fascinating stuff. I'm still amazed at how many username/passwords are freely available via github search: https://github.com/search?p=96&q=gmail+password&ref=searchre... even if they have 2-step auth setup, people choose "complete the email address" as a form of authentication which you can most likely get from their github profile. the moral of the story here is - if you do not want someone to find it - do not publ…
Im not a hacker/cracker or whatever but I am curious would it be illegal to use one of those usernames and passwords to see if it actually worked for an account? edit: I know that it is not ethical and I am only slightly tempted to do it but is it actually illegal to use open source code in that way?
You can compare it to opening someone's home because he left his key in a public place unbeknownst to him.
You generally couldn't make the argument that 'he may have wanted people to have the key, that's why he left it in a public/open source place'. Firstly, one can't assume that, so we must hear it explicitly before it's true. And secondly, if universal open-source access was provided, there wouldn't be a key to find as there wouldn't be a lock in the first place to allow specific access. The whole point of a password or key means you do not want fully open access to all, meaning any password or key in an open-source project is likely unintentional, a mistake, and thus you'd be entering without permission which is illegal in most jurisdictions.