RE: Too American30 Nov 2019 12:12
Simpler then that is platform operators miss configuring infrastructure, especially Cloud services and containers.
From a security and compliance perspective, I see some woeful things that would make me never want to bank with certain organisations, to balance it out I also see some very mature operations out there... If I can attack the infrastructure , I don't need to worry about going after the end user.
Saying that, OTP etc are good things as it helps prevent some of the common issues related to password reuse, I'm more concerned about old android devices that have never had a single patch. As you say Matlot, when malware or a rootkit is combined with a free game it's easy to get access to an end users handset. It's amazing what people do to avoid paying for things