Comment by tdiff

4 months ago

So the attacker has known in advance that the secret was stored in google photos? Is it a common way to store passwords, or is some piece missing here?

Likely a common way to store recovery codes. Similar to those bots that scrape github for API keys