Hacker News new | ask | show | jobs
by forgotpwtomain 3316 days ago
Why do they need a specific target in-this case, it appears from the video like they can overlay the keyboard and simply grab all keyboard input?

> that's something that should be straightforward for app stores to screen for.

Also wouldn't it be relatively viable to gain update access to a popular existing application or to provide an innocuous application at first and then push a patch enabling this vulnerability?

1 comments

> they can overlay the keyboard and simply grab all keyboard input?

Keyboards have variable heights, widths, etc, so they at least have to know what the keyboard looks like.

Most of users use same and default keyboards. Even if you use different keyboard, with click heatmaps, they could find out keyboard layout and specs.