Hacker News new | ask | show | jobs
by notyourday 2624 days ago
You are talking about organizations that have GPG private keys used for signing laying around and those that have Jenkins exposed to the outside world.

Dynamic IP white listing and port knocking are perfectly adequate for 99.9% of the organizations.