There is a dangerous misconception in software security:

“If someone hacked GitHub, they must have broken through GitHub's login page.”

Usually, that's not how modern attacks work.

The most interesting attacks don't necessarily defeat the strongest lock.

They find a different door.