of the internet.",{"type":109,"attrs":110,"content":112},"heading",{"level":111,"textAlign":22},2,[113],{"text":114,"type":26,"marks":115},"How to secure your network by design",[116],{"type":59},{"type":109,"attrs":118,"content":120},{"level":119,"textAlign":22},3,[121],{"text":122,"type":26,"marks":123},"Don’t Box Yourself In",[124],{"type":59},{"type":20,"attrs":126,"content":127},{"textAlign":22},[128],{"text":129,"type":26},"When designing a Secure By Design corporate network that overcomes the internet’s inherent flaws, few have the luxury of starting from scratch. Some parts of the current network will remain.",{"type":20,"attrs":131,"content":132},{"textAlign":22},[133],{"text":134,"type":26},"Recognizing this, careful planning is essential to ensure that your network can adapt to future cybersecurity challenges.",{"type":20,"attrs":136,"content":137},{"textAlign":22},[138],{"text":139,"type":26},"In practice, this means steering away from vendors that lock customers into proprietary formats and opting for widely-used portable standards instead. This approach allows your network to remain modular, flexible, and unlikely to require a complete overhaul as threat actors and security standards evolve over time.",{"type":109,"attrs":141,"content":142},{"level":119,"textAlign":22},[143],{"text":144,"type":26,"marks":145},"Free Network Designs from Real-World Constraints",[146],{"type":59},{"type":20,"attrs":148,"content":149},{"textAlign":22},[150],{"text":151,"type":26},"Traditionally, communication systems are designed as if information were a tangible asset.",{"type":20,"attrs":153,"content":154},{"textAlign":22},[155],{"text":156,"type":26},"For example, imagine that we had two camps (endpoints), Camp A and Camp B, surrounded by high walls (firewalls) that needed to exchange information.",{"type":20,"attrs":158,"content":159},{"textAlign":22},[160],{"text":161,"type":26},"A messenger from Camp A would journey to Camp B where they would plead their case and guards could decide to admit them into Camp B to deliver the message.",{"type":20,"attrs":163,"content":164},{"textAlign":22},[165],{"text":166,"type":26},"Of course, if the guards make the wrong decision about who to trust, Camp B could suffer a (literal) Trojan Horse attack.",{"type":20,"attrs":168,"content":169},{"textAlign":22},[170],{"text":171,"type":26},"This communication model, while risky, is so familiar to us as to be nearly automatic. But why, in the 21st century, do we still limit ourselves to insecure, medieval communication designs?",{"type":20,"attrs":173,"content":174},{"textAlign":22},[175,181,183,190],{"type":176,"attrs":177},"image",{"id":178,"alt":13,"src":179,"title":13,"source":13,"copyright":13,"meta_data":180},187881505536726,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1541x851\u002F944f4dfba2\u002Fperimeter-security-castle.png",{},{"text":182,"type":26},"Using digital tools without clear real-world analogues such as ",{"text":184,"type":26,"marks":185},"Zero Knowledge Proofs",[186,189],{"type":65,"attrs":187},{"href":188,"uuid":22,"anchor":22,"target":22,"linktype":68},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FZero-knowledge_proof",{"type":75},{"text":191,"type":26}," and outbound-only communication can provide orders of magnitude higher levels of communication security without adding additional complexity.",{"type":20,"attrs":193,"content":194},{"textAlign":22},[195],{"text":196,"type":26},"For instance, imagine if it was possible for Camp A and Camp B to exist without physical, public addresses, like they were shielded in an invisibility cloak. A messenger from Camp A could leave an encrypted message in a lockbox at a known middle location and walk away. A messenger from Camp B could later use a key to unlock the box, retrieve the message, and inspect it. If they determine it to be malicious, they can burn it right then and there, far outside the cloaked walls of Camp B.",{"type":20,"attrs":198,"content":199},{"textAlign":22},[200,205,207,211],{"type":176,"attrs":201},{"id":202,"alt":13,"src":203,"title":13,"source":13,"copyright":13,"meta_data":204},187881917737690,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1540x608\u002F95406a80a9\u002Fcamp-a-b.png",{},{"text":206,"type":26},"Critically, this design is ",{"text":208,"type":26,"marks":209},"not ",[210],{"type":36},{"text":212,"type":26},"the same as “break-and-inspect”. Camp B is inspecting the message contents themselves, not allowing a third (compromisable) party any access to the data whatsoever.",{"type":20,"attrs":214,"content":215},{"textAlign":22},[216,218,225],{"text":217,"type":26},"Designing robust networks requires careful planning and analysis. Simply using regulatory or compliance guidelines to secure a network is insufficient—compliance alone does not guarantee security, even with standards like ",{"text":219,"type":26,"marks":220},"NIST 800–207 (Zero Trust Architecture)",[221,224],{"type":65,"attrs":222},{"href":223,"uuid":22,"anchor":22,"target":22,"linktype":68},"https:\u002F\u002Fnvlpubs.nist.gov\u002Fnistpubs\u002FSpecialPublications\u002FNIST.SP.800-207.pdf",{"type":75},{"text":226,"type":26},".",{"type":109,"attrs":228,"content":229},{"level":119,"textAlign":22},[230],{"text":231,"type":26,"marks":232},"Warn Early, Warn Often",[233],{"type":59},{"type":20,"attrs":235,"content":236},{"textAlign":22},[237],{"text":238,"type":26},"Regardless of how secure a network is designed, knowing what’s going on across a network at all times is of paramount importance. Ideally, “out-of-band” notifications should be implemented—that is, created by an observer that is not reachable from the main network.",{"type":20,"attrs":240,"content":241},{"textAlign":22},[242],{"text":243,"type":26},"During modern cyberattacks, most rely on “in-band” notifications (e.g., IDS, IPS, firewall) to notify their administrators when something seems suspicious. But since these notifiers are part of the network that’s been attacked, there’s no assurance that they too haven’t been compromised in some way!",{"type":109,"attrs":245,"content":246},{"level":119,"textAlign":22},[247],{"text":248,"type":26,"marks":249},"Secure By Design In Practice",[250],{"type":59},{"type":20,"attrs":252,"content":253},{"textAlign":22},[254,256,266],{"text":255,"type":26},"Implementing the principles outlined above is not merely a theoretical exercise—commercial solutions such as ",{"text":257,"type":26,"marks":258},"Xiid’s Terniion",[259,265],{"type":65,"attrs":260},{"href":261,"uuid":262,"anchor":22,"target":263,"linktype":264},"\u002Fplatform","2b07cab0-dd04-48d6-92cd-0c7160179571","_self","story",{"type":75},{"text":267,"type":26}," platform are specifically developed to be secure by design.","BlogPost",{"id":270,"alt":13,"name":13,"focus":13,"title":13,"source":13,"filename":271,"copyright":13,"fieldtype":272,"meta_data":273,"is_external_url":274},187880212343499,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F7373x4147\u002Fc1c75306db\u002Fsoftware-engineer-writes-complex-binary-code-scripts-computer.jpg","asset",{},false,{"type":17,"content":276},[277],{"type":278,"content":279},"bullet_list",[280,288,295],{"type":281,"content":282},"list_item",[283],{"type":20,"attrs":284,"content":285},{"textAlign":22},[286],{"text":287,"type":26},"The internet was designed for connectivity, not security. Vint Cerf acknowledged security wasn't the priority; this is a foundational architectural flaw, not a patchable bug.",{"type":281,"content":289},[290],{"type":20,"attrs":291,"content":292},{"textAlign":22},[293],{"text":294,"type":26},"Companies can't fix the internet but can design their own networks to be \"secure by design\" using outbound-only communication, zero-knowledge proofs, and eliminated public IP addresses.",{"type":281,"content":296},[297],{"type":20,"attrs":298,"content":299},{"textAlign":22},[300],{"text":301,"type":26},"Compliance frameworks like NIST 800-207 are insufficient — compliance doesn't equal security, and network architecture matters more than policies layered on top.",{"id":270,"alt":13,"name":13,"focus":13,"title":13,"source":13,"filename":271,"copyright":13,"fieldtype":272,"meta_data":303,"is_external_url":274},{},"The internet is not secure by design. What can we do?",[],"See how Xiid SealedTunnel eliminates SSH attack surfaces, closes inbound ports, removes public IPs, and delivers quantum-secure, zero-knowledge protection—ending vulnerability cycles.","The recent discovery of critical vulnerabilities in OpenSSH (CVE-2024–6387and CVE-2024–6409) has sent shockwaves through the cybersecurity community.","the-internet-is-not-secure-by-design","blog\u002Fthe-internet-is-not-secure-by-design",0,[],193139877037850,"59ab45b1-1a23-42a4-98ee-908d5f930948","2026-07-25T00:31:18.999Z","default",[],1785043618,[],[],{"cache-control":321,"connection":322,"content-encoding":323,"content-type":324,"date":325,"etag":326,"referrer-policy":327,"sb-be-version":328,"server":329,"transfer-encoding":330,"vary":331,"via":332,"x-amz-cf-id":333,"x-amz-cf-pop":334,"x-cache":335,"x-content-type-options":336,"x-frame-options":337,"x-permitted-cross-domain-policies":338,"x-request-id":339,"x-runtime":340,"x-xss-protection":341},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","gzip","application\u002Fjson; charset=utf-8","Sun, 26 Jul 2026 05:32:11 GMT","W\u002F\"5099d77fa61a209fdb693ab4f395cb3b\"","strict-origin-when-cross-origin","5.924.0","nginx\u002F1.29.1","chunked","Origin,Accept-Encoding","1.1 e826e01cc4bc0a413496d51238909c7a.cloudfront.net (CloudFront)","NtITBb8dm3U-IExiJ7gFhNUsR4t0z7LeoLVc6Y1RnjS0eZED3Aee4Q==","CMH68-P4","Miss from cloudfront","nosniff","SAMEORIGIN","none","b1958031-7b3d-44dd-a053-d46251c33944","0.029358","0",1785043931578]