3 ms·
2FA and login limits alone aren't likely to stand in the way of state-sponsored hackers. Lots of companies still haven't upgraded to zero trust / BeyondCorp Au
by dub 7y ago
2FA and login limits alone aren't likely to stand in the way of state-sponsored hackers.
Lots of companies still haven't upgraded to zero trust / BeyondCorp AuthN, and lots of companies don't have reproducible signed build artifacts from CI/CD with automatic policy enforcement regarding the properties that those build artifacts must have before they can be deployed.
High-profile companies that think VPNs and networking rules are a security solution have probably already been hacked and just don't know it yet.