No technology ever comes out free of caveats, and trams, even though they are way better than busses, require years of public work on the infrastructure. That job should be started ASAP, but letting diesel run in the meanwhile is pointless
The attackers used IPs situated in their victims regions to log in, across months, bypassing rate limiting or region locks / warnings
I don't know if they did but it would seem trivial to just use the tokens in-situ once they managed to login instead of saving and reusing said tokens. Also those tokens are the end user client tokens, IP locking them would make people with dynamic IPs or logged in 5G throw a fuss after the 5th login in half an hour of subway
Yeah 2FA should be a default everywhere but people just throw a fuss at the slightest inconvenience. We very much need 2FA to become the norm so it's not seen as such
No one drives in Paris who's not already rich, the public transportation there is great