Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While it is true that hooking _all_ keyboard input requires SYSTEM access (because it involves either impersonating the session manager or injecting code into kernel), you don’t really need that to exfiltrate passwords for random websites that are entered into web browser. Owner of session can hook any event that is passed to the session, which obviously includes any keyboard event that the browser is going to see.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: