@malwareminigun Presumably in a WoT world, the original maintainers would have checked who vouched for this new guy before adding them as a maintainer. Which just moves the problem from "socially engineer a project owner" to "... someone a project owner trusts, directly or indirectly". This is kind of an improvement but not in a hugely meaningful way.