There is just... SO MUCH... wrong with this.
@atarifrosch It's the scans for the Catch-22 work (identifying compromised hosts via an SSH feature that lets you test whether a public key is installed or not. ;-))
This one: https://www.usenix.org/system/files/usenixsecurity25-munteanu.pdf