So Twitter's admin panel just takes a username and password, no 2FA, no device authentication??
VPN credentials can also be tied to a device certificate, which can be securely stored in the machine’s TPM.
This prevents VPN login from anything except a company issued machine. You don’t get this with normal password auth.
Practitioners take issue with these gross failings, but the markets and regulators seem to not care in the slightest. Disheartening to say the least, yet the reality of the situation.