Posted Mar 7, 2012 11:29 UTC (Wed) by job (guest, #670)
In reply to: Not a big deal by slashdot
Parent article: Github compromised
Not necessarily. He could attach his PGP key to any project in the system. If the key was made to look more like a trusted contributor, a malevolent commit could easily have gone undetected.