@astrid galaxy brain idea: make a burner github account that's a member of nixos, cncf and a bunch of other high value targets, wait for the email, then delete all the memberships and hand the account over to see what they try
Top-level
@astrid galaxy brain idea: make a burner github account that's a member of nixos, cncf and a bunch of other high value targets, wait for the email, then delete all the memberships and hand the account over to see what they try 5 comments
@danderson @astrid let's thank the gods of economical efficiency everyday it doesn't seem like the chaotic attacker that could be so meticulous to target all distros and be stealthy as fucked has appeared *or* we didn't detect it @danderson @raito @astrid the way we see it, the primary exploit here was the social one (see details at [1]). this is absolutely what passes for stealth on that front. [1] https://boehs.org/node/everything-i-know-about-the-xz-backdoor |
@danderson @astrid though it's highly likely here they're here for the airdrop cryptocurrency money and are just scamming you out of shitcoins