A lot of this weeks security news has the same awkward answer to one question: Why was that allowed to work? An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isnt. Different stories, same basic problem: the path in was often already