top | item 44814745

(no title)

superzamp | 6 months ago

I think it's even realistic to say that dotfiles are vulnerable to being used as a fingerprint mechanism by nefarious packages. One could easily create an inventory of github profiles <> dotfiles; then read local dotfiles when their package gets installed on a developer laptop.

discuss

order

meribold|6 months ago

Such a nefarious package could also read browser cookies, SSH keys, emails, photos, and a million of other things.