| ▲ | carefree-bob 2 hours ago | |
Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this. They can try: * various education campaigns * force users/customers to adopt passkeys or other phishing resistant mfa * add various alarms and alerts for unusual activity, resulting in lockout The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two. | ||