Hacker News new | ask | show | jobs
by lmm 4489 days ago
I think they'd be banned from the project. If it looked to be malicious, I can see a lawsuit happening, though that would probably be a slow process and end in a settlement of some sort. Packager identities are verified against legal identity documents; depending on your threat model that may or may not be an effective barrier - a nation state can probably afford to burn a few identities, but regular criminals not so much.
1 comments

It might not be malice on the part of the packager. It could be that their machine is deliberately compromised.