Wpis z mikrobloga

@rtpm: https://news.ycombinator.com/item?id=24976138

Others probably have not fully realized this yet, but with GitHub one can:

1) Publish arbitrary commits under your https://github.com/my/project URL, e.g. a fake https://github.com/my/project/blob//README.md in your project describing how to install it that actually describes installing malware.

2) Publish those commits under your name, with your email address, and GitHub will prominently display it as if you made the commit (most do not use GPG signatures, and most