|
|
|
|
|
by charcircuit
1 day ago
|
|
>Data Protection API do meaningfully reduce what you can extract from a windows system It's not meaningfully reduced. The stealer just has to call CryptUnprotectData before uploading it. It's not even like it will show a suspicious prompt to the user, without having to do anything extra the stealer can silently decrypt it. I agree with the rest of the post though. |
|