How could a stolen session token even be useful. I have to log into tools every day, if I change IPs at all I have to re-authenticate, and all prod access needs to be approved and has a finite lifespan.
How could a CI company be that negligent. They should be leading this stuff from a best practice point of view.
No need for a VPN if you have access to the laptop, you just use that as a proxy. Look at any c2, open source or commercial, and they'll have that as a feature.
Most places I’ve worked, has the concepts from above.
Security is lax at most companies but even having worked as an engineer on support rotation, customer anc production access was the last thing I could do and I needed to have exhausted all other options. I don’t feel retaining production access to generate tokens should be a thing.
How could a CI company be that negligent. They should be leading this stuff from a best practice point of view.