Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, but it isn't limited to non-verified emails, you can do it with verified emails as well. I assume it's already used to obscure deliberate security compromises in forks etc.

There are many practical impersonation vectors. I assume Github is gonna have to require signed commits for profile links in the medium term future.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: