5 ms·
I always wondered about JS-powered keyloggers. What if you type your Linux admin password, or other sensitive things by accident into the webpage and it all get
by cyberlab 5y ago
I always wondered about JS-powered keyloggers. What if you type your Linux admin password, or other sensitive things by accident into the webpage and it all gets scooped up? Yes: the keylogger would have a privacy policy in place, but it irks me to think I could accidentally reveal my dearest secrets into some nosy webpage.
- googillionaire 5y agoThere are other ways that could happen, too, for example a chat window or a search bar. Change your password asap.
- gspr 5y agoAnd if you're running X: any window can just decide that it wants your keystrokes anyway.
- iamacyborg 5y agoThis, but with everyone using Grammarly which is effectively a keylogger browser extension.
- jfk13 5y agoFortunately for me, Grammarly has so alienated me with its relentless, irritating ads that there is no possibility that I will ever install it.
- Kelamir 5y agoI've found LanguageTool(https://languagetool.org/ https://languagetool.org/) superior overall. It's open-source and is recommended by Firefox.
- arecurrence 5y agoAn even creepier analog to this was a big problem in mobile apps until Apple squashed it by telling everyone when it happens. Mobile apps were recording the clipboard every time they gained focus and many then uploaded that to the web. Copy pasted passwords... email addresses... etc.
- cyberlab 5y agoYes, pasteboard scraping and exfil was rampant prior to Apple's new prompts.
- Ueland 5y agoI often think about this when I see services that does stuff with your input to help you. For example online JSON formatters, online RegEx testers and such.
- viraptor 5y agoIdeally it shouldn't matter that it happens. I mean, it's not great and if you're aware of this, you should roll your password, but realistically the external services should have no way to interact with your admin account. For better protection you can use totp codes or some type of security token which makes password leaks useless.