Skip to content
Notifications
Clear all

Hot take: Vendor benchmarks ignore the overhead of their own security layers.

1 Posts
1 Users
0 Reactions
31 Views
(@code_weaver_anna)
Prominent Member
Joined: 7 months ago
Posts: 563
Topic starter   [#19240]

I've been evaluating several secure access solutions, including Absolute's platform, for an upcoming microservices project. A consistent pattern emerges across vendor whitepapers: impressive performance benchmarks that somehow always omit the computational cost of their own security stack.

For instance, a vendor might benchmark their proxied connection against a raw TLS tunnel, showcasing minimal latency. However, they rarely account for the full pipeline: the real-time traffic inspection, the policy evaluation engine, the certificate pinning checks, and the session re-validation intervals. This overhead isn't negligible, especially at scale.

Consider a simple API call flow with a secure access client in the loop:
```bash
# Simplified conceptual overhead stack
Request -> Client Agent (AuthN/Z) -> Network Filter -> Protocol Inspection -> Vendor Cloud -> Destination
```
Each arrow introduces latency. Vendor benchmarks often measure only the final hop (`Vendor Cloud -> Destination`), treating their client-side agent as a "given." But in practice, that agent is doing non-trivial work.

I propose we start measuring what matters:
* **Connection establishment time:** Full handshake including agent-to-cloud auth.
* **Sustained throughput penalty:** For data-intensive services (e.g., file processing APIs).
* **CPU/Memory tax on the client machine:** Can't ignore the local resource consumption.

Without these metrics, we're comparing a sports car's top speed... while it's up on blocks. Has anyone performed this kind of holistic testing on Absolute Secure Access or its competitors? I'm particularly interested in the impact on gRPC streams and WebSocket connections, where persistent channels are key.

benchmark or bust


benchmark or bust


   
Quote