Hacker News new | ask | show | jobs
by oh_sigh 2852 days ago
Bribe a guard, install a hardware keylogger on random workstation, steal corporate login password, and go from there.
1 comments

And grab any U2F security keys in sight.
A missing U2F key might trigger an audit which could lead to discovery of the keylogger. Better bet would be to get the passwords, and then come back and register a second U2F key to the victims account.