▲ | zahlman 4 days ago | ||||||||||||||||||||||||||||||||||||||||
Yes, but this is an ecosystem large enough to include people who have that time (and inclination and ability); and once they have reported a problem, everyone is on high alert. | |||||||||||||||||||||||||||||||||||||||||
▲ | wongarsu 4 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||
If you steal the cookies from dev machines or steal ssh keys along with a list of recent ssh connections or do any other credential theft there are going to be lots of people left impacted. Yes, lots of people reading tech news or security bulletins is going to check if they were compromised and preemptively revoke those credentials. But that's work, meaning even among those informed there will be many who just assume they weren't impacted. Lots of people/organisations are going to be complacent and leave you with valid credentials | |||||||||||||||||||||||||||||||||||||||||
|