Hacker News new | past | comments | ask | show | jobs | submit login

because people are stupid and maintaining a separate private fork is more annoying than it's worth?



If the intention here was really to steal passwords, it could also be deniability?

Uploading sensitive stuff to logging and/or analytics packages or third party providers is a surprisingly easy mistake to make – which in turn makes it an excellent avenue for plausible deniability.

It can be really hard to tell which one it was without inside information or a detailed investigation.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: