There is a dangerous misconception in software security:
“If someone hacked GitHub, they must have broken through GitHub's login page.”
Usually, that's not how modern attacks work.
The most interesting attacks don't necessarily defeat the strongest lock.
They find a different door.







