Hacker News new | ask | show | jobs
by ubercow13 2678 days ago
No, it just has to wait until you unlock your password manager once
1 comments

Well yes, right now that is true. Without filesystem access, without long term persistence, just process memory access, a compromised browser can dump whole db from 1password7 at once. You only need seconds of time.

If only recently accessed passwords were unencrypted, only those would be available.