Hacker News new | ask | show | jobs
by sersi 35 days ago
How would they have been able to install a hijacked Chrome if your computer was on the lock screen?
3 comments

perhaps, back in the day, when windows machines would automatically run autorun.inf if present on a cd or usb drive regardless of whether the machine was locked or not.
Little Snitch is Mac software though.
There's often ways around things. Back in the day I worked in a callcenter. You'd screen-lock & take a short break.

Screen-lock itself required a password. But lo & behold, if you'd pick up the headset & hit a button "accept call" (usually meaning you're back in action), screen would be unlocked.

Convenience (read: profit) trumps security every time.

Mac's had several vulnerabilities during that time including the ability to log in from lock screen with the user "root" with no password. There was also a vulnerability with executing a rubber ducky even with file vault. It was almost 10 years ago so I don't remember the specifics but the point was they had physical access to the building so they could do anything.

People walked to conference rooms and to get food without taking their laptop with them all the time (of course) so it's not like I did something out of the ordinary or against policy. I remember them accusing me of leaving my laptop over night but I was just working late.

And this was in a secure area with cameras within earshot of the over night crew and behind a door in a private shared office (glass door, glass wall so someone could have seen them) so it's not like I was at a common area and just walked out leaving my laptop on a random table).