Hacker News new | ask | show | jobs
by lalaland1125 1271 days ago
The threat model where someone is able to run malware on your machine, but not run a keylogger to grab your master key for your password manager seems sorta absurd.

Yes, if someone installs malware on your machine (in your user account), they can grab the Chrome password vault. But in that case, 99% of the time they will be grabbing the password vault of other providers as well.

Also, note that the Chrome password vault is encrypted on disk.