Viewing profile — burner589432
burner589432
HN member- Joined
- Thu, Oct 31, 2019, 1:52 AM UTC
- HN karma
- -2
- Public activity
- 8 items
- HN profile
- View on Hacker News ↗
About burner589432
No profile information was provided.
Recent public activity
-
comment
Comment #21414476
Last I checked hooking key events in Windows requires SYSTEM access. Stealing session tokens can be as easy as just pulling the entire browser profile, which I doubt requires eleva…
-
comment
Comment #21407851
So... Nothing apart from some convoluted anecdote? If currently there's no password manager in existence that doesn't let you override the plaintext password extraction / override …
-
comment
Comment #21405868
> since the autofill is not 100% reliable, it's not that unusual to go into the password store and manually get the password out of there. I imagine you can extract passwords out o…
-
comment
Comment #21405691
If your host is infected with malware but it can't steal your passwords due to hardware boundaries, it still has access to your host at a pretty reasonable permission level. In mos…
-
comment
Comment #21405684
If you're trying to prevent credential theft: Educate users on password managers, deploying 2FA, or tokens like this would also make sense. MFA deployments are probably significant…
-
comment
Comment #21405599
If malware is in a position to steal data from your clipboard or keylog your device, it's very likely to be in a position to hijack your session tokens.
-
comment
Comment #21405591
Browser based password managers solve this.
-
comment
Comment #21404962
Unpopular opinion: These keys are about selling the idea that physical-based security is somehow magically better. If you have good password hygene (read: a decent password manager…