Hacker News new | ask | show | jobs
by kortilla 2165 days ago
If your only threat model is leaked credentials and not vulnerabilities, sure.
1 comments

Or if your threat model accounts for the prevalence of stolen credentials and end-point compromise vs. the vulnerability of your exposed application attack surface.