Live data from Hacker News

Viewing profile — burner589432

burner589432

HN member
Joined
Thu, Oct 31, 2019, 1:52 AM UTC
HN karma
-2
Public activity
8 items

About burner589432

No profile information was provided.

Recent public activity

  1. comment
    Comment #21414476

    Last I checked hooking key events in Windows requires SYSTEM access. Stealing session tokens can be as easy as just pulling the entire browser profile, which I doubt requires eleva…

  2. comment
    Comment #21407851

    So... Nothing apart from some convoluted anecdote? If currently there's no password manager in existence that doesn't let you override the plaintext password extraction / override …

  3. comment
    Comment #21405868

    > since the autofill is not 100% reliable, it's not that unusual to go into the password store and manually get the password out of there. I imagine you can extract passwords out o…

  4. comment
    Comment #21405691

    If your host is infected with malware but it can't steal your passwords due to hardware boundaries, it still has access to your host at a pretty reasonable permission level. In mos…

  5. comment
    Comment #21405684

    If you're trying to prevent credential theft: Educate users on password managers, deploying 2FA, or tokens like this would also make sense. MFA deployments are probably significant…

  6. comment
    Comment #21405599

    If malware is in a position to steal data from your clipboard or keylog your device, it's very likely to be in a position to hijack your session tokens.

  7. comment
    Comment #21405591

    Browser based password managers solve this.

  8. comment
    Comment #21404962

    Unpopular opinion: These keys are about selling the idea that physical-based security is somehow magically better. If you have good password hygene (read: a decent password manager…