"security" is a cost-center, it does not generate revenue. Incidents from lack of "security" need to have a greater impact on revenue before the typical corporate entity spends money.
Exec Bonuses being able to be clawed back for Security issues is just about the only fix that will have real effects. Anything else will have MBAs believing it's a "next guy" problem, and a obstacle to hitting their objectives.
Though right now the US thinks it's winning the Security Vulnerability Stockpile war, so it won't change the state quo.
Europe is implementing a law that requires software made for profit to hit at least industry security standards. Punishments include the purchaser being able to sue the seller as well as jail time for execs.
At some point, we need to push back against the reality in the US that we have effectively no way to stop mass harvesting (and then breaching) of our PII -- and there's basically zero downside to companies when it happens.
And how do you enact exec bonuses being clawed back? They're often the most connected people in the company to those setting the rules of the company, the board.
Hell, some companies have a CEO that has an absolute majority of voting power, meaning they cannot be held accountable and made to implement changes like the one you suggest.
huh? platform? lol. you go to bank with proof of collateral.. get secured loan. wtf does everything need a platform or some VC garbage scrambling to find rent.
Not familiar with the situation in Brazil, but it could be as simple as local credit being harder to get than global credit, or a desire to deal in a denomination that local credit doesn't typically offer without hitting a conversion fee.
A local farmer could perhaps figure out how to contact a swiss banker all on their own, but it would be a lot easier, and cheaper, if there were single place (or better yet, a few competing places) that offer a central place that anyone looking to use/supply credit could come together.
But it is regenerated by reinstalling. So I suspect that its less fingerprint based and more of an in disk IDs thing. Which goes back to if you clear the right things while the system is not running you might be able to change it
They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".
anthropic etal would not have a product to sell without their violation..
kdc had a service that just happened to be popular for pirating...
how are the two even remotely similar?