The Hammer and the Nut: Is Bilevel Optimization Really Needed to Poison Linear Classifiers?