What about tampering the javascript code once vilain has access to the server?
Did you not see the read-only part...
1. How does that justify as
collateral for a loan? you can easily delete the account and leave the lender with no collateral
2. What if the villain uses one of thousands of local root exploits to gain root permissions? it's still idiotic to hand out "read only" accounts like that.
3. You posted about the "read only" account
after everyone pointed out how idiotic what you were doing is.
You've been officially outed. SCAMMER! Now run along to your next username and attempt peddle your next scam