Earlier quoted context omitted.
What if the attackers phish the VPN credentials too? Does Zero Trust imply phishing-resistant credentials? What Twitter needed was phishing-resistant credentials (security keys, aka U2F).
Zero Trust != VPN. Zero Trust means that the network is not what determines trust. Consider this: * You go to your office, connect to the network * Now you have access to internal services, by virtue of being on the network In a Zero Trust network it does not matter what network you are on. Trust is handed out individually, based on the identity/ role of the user and the context of their session (is their os patched?…
The attacker can surely use a patched OS. Are the security tools secret? If not, then the attacker can run the security tools too.