top | item 29721049

(no title)

liups | 4 years ago

I wonder(worry) that this dump is actually a key honeypot.

May have people thinking: "I already have a <STREAM-SERVICE> account, but with this I could at least get 4k."

They put their legitimate key in, and maybe it phones home the key before begining the download?

This comment from a previous thread illuminates some concerning oversights concerning public repository etiquette:

> I also noticed it provides part of the functionality with a .pyc file, without including the normal python source.[0]

[0] https://news.ycombinator.com/item?id=29704610

discuss

order

No comments yet.