Hacker News new | ask | show | jobs
by cientifico 743 days ago
If an intruder gets into my local account, I'm far more worried about them stealing my cookies or accessing company IP than my browser history.

With cookies and browser access, they could get into my emails, family photos, bank accounts, and even read desktop notifications from my phone's SMSs.

For developers, the real risk lies in the variety of dependencies our apps have, which could get compromised.

So, this isn't really news. There are also tools to access all your iMessage history from a Mac, for example.

I believe the feature is really useful, and for sure you can turn it off.

2 comments

It's more than just browser history.

What if the screenshot that is safed is taken while you have a password in plain sight?

Companies will use it to check on their employees.

Hackers will get material to extort you. "Interesting porn you watched three weeks ago". No need to caught you in the act. It's enough to get access some time later.

Abusers can control their partners.

When do you have a password in plain sight? On the other hand, a key logger that extracts the passphrase for my password manager and steals the database file of it would be a disaster. I’d rather have an attacker browse through years of screenshots.
> When do you have a password in plain sight?

When I generate a new password.

Or when you click the little eye icon to show you a password when you’re typing it in or looking at it in your password manager
Recall is just a massive trove of data and there is no single way it can be abused. For example, key loggers are extremely noisy (bunch of keystrokes being dumped into a log) and an attacker could use the data to see when the last time the user logged into their password manager was to narrow down the search.
>On the other hand, a key logger that extracts the passphrase for my password manager and steals the database file of it would be a disaster

Too bad that's it's not either or but on top of that.

So they can steal your current and past secrets.

The total package.

Oh, why care about key loggers. They are rare. On the other hand, a serially killer in my house would kill me literally!
How is it useful unless you suffer from complete amnesia?

Since when is storing plaintext passwords on disk not a security concern anymore, which is precisely what this tool will do?