Good attacks make good detections make good attacks (a MySQL booby-trap)

  • > By default, we encode this snippet so that an attacker eyeballing a plundered MySQL dump file doesn’t spot it immediately.

    But if you're looking at the dump file, isn't their encoded version itself super suspicious looking?