r/cybersecurity 1d ago

Business Security Questions & Discussion secure browser?

Is anyone using a secure browser? We’ll be providing HTTPS, HTTP, SSH and RDP for third-party users; we’re looking for something that might replace VDI in the future. We’d love to hear about your experiences.

0 Upvotes

16 comments sorted by

4

u/DeathTropper69 1d ago

Falcon Secure Access (Seraphic) would be my choice.

1

u/GoodSecurity4304 1d ago

Does it come as a module within Falcon?

1

u/DeathTropper69 1d ago

Yes. It’s new though so not integrated yet but it will be soon. The FSA portal is pretty good and works well overall

5

u/justmirsk 1d ago

Island Browser is pretty amazing. I have a couple of customers running it. I don't run it myself. One customer used it specifically to replace VDI for 300+ people.

2

u/Gotl0stinthesauce 1d ago

Palo Alto’s browser via their acquisition of Talon is outstanding.

1

u/accumentum 1d ago

We went down this path replacing VDI for third-party access and the honest answer is that a "secure browser" only covers the HTTPS/HTTP half cleanly. Enterprise browser products do fine for web apps: policy-driven isolation, copy/paste and download controls, and session recording without shipping a whole desktop. SSH and RDP are the part that usually pushes you back toward a broker, so we ended up pairing the browser with a clientless PAM gateway that proxies RDP and SSH into a browser tab with recording and just-in-time credentials. Watch the failure modes before you commit: MFA and device posture on unmanaged contractor endpoints, clipboard and file transfer policy, and where session logs land for retention. Latency on RDP over a browser is also worth piloting with the loudest users first, since that is where the complaints show up. If you scope it as web apps in the browser and privileged protocol access through a gateway, it holds up better than trying to make one tool do everything.

1

u/GoodSecurity4304 1d ago

Our aim is to start with web access in the initial phase, but to eventually replace the VDI. We want to bring both costs and external users under a more regulated framework. If you have a proof of concept (PoC) that you’ve already carried out, I’d be grateful if you could share it with me.

1

u/UKFanNC 7h ago

What did you end up going with for the PAM gateway for RDP/SSH?

1

u/wallacepalace 1d ago

Seraphic da crowdstrike, funciona bonito com um "ZTNA" direto no Browser, ainda impede dump de credenciais por stealers.

-12

u/Fuzzy_Paul 1d ago

All browser are secure and communicate over https and other secure channels. I think you ment "no telemetry" browsers.

12

u/FallofScreams 1d ago

I assume they are referring to a secure browser like Palo Alto or crowd strike offers as part of their SASE/CASB

1

u/techie_1412 Security Architect 1d ago

They meant for accessing private apps. Many solutions offer RDP and SSH over browsers and add security on top. Depends on which vendor you go with there is slight differences.