upvote
> And being a cat and mouse game doesn’t mean the defenders failed.

It does though, in the end attackers always win. If something is a "cat and mouse game" then it's unwinnable by design from the defender side.

Sure, you can keep playing it if you feel like it, but at some point the attacker will be indistinguishable from a legitimate user and you will lose that fight.

reply
By that logic, every security task is doomed to fail. Spam detection and antivirus are cat and mouse games too. I wouldn’t say they fail just because they have to adapt over time.
reply