About
Dave Hart is CTO and co-founder of NetFoundry, the company behind OpenZiti, the open-source Zero Trust networking project. He has spent more than 20 years building remote-connectivity platforms, with deep roots in machine-to-machine and IoT systems where devices must reach one another without ever exposing an attack surface, including CTO roles at the ThingWorx IoT segment of PTC and at Axeda before it. He is presenting the architecture this talk demonstrates and the demo built around it.
Sessions
Going Dark: Making MCP Servers and LLM Endpoints Unreachable to Everything Except an Authorized Agent
What you will learn:
1. A reproducible pattern for making any MCP server or LLM endpoint unreachable until an authenticated, authorized identity connects, built entirely on open-source tooling you can pull the same day. 2. A working mental model for why moving authorization before reachability shrinks the attack surface that scanners, tool-poisoning attacks, and stolen API keys all depend on. 3. The failure mode that matters: why a revoked identity killing a call for lack of a path is architecturally different from a rejected credential, and why that difference changes the exploitation math. 4. An honest map of the trade-offs — what going dark defends against (exposure, discovery, lateral movement, secret sprawl), what it does not (a compromised authorized agent, prompt injection inside an authorized session), and where the added plumbing costs you. 5. The war-story version: what actually broke while building the demo, and what those failures taught me about the pattern's real edges.