The Door I Left Unlocked Because It Was Inside

by Serguey Shinder

For years I built systems with a hard shell and a soft interior. The perimeter was fortified, every request from the outside world checked, validated, rate-limited, suspected. But once a call had made it past the front door, once it was inside the network, I treated it like family. Internal services trusted each other completely. They passed data without asking who was asking. I had built a castle with a magnificent gate and no interior locks at all.

The reasoning felt sound at the time, and it is the reasoning almost everyone starts with. The dangerous world is out there. In here, among our own services, we are among friends, and adding checks between components that we ourselves wrote and deployed seemed like paranoia, like frisking your own colleagues. So the inside stayed open, warm, and completely undefended, on the assumption that nothing hostile could ever get in.

The flaw in that assumption is not that the front door fails, although it can. The flaw is that a single compromised component on the inside inherits the trust of everything around it. If an attacker reaches one internal service, through a dependency, a misconfiguration, a leaked credential, they do not find another wall. They find a house where every interior door stands open and every occupant assumes anyone already inside belongs there. One breach becomes total, not because the perimeter was weak, but because the interior had no perimeters of its own.

I learned this not from a catastrophe, thankfully, but from a review where someone asked a simple question I could not answer. If this one service were compromised, what could it reach? The honest answer was everything, and hearing myself say it out loud made the soft interior suddenly look less like trust and more like negligence dressed up as trust.

What changed was not that I stopped trusting my own services. It was that I stopped letting location be a substitute for identity. Being inside the network is not a credential. It is just a position, and positions can be taken. So the interior doors got locks. Services now verify who is calling even when the caller is one of our own, not out of suspicion of my colleagues, but out of respect for the possibility that any one of us could be impersonated.

The castle is less comfortable to live in now. There are more checks, more identity, more friction between rooms. But comfort was exactly the thing the old design was optimizing for, and comfort is what an attacker feeds on. The safest assumption is that the inside is not automatically safe, that trust should follow identity rather than address, and that the most dangerous door is the one you left open because you were sure no threat could ever be standing behind it.

– Serguey Asael Shinder

Leave a Reply